Verisign

Senior Application Security Engineer

Verisign
Apply
6 hours ago
Reston, VA, USASenior
H1B sponsor

Base Salary

$164k - $222k/yr

Responsibilities

  • Serve as the application security subject matter expert for development teams during requirements, design, and architecture phases, including threat modeling.
  • Lead manual and automated application vulnerability assessments and provide remediation guidance.
  • Own vulnerability management across software composition analysis, static and dynamic testing, interactive testing, and secrets-scanning tools.
  • Review submissions from Verisign’s public bug bounty program and track issues against defined SLAs.
  • Integrate security testing into CI/CD pipelines and review third-party applications against internal security requirements.
  • Assess AI and LLM application security risks and develop guidance for AI coding assistants and AI-assisted security workflows.
  • Contribute to information security standards and secure coding guidance while mentoring junior engineers and analysts.

Requirements

  • 10+ years of experience in Information Technology, including hands-on application development experience.
  • 6+ years conducting application security assessments using commercial or open-source tools such as Burp Suite or Fortify.
  • Hands-on experience with software composition analysis, dynamic application security testing, and secrets-scanning platforms.
  • Experience managing vulnerability programs through ticketing and workflow systems, including SLA definition and executive reporting.
  • Strong knowledge of the OWASP Testing Framework, OWASP Top 10, software development life cycles, and current application architectures.
  • Practical familiarity with AI and LLM application security risks and industry guidance.
  • Preferred: 6+ years of software development using Java, C++, Rust, Go, Python, or Perl.
  • Preferred: experience with continuous integration security assessments, Linux, API security testing, and public or private bug bounty programs.
  • Preferred: understanding of DevOps and security integration and familiarity with Kanban, Scrum, or pair programming.
  • Strong communication, presentation, leadership, organizational, multitasking, and independent-working skills.

Benefits

  • Hybrid work schedule based in the Reston, Virginia office.
  • Competitive benefits and opportunities for career growth.
  • Discretionary performance-based bonus and potential discretionary stock awards for eligible roles.

Categories

Verisign

About Verisign

1,001-5,000 employees

Verisign operates critical internet infrastructure, including the authoritative registries for .com and .net, and provides DNS and security services to registrars and enterprises. It earns revenue from wholesale domain registrations and managed DNS/security offerings under long-term agreements with internet governance bodies and partners. Founded in 1995 and headquartered in Reston, Virginia, Verisign is a public company listed on NASDAQ.

Contact me