SRM Technologies
Posted 1mo ago

Application Security - Vulnerability Discovery

SRM Technologies
United States
RemoteFull Time
Responsibilities
  • triaging vulnerabilities
  • reviewing code
  • driving remediation
Requirements
  • 3+ years application security experience
  • Experience triaging vulnerabilities
  • Handling bug bounty reports
  • Building SDLC
  • Cloud-native (AWS preferred)
  • Strong communication and code-review skills
Technical tools mentioned
TenableSASTDASTSCAIaC scanningAWS

Job description




This is a remote position.

Product Security Engineer CW Job Description

This document outlines the job description for an Application Security Engineer (Contractor) that will be partnering with the Product Security organization 

 

Team Description 

As part of the Product Security Engineering team, you’ll be working to reduce overall security risk across Dropbox. We partner with engineering and product teams during each point of the software development lifecycle (SDLC) and help drive broader security initiatives across Dropbox.

 

Product Security Engineers provide security impact by developing secure-by-default libraries and frameworks that teams across Dropbox can frictionlessly integrate into their products. They also offer their expertise on security matters through documentation and educational initiatives.

Responsibilities

  • Triage, validate, and prioritize security vulnerabilities identified through manual reviews, automated tooling, bug bounty reports, and AI-assisted security analysis platforms.
  • Participate in on-call rotation to support security incident triage, perform code reviews, and address security questions.
  • Partner closely with engineering teams to drive remediation efforts, provide actionable guidance, and ensure timely closure of security findings based on risk and severity.
  • Review security-related pull requests and code changes, providing guidance on secure implementation patterns and identifying potential vulnerabilities before production deployment.
  • Analyze findings generated by AI-powered security agents and automation platforms, validate results, reduce false positives, and help drive remediation workflows across engineering teams.
  • Collaborate with Product Security Architecture and development teams to improve vulnerability detection, prioritization, and remediation processes.
  • Support security incident investigations and root cause analysis when vulnerabilities or application security issues are discovered.
  • Develop security tooling, automation, and workflows that improve security coverage and reduce manual effort for security reviews and vulnerability management.
  • Administer and manage vulnerability scanning tools (e.g., Tenable or similar)
  • Configure, optimize, and maintain scanning tools, policies, and schedules
  • Track and report on remediation progress, security metrics, and risk reduction initiatives across assigned engineering organizations.
  • Contribute to security documentation, best practices, and developer education efforts to improve secure coding practices across Dropbox.

 

Requirements

  • Available to work until 11:00AM Pacific Standard Time (PST).
  • 3+ years experience in application security engineering
  • Strong communication skills and relationship building skills
  • Experience in building and scaling the Secure Development Lifecycle
  • Experience with handling vulnerability, and bug bounty reports
  • Experience partnering with cross-functional engineering and product teams
  • Experience triaging, validating, and prioritizing security vulnerabilities from static analysis, dynamic analysis, dependency scanning, penetration testing, or bug bounty programs.
  • Experience partnering with software engineering teams to drive remediation and risk reduction efforts.
  • Strong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.).
  • Experience reviewing source code and identifying security vulnerabilities in modern programming languages and frameworks.
  • Familiarity with security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, and vulnerability management platforms.
  • Experience working with cloud-native architectures and public cloud environments (AWS preferred).
  • Ability to evaluate security findings, distinguish signal from noise, and communicate risk-based remediation recommendations.
  • Familiarity with AI-assisted development workflows, AI-powered security tooling, or LLM-based security use cases is a plus.

 





About SRM Technologies

Global engineering and digital transformation services provider.

