East West Bank
Posted 3w ago

Lead Application Security - DevSecOps & AI-Driven Software Assurance

East West Bank
Dallas or San Marino
$120k-$180k/yrOnsiteFull Time
Responsibilities
  • integrating security
  • conducting testing
  • analyzing software
Requirements
  • Proven application security/DevSecOps experience with SAST/DAST
  • GitHub Advanced Security
  • Third-party software analysis or binary/reverse engineering
  • Threat intelligence integration
  • Secure SDLC, and penetration testing coordination
  • US work authorization required
Technical tools mentioned
GitHubGitHub Advanced SecurityGitHub WorkflowsCodeQLDependabotOWASP ZAPWAF

Job description

Introduction:

Since 1973, East West Bank has served as a pathway to success. With over 110 locations across the U.S. and Asia, we are the premier financial bridge between the East and West. Our teams of experienced, multi-cultural professionals help guide businesses and community members on both sides of the Pacific looking to explore new markets and create new opportunities, and our sustained growth and expertise in industries like real estate, entertainment and media, private equity and venture capital, and high-tech help build sustainable businesses and expand our associates’ potential for career advancement. 

 

Headquartered in California, East West Bank (Nasdaq: EWBC) is a top-performing commercial bank with a strong foundation, an enterprising spirit and a commitment to absolute integrity. East West Bank gives people the confidence to reach further.



Overview:

The Senior Cyber Security Engineer will lead and execute security initiatives across the application lifecycle, integrating security into DevOps pipelines, managing vulnerability assessments, and coordinating penetration testing efforts. This role also extends into advanced software assurance, including third-party software analysis, binary-level inspection, and application trust validation, ensuring that both internally developed and externally sourced applications meet the bank’s security standards prior to execution within the enterprise environment. 



Responsibilities:

Application Security & DevSecOps Integration 

  • Embed security controls into CI/CD pipelines using GitHub workflows and automation tools. 

  • Collaborate with development teams to implement secure coding practices and threat modeling during design and development phases.  

  • Manage GitHub Advanced Security configurations, including secret scanning, push protection, and impact analysis. 

Security Testing & Vulnerability Management 

  • Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using approved tools (e.g., CodeQL, Dependabot,, OWASP ZAP).  

  • Perform manual and automated code reviews to identify vulnerabilities and ensure remediation through code fixes or configuration changes.  

  • Maintain accurate mapping of applications to GitHub repositories to support vulnerability tracking and reporting.  

Advanced Software Analysis & Trust Establishment  

  • Perform security analysis of third-party software, including both source code review and compiled binary analysis where source is not available. 

  • Conduct binary decomposition and reverse engineering techniques, as appropriate, to evaluate software behavior and identify embedded risks. 

  • Support the establishment and execution of a software trust and reputation framework, enabling secure decision-making for application onboarding and whitelisting within the enterprise environment. 

  • Analyze open-source and GitHub-hosted code, including dependencies and contribution risk. 

  • Partner with AppSec leadership to support application security activities and formalize secure software approval processes. 

API & Web Application Security 

  • Conduct API security assessments and integrate monitoring tools to protect application endpoints.  

  • Support WAF policy management and application-layer threat monitoring. 

  • Threat Intelligence Integration 

  • Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software. 

  • Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications. 

Penetration Testing & Third-Party Risk 

  • Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software.  

  • Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications. 



Qualifications:
  • Proven experience in application security, DevSecOps, or software security analysis 

  • Strong hands-on expertise in: 

    • SAST/DAST tools and secure SDLC practices 

    • GitHub and open-source ecosystems  

    • GitHub Advanced Security  
       

  • Experience with third-party software risk analysis, software composition analysis (SCA), or reverse engineering / binary analysis 

  • Familiarity with software supply chain security and trust validation frameworks 

  • Experience integrating threat intelligence into security decision-making 

  • Strong understanding of secure SDLC, threat modeling (e.g., STRIDE), and vulnerability management.  

  • Experience coordinating penetration tests and working with third-party vendors.  

  • Strong communication and stakeholder engagement skills. 

 

Applicants must have legal authorization to work in the United States. We do not offer visa sponsorship at this time.  



Compensation:
The base pay range for this position is USD $120,000.00/Yr. - USD $180,000.00/Yr. Exact offers will be determined based on job-related knowledge, skills, experience, and location.

About East West Bank

Provides commercial and consumer banking services across US and Asia.

Similar jobs

Application Security Engineer roles near Dallas, Texas
2d
Save
Mark Applied
Hide
Engineering, Cybersecurity, Application Security Engineer, Vice President
Fort Worth, Texas, United States
OnsiteFull Time
TPG
TPGNASDAQ: TPG: Global alternative asset manager across private equity and credit.
3+ YOERequires 3+ years in application security, 7+ cumulative years in software development and information security, AI security expertise, identity protocols, SDLC, CI/CD, testing tools, cloud architectures, and code literacy.
Model Context Protocol (MCP), OWASP Top 10, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, MITRE ATLAS, OAuth 2.0, OpenID Connect, SAML, JWT, SDLC, DevOps, CI/CD, Kubernetes, SAST, DAST, SCA, Python, JavaScript/TypeScript, Java, C#, Go, CWE, CVSS, AWS, Azure, GCP, GitHub Actions, GitLab CI, Jenkins, GitHub Advanced Security, Dependabot, NIST Secure Software Development Framework (SSDF), OWASP SAMM, SLSA
2d
Save
Mark Applied
Hide
Specialist - CyberSecurity
Dallas or Fort Worth
$62-$66/hr HybridFull Time
LTIMindtree
LTIMindtreeNational Stock Exchange of India: LTIM: Global technology consulting and digital solutions.
3+ YOEBachelor's degree or equivalent experience; 3+ years in cybersecurity engineering, with cloud security, application vulnerabilities, security automation, compliance, and threat response experience.
PowerShell, Python, Java, JavaScript, C#, AWS, Microsoft Azure, Google Cloud, Electronic Medical Records (EMR)
1w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Global manufacturer and distributor of snacks and beverages.
3+ YOEBachelor's in CS/Engineering or related and 3+ years experience; application security, vulnerability management, cloud-native security, Python/Go, SAST/SCA/DAST, WAF, and CI/CD security experience.
Python, Go, AWS, Azure, GCP, SAST, SCA, DAST, WAF, OPA, HashiCorp Sentinel, OAuth, JWT, CDN
1w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Produces and distributes global snack and beverage products.
3+ YOEBachelor's in computer science/engineering or equivalent, 3+ years experience, hands-on application security and vulnerability management, cloud and tooling experience, Python or Go proficiency.
Python, Go, AWS, Azure, GCP, OPA, HashiCorp Sentinel, SAST, SCA, DAST, WAF, CDN
1w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Global food and beverage manufacturer and distributor.
3+ YOEBachelor's in CS/Engineering or equivalent,3+ years experience,proficiency with Python or Go,experience with SAST/SCA/DAST,WAF,policy-as-code (OPA/Sentinel),cloud security (AWS/Azure/GCP),and vulnerability management.
Python, Go, AWS, Azure, GCP, SAST, SCA, DAST, WAF, OPA, HashiCorp Sentinel, OAuth, JWT
2w
Save
Mark Applied
Hide
Senior Application Security Engineer
Malvern or Charlotte or Plano or Dallas
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
Requires a related undergraduate degree or equivalent experience, strong DAST deployment and CI/CD integration experience, application security expertise, and familiarity with NIST, OWASP, and MITRE.
DAST, CI/CD, SAST, SCA, IAST, RASP, NIST, OWASP, MITRE
2w
Save
Mark Applied
Hide
Senior Application Security Engineer
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
Undergraduate degree or equivalent; strong experience with DAST and CI/CD integration; familiarity with SAST, SCA, IAST, RASP, secure SDLC, and standards such as NIST, OWASP, MITRE.
DAST, SAST, SCA, IAST, RASP, CI/CD, NIST, OWASP, MITRE
3w
Save
Mark Applied
Hide
Application Security Engineer – Software Composition Analysis (SCA)
Plano, Texas, United States
HybridFull Time
Zelis
Zelis: Providing healthcare payment and claims cost management solutions.
8+ YOE8+ years AppSec experience with SCA, integrating security tools into CI/CD, evaluating vulnerabilities, managing open-source license compliance, and guiding developers; strong Java/Python/C++/Ruby skills.
Synk, Black Duck, Mend, Veracode, Checkmarx ONE, Jenkins, GitHub Actions, GitLab CI, Artifactory, CI/CD, AI/LLM, Java, Python, C++, Ruby, npm, pip, Maven/Gradle, OWASP Top 10