📋 External Recruiting Agencies

Precision Solutions is a staffing and recruiting agency that places talent with other companies, rather than hiring for its own internal product development operations.

This company was flagged and excluded from default search results. Proceed with caution.

Overview
Posted 1w ago

Application Security Engineer

Overview
United States
RemoteContract
Responsibilities
  • managing firewalls
  • analyzing security events
  • developing detections
Requirements
  • Requires 4+ years of experience
  • Including network and application security
  • With expertise in WAF
  • Zero trust
  • Cloud security, APIs
  • Python
  • Terraform, and cybersecurity analysis
Technical tools mentioned
Web Application Firewall (WAF)Zero Trust Network AccessOAuthSAMLOIDCAkamaiRadwareAWSAzureGoogle Cloud Platform (GCP)TerraformPythonServiceNowHTTPDNSSSL CertificatesAI

Job description

Application Security Engineer

Remote within the US

US Citizen

Approximately 8 Month Contract (w/ possible extensions)

 

Summary

The Application Security Engineer candidate will have a strong background in cybersecurity and understanding of web application and zero trust proxy security practices. The primary responsibility of the Engineer will be to ensure the effective deployment, configuration, and maintenance of our systems for Global customers. This role requires expertise in Web Application Firewalls, Zero Trust Proxy, Cloud security as well as experience with alerts and detections and data log analysis. This role will be part of the Application Edge Protection Service within the CyberSecurity pillar.

 

Responsibilities

  • Web Application Firewall Management: Deploy, configure, and maintain web application firewall systems to protect our web applications against potential threats and vulnerabilities.
  • Zero Trust Proxy: Deploy, configure, and Zero Trust Proxy systems to support identity gates to include defining and maintaining policies and connectors.
  • Security Incident Response: Monitor and analyze security events, alerts, and logs generated by the web application firewall systems. Investigate and respond to potential security incidents, working closely with the Security Operations Center (SOC) and other Cybersecurity teams.
  • Detection and Analysis: Develop and maintain detection rules, alerts, and reports to proactively identify and mitigate risks utilizing logs. Provides investigation findings to relevant business units to help improve information security posture.
  • CDN Integration: Collaborate with the infrastructure and application teams to integrate the web application firewall with CDNs such Akamai and Radware, ensuring seamless traffic management and content delivery.
  • Vulnerability Assessment: Utilize WAF data to identify potential vulnerabilities and recommend appropriate remediation measures to customers.
  • Documentation and Reporting: Maintain accurate documentation of WAF configurations, policies, and procedures. Prepare reports and metrics related to web application security, including trends, incident summaries, and mitigation strategies, as needed.
  • Collaboration: This role requires ability to explain security details to non- security teams such as application and engineering teams. Must be able to collaborate with cross-functional teams to ensure effective communication, knowledge sharing, and alignment of security objectives. Provide guidance to application teams on application security best practices and security awareness, as needed.
  • Automation: This role required individuals who are knowledgeable of automation processes, python terraform, use of AI and Cloud native concepts with AWS, Azure and Google cloud.

 

Requirements

 

Years of Experience: 4+ years with minimum 2 years in network security and 2 years in application security

 

Technical Skills

  • Strong knowledge of web application security concepts, OWASP Top 10 vulnerabilities, and related mitigation techniques.
  • Understanding of authentication and authorization flows (OAuth, SAMAL, OIDC)
  • Strong technical background with Web Application Firewall (WAF), Zero Trust Network Access, APIs, and Cloud security policies.
  • Understanding of API security issues and API authentication.
  • Previous experience in a Security Operations Center (SOC) or performing cybersecurity analysis, log analysis, and threat detection is highly desirable.
  • Good understanding of information security principles and policy enforcement.
  • Solid comprehension of HTTP protocol and demonstrated ability to troubleshoot using HTTP logs
  • Strong technical background in web development and familiarity with potential attack vectors/methods
  • Understanding of Authentication, DNS, Networks, Firewalls, SSL Certificates

 

Experience in the following areas are strongly preferred:

  • Knowledge of Web Application Firewall technologies (Akamai)
  • Knowledge of Zero Trust framework and technologies
  • Experience integrating zero trust with WAF
  • Familiarity with cloud security services, concepts, and best practices (AWS, Azure, GCP)
  • Infrastructure as code (Terraform) and automation using Python
  • Ethical hacking
  • ServiceNow experience
  • Technical documentation experience
  • CISSP, CISM, CISA, GIAC or other security certifications are desired
  • Familiarity and comfortability using AI tools

 

Soft Skills

  • High degree of personal integrity and ethics with a passion for protecting people and systems against cybersecyurity threats
  • Excellent written and oral communication and presentation skills for technical and business audiences
  • Advanced critical thinking, problem solving and technical troubleshooting abilities
  • Track record of getting things done quickly and with high levels of quality
  • Demonstrated ability to operate in a dynamic, evolving environment
  • Ability to coordinate completion of multiple tasks and meet aggressive time frames
  • Strong analytical skills with high attention to detail and accuracy
  • Experience with and the ability to thrive in a complex and fast-paced technology and/or information security organization, within a large enterprise environment
  • Bi-lingual a plus

