
Application Security Engineer (Experienced in applications security focusing on red, blue or purple team activities)
MUFG Investor Services2 months ago
Dublin, IrelandSenior
Responsibilities
- Act as a security champion and promote secure-by-design practices across the business.
- Identify and analyze web application vulnerabilities and provide remediation guidance to engineering teams.
- Manage application security platforms and maintain coverage, compliance, and remediation tracking.
- Conduct threat modeling and application architecture reviews to identify risks early in the SDLC.
- Implement application security controls and preventative measures.
- Implement and manage SAST and SCA tooling across application repositories.
- Scale automated DAST solutions to improve testing coverage and runtime security visibility.
- Perform penetration testing on internally developed applications and coordinate external penetration tests.
- Review third-party application configurations and hardening, and validate remediation of security issues.
- Collaborate closely with development, IT, and DevOps teams to resolve security issues.
- Create custom security tooling, scripts, and CI/CD pipeline jobs for security reviews and scans.
Requirements
- Experience in application security with a focus on red-team, blue-team, or purple-team activities.
- Experience in software development or contributing to open-source projects.
- Experience with DAST tools such as Burp Suite or OWASP ZAP.
- Experience with SAST and SCA tools such as Snyk, Veracode, or Checkmarx.
- Proficiency in one or more of Python, JavaScript, .NET, or Java.
- Strong understanding of open-source and third-party library vulnerabilities.
- Knowledge of the software development life cycle and agile development practices.
- Experience testing REST and GraphQL APIs.
- Experience with GitLab or GitHub, Datadog, Jira, Docker, and development IDEs.
- Experience working with development and DevOps teams to resolve security issues.
- Experience conducting security-focused code reviews and creating custom security tooling or scripts.
- Preferred experience in the financial sector or another heavily audited industry.
- Preferred experience with AWS services such as WAF and Cognito, Infrastructure as Code, Kubernetes, containers, OpenID Connect, OAuth, identity providers, and security-focused CI/CD pipeline jobs.
Benefits
- Collaborative and connected team culture.
- Learning and development opportunities.
- Innovation-focused environment and client-focused work.
- Equal opportunity employer.