Year founded
1998
Employees
1000
Organization type
Private
Headquarters
IN

Similar jobs

Application Security Engineer roles
2mo
Save
Mark Applied
Hide
Security Engineer, Application Security
United States
$100k-$200k/yr RemoteFull Time
Trail of Bits
Trail of Bits: Provides high-end security research and software auditing services.
Deep application security and low-level code assessment experience, manual static/dynamic and binary analysis, memory corruption expertise, tool development, and proficiency in multiple programming languages for security tooling.
Rust, Golang, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, C++, AWS, GCP, Azure
7h
Save
Mark Applied
Hide
Overseas Contractor
Dallas, Texas, United States
$66-$70/hr OnsiteFull Time
LTIMindtree
LTIMindtreeNational Stock Exchange of India: LTIM: Global technology consulting and digital solutions.
3+ YOEBachelor’s degree or equivalent experience, 3+ years in cybersecurity engineering, and application security expertise. Preferred: 5+ years in cloud security, cloud architecture, compliance, and security automation.
Python, Java, JavaScript, C#, PowerShell, AWS, Microsoft Azure, Google Cloud
8h
Save
Mark Applied
Hide
Senior Application Security Engineer
United States
$112k-$140k/yr RemoteFull Time
IDEMIA
IDEMIA: Develops biometric identification and secure identity technologies globally.
10+ YOE10+ years of combined software engineering and security experience, including DevSecOps; CI/CD security, architecture reviews, SAST/SCA triage, AWS/Azure security, compliance frameworks, and eligibility for background clearances required.
Java, TypeScript, AWS Lambda, AWS GovCloud, Azure Government, GitLab CI, AWS CodePipeline, Jenkins, SonarQube, Nexus, Tenable, FedRAMP, CJIS, NIST 800-53, SAST, SCA, CI/CD, SBOM, STRIDE, PASTA
12h
Save
Mark Applied
Hide
Application Security Engineer, AWS Proactive Security
Seattle or Herndon
$159k-$202k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOERequires 3+ years programming, 2+ years security code review and systems troubleshooting, STEM bachelor's degree or 2+ years IT security experience, networking knowledge, and vulnerability remediation expertise.
Python, Ruby, Go, Swift, Java, .Net, C++, HTTP, DNS, TCP/IP, HTTP(S), AWS
1d
Save
Mark Applied
Hide
Staff/Lead Application Security Engineer
San Francisco or New York or Toronto
OnsiteFull Time
SnailWorks
SnailWorks: SnailWorks provides mail tracking and delivery intelligence software for marketers.
Expert web/API security, identity and access design, applied cryptography, cloud and container security; production coding experience and a record of driving security work across engineering organizations.
AI, SAST, DAST, SCA, CI/CD, RBAC, ABAC
2d
Save
Mark Applied
Hide
Application Security Engineer IV - AI Harness
Tempe or St. Louis
HybridFull Time
Edward Jones
Edward Jones: Offers investment management and financial planning through local branches.
6+ YOEBachelor's degree or equivalent practical experience and 6+ years in application security, secure software engineering, DevSecOps, platform engineering, security operations, or related cybersecurity engineering roles.
Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, Jira, Azure DevOps, Python, SARIF, SBOMs, SAST, SCA, DAST, OWASP Top 10, CWE, CVSS, NIST SSDF, NIST CSF 2.0, SIEM, APIs, Kubernetes, AWS, Azure
2d
Save
Mark Applied
Hide
Confluent - Staff Security Engineer
Poughkeepsie or Lowell or Rochester or Tucson or Research Triangle Park or Armonk or Boston or Bellevue or Atlanta or San Jose or Dallas or Austin or San Francisco or Seattle
$161k-$299k/yr RemoteFull Time
IBM
IBMNew York Stock Exchange: IBM: Global technology providing enterprise software, cloud, and consulting.
10+ YOERequires a bachelor's degree and 10+ years of application security experience, with expertise in secure architecture, cloud-native platforms, security automation, CI/CD, and Go, Python, or Java.
Go, Python, Java, CI/CD, AI, LLMs
3d
Save
Mark Applied
Hide
Application Security Engineer IV - AI Harness
Tempe or St. Louis
$102k/yr HybridFull Time
Edward Jones
Edward Jones: Provides personalized financial advice and wealth management services.
6+ YOEBachelor's degree or equivalent practical experience, 6+ years in application security or related cybersecurity engineering, CI/CD and AppSec tooling, automation with Python or shell, observability, secure SDLC, and AI-assisted security workflows.
Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, Jira, Azure DevOps, Python, SAST, SCA, DAST, SBOMs, SARIF, Selenium, Microsoft Azure, AWS, Kubernetes, SIEM, APIs, NIST SSDF, NIST CSF 2.0, OWASP Top 10, CWE, CVSS, CISSP, CSSLP, CCSP, GIAC