远程工作雷达

高级应用安全工程师

Senior Application Security Engineer

开发工程限定地区(需当地身份)
公司Clear Capital
薪资$111,000 - $144,400/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

高级应用安全工程师负责验证应用服务在设计和实现过程中是否符合高标准的安全要求。该角色会与底层服务一起分析应用的安全性,包括连接的依赖项,如中间层系统和数据库。此外,高级应用安全工程师还需处理遗留和新兴的安全问题,并实施可重复的安全开发实践,以减少可能导致被利用的程序设计缺陷。当发现安全问题时,应用安全工程师会与相应的技术及管理层团队沟通,确保关注风险缓解——保障业务连续性,但不忽视风险。应用安全工程师持续评估应用的弱点,并在它们被滥用之前找到解决办法。

该职位还负责评估企业间合作项目、第三方关系、外包解决方案和供应商的应用安全性。高级应用安全工程师需推荐程序控制措施,并监控和管理安全开发实践以应对现代问题。应用安全工程师会像攻击者一样思考,但始终秉持诚信,不会滥用其权限。

你将参与的工作

  • 在软件开发生命周期的所有阶段规划并执行应用安全测试,以识别应用中的漏洞和安全编码实践中的弱点。
  • 评估发现的漏洞并推荐风险缓解方案,利用自动化提高测试和修复过程的效率。
  • 向相关方传达发现的问题、风险和建议,同时记录并文档化 against 定义的服务级别协议(SLAs)和业务指标的交付和实施进度。
  • 领导人工智能安全项目,包括对生产级大语言模型堆栈进行威胁建模,防范自主性和提示注入风险,并审计第三方模型和API以保护软件供应链。
  • 参与产品和应用项目。这包括与业务部门和技术团队互动,了解即将开展的内容以及如何从一开始就使他们的项目更安全。
  • 与架构师和开发团队合作,推动安全设计实践,利用已建立的安全标准。
查看英文原文

The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the Sr. Application Security Engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the application security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused.

This position is also responsible for assessing the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. The Sr. Application Security Engineer is expected to recommend programmatic controls, and monitor and manage secure development practices to address modern day issues. Application Security Engineers think like attackers, but always act with integrity and do not abuse their privilege.

What You Will Work On

  • Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices.
  • Assess discovered vulnerabilities and recommend risk-mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes.
  • Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service-level agreements (SLAs) and business metrics.
  • Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third-party models and APIs to secure the software supply chain.
  • Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning.
  • Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks.
  • Fully define and follow a security review process to ensure an automated and repeatable process is managed.
  • Regularly monitor the security community for public-facing security issues, as well as to learn new tactics that can be used in testing.
  • Train developers and junior application security engineers on weaknesses to avoid.
  • Perform other duties as assigned.

Who We Are Looking For

  • 4+ years of related experience required.
  • Bachelor’s Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience.
  • Highly technical and analytical, with a background in software development, and scripting (e.g., Java, Python, C++, Ruby, JavaScript, PowerShell, PHP).
  • Expertise in application security testing, including hands-on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools.
  • Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.
  • Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.
  • Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.

What You Can Expect

  • Compensation: The base salary for this position ranges from $111,000 to $144,400 annually, depending on your location, experience, and qualifications. Additional compensation offerings include company profit-sharing bonus program, communication stipends, and referral bonuses.
  • Inclusive benefits package offering:
  • Comprehensive medical, dental, and company paid vision insurance, 401(k) retirement plan with employer match, voluntary life and AD&D insurance options, voluntary supplemental insurances for accident, critical illness, and legal services, paid time off (PTO) and paid holidays, employee assistance and wellness programs, company paid short term disability coverage, company contributions to health saving funds (with participation in the high deductible health plan. We offer company paid access to Galileo for virtual primary care and Rula for virtual mental health resources.
  • Through our Anniversary Program, we celebrate the meaningful milestones and long tenure that reflect how much we value your contributions and commitment to our team.
  • Career and skill development resources to help advance your career and personal growth.
  • A mission-driven environment where your work makes a measurable impact on the real estate industry.

What We Value

  • Wherever it Leads, Whatever it Takes® - No matter how remote, complex, or unexpected. Our commitment never wavers.
  • Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit.
  • Lift others up - We lead with empathy and strive to improve the lives of those around us.
  • Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact.
  • Raise the bar - We don’t settle for industry standards, we redefine them.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位