 

Education/Certification Requirements

  • Education (degree): Bachelor's Degree/University Degree and/or Undergraduate Diploma in Information Security, Information Technology, Computer Science, Engineering or equivalent years in experience
 
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
 
 

Similar jobs

Application Security Engineer roles
2mo
Save
Mark Applied
Hide
Security Engineer, Application Security
United States
$100k-$200k/yr RemoteFull Time
Trail of Bits
Trail of Bits: Provides high-end security research and software auditing services.
Deep application security and low-level code assessment experience, manual static/dynamic and binary analysis, memory corruption expertise, tool development, and proficiency in multiple programming languages for security tooling.
Rust, Golang, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, C++, AWS, GCP, Azure
9h
Save
Mark Applied
Hide
Senior Application Security Engineer
Marina del Rey or Los Angeles or San Francisco
$180k-$230k/yr HybridFull Time
Sift
Sift: Software platform for high-frequency hardware telemetry observability.
5+ YOERequires 5+ years building production software, security ownership of shipped code, Go or Rust proficiency, application security expertise, threat modeling, secure design, and hands-on CI/CD security tooling experience.
Go, Rust, SAST, software composition analysis, secret scanning, fuzzing, CI/CD, Sigstore, SLSA, SBOM
1d
Save
Mark Applied
Hide
Application Security Engineer
United States
$82k-$118k/yr RemoteFull Time
Guild Mortgage
Guild Mortgage: Provides residential mortgage lending and loan servicing.
3+ YOEBachelor's degree preferred or equivalent experience; minimum 3 years as a software developer or similar. Requires application security, vulnerability testing, secure development, AI security, and Microsoft Office proficiency.
Microsoft Office Suite, Microsoft Word, Microsoft Excel, Burp Suite, Wiki, OWASP Top 10 for LLM Applications, MITRE ATLAS, CI/CD, LLM, retrieval-augmented generation (RAG)
1d
Save
Mark Applied
Hide
Overseas Contractor
Dallas, Texas, United States
$66-$70/hr OnsiteFull Time
LTIMindtree
LTIMindtreeNational Stock Exchange of India: LTIM: Global technology consulting and digital solutions.
3+ YOEBachelor’s degree or equivalent experience, 3+ years in cybersecurity engineering, and application security expertise. Preferred: 5+ years in cloud security, cloud architecture, compliance, and security automation.
Python, Java, JavaScript, C#, PowerShell, AWS, Microsoft Azure, Google Cloud
1d
Save
Mark Applied
Hide
Senior Application Security Engineer
United States
$112k-$140k/yr RemoteFull Time
IDEMIA
IDEMIA: Develops biometric identification and secure identity technologies globally.
10+ YOE10+ years of combined software engineering and security experience, including DevSecOps; CI/CD security, architecture reviews, SAST/SCA triage, AWS/Azure security, compliance frameworks, and eligibility for background clearances required.
Java, TypeScript, AWS Lambda, AWS GovCloud, Azure Government, GitLab CI, AWS CodePipeline, Jenkins, SonarQube, Nexus, Tenable, FedRAMP, CJIS, NIST 800-53, SAST, SCA, CI/CD, SBOM, STRIDE, PASTA
1d
Save
Mark Applied
Hide
Application Security Engineer, AWS Proactive Security
Seattle or Herndon
$159k-$202k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOERequires 3+ years programming, 2+ years security code review and systems troubleshooting, STEM bachelor's degree or 2+ years IT security experience, networking knowledge, and vulnerability remediation expertise.
Python, Ruby, Go, Swift, Java, .Net, C++, HTTP, DNS, TCP/IP, HTTP(S), AWS
2d
Save
Mark Applied
Hide
Staff/Lead Application Security Engineer
San Francisco or New York or Toronto
OnsiteFull Time
SnailWorks
SnailWorks: SnailWorks provides mail tracking and delivery intelligence software for marketers.
Expert web/API security, identity and access design, applied cryptography, cloud and container security; production coding experience and a record of driving security work across engineering organizations.
AI, SAST, DAST, SCA, CI/CD, RBAC, ABAC
3d
Save
Mark Applied
Hide
Application Security Engineer IV - AI Harness
Tempe or St. Louis
HybridFull Time
Edward Jones
Edward Jones: Offers investment management and financial planning through local branches.
6+ YOEBachelor's degree or equivalent practical experience and 6+ years in application security, secure software engineering, DevSecOps, platform engineering, security operations, or related cybersecurity engineering roles.
Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, Jira, Azure DevOps, Python, SARIF, SBOMs, SAST, SCA, DAST, OWASP Top 10, CWE, CVSS, NIST SSDF, NIST CSF 2.0, SIEM, APIs, Kubernetes, AWS, Azure