Fragomen
Posted 4mo ago

Security Engineer - Application Security

Fragomen
Pittsburgh, Pennsylvania, United States
RemoteFull Time
Responsibilities
  • Build tooling
  • Triage findings
  • Collaborate developers
Requirements
  • 5+ years web app development
  • Secure SDLC, DAST/SAST experience
  • Strong communication
  • Knowledge of secure coding and threat modeling
Technical tools mentioned
DotNetPythonJavaDASTSASTCSSLPCASE

Job description

Job Description

Fragomen is seeking a Security Engineer – Application Security to join our talented Cyber Security team in our Technology Innovation Lab in Pittsburgh. 

Our industry-leading, immigration specific software and supporting infrastructure is undergoing tremendous transformation and security is on the critical path to success in that endeavor. A professional, who is passionate about security, capable of effecting change, and ready to build a strong AppSec program, is what we seek. You will be joining a small team of Security Engineers who make security a distinguishing factor in our technological offerings.  A successful candidate will help engineer solutions to secure software development, identify threats and mitigate vulnerabilities throughout our environment.

What an Application Security Engineer does at Fragomen:

  • Build, deploy and maintain tooling to validate and track security controls in and around our code
  • Work closely with application development and infrastructure architectural teams to create code which is secure by design and default
  • Triage programmatic source code findings and automate penetration testing to decrease potential introduction of vulnerabilities
  • Lead and collaborate with developers on secure coding techniques and threat modeling
  • Contribute to vulnerability detection and remediation of technological offerings
  • Deploy developed or OTS security applications to support our efforts
  • Participate in a cross-functional response to cyber security incidents
  • Work closely the security team to establish prevention, detection and mitigation techniques
  • Support the scoping and rules of engagement of our penetration testing regime

Let’s talk if you have the following experience, knowledge, skills and education:

  • A passionate team player who builds knowledge and solves complex problems
  • 5+ years of web application development (.net, python, java, etc.)
  • Secure SDLC (Software Development Life Cycle), DAST (Dynamic Application Security Testing), and SAST (Static Application Security Testing) experience
  • Demonstrated understanding of web application penetration testing, secure coding and source code analysis
  • Strong, professional communication skills that maintain under pressure

These things are great, but not required:

  • Experience in developing highly automated detection and triage tools
  • Deep understanding of cyber security techniques
  • Technical certification demonstrating technical prowess in secure software development e.g. Certified Secure Software Lifecycle Professional (CSSLP), or Certified Application Security Engineer (CASE) or similar
  • BA degree in a related field or a combination of related experience is a must

All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position’s location, and conducting a comprehensive background check, where permitted by local regulations. We use limited AI‑assisted tools for administrative screening purposes only - never for decision‑making. All hiring decisions are made by people. Applicants may have rights to information and explanations regarding the use of such tools, or request human review, as required by applicable regional laws.

About Fragomen

Provides global immigration legal services and mobility solutions.

Similar jobs

Security Engineer roles near Pittsburgh, Pennsylvania
1w
Save
Mark Applied
Hide
Principal Security Engineer - AI Data Protection
Pittsburgh or Cleveland
$150k-$190k/yr OnsiteFull Time
Citizens Financial Group
Citizens Financial GroupNYSE: CFG: Provides retail, commercial, and private banking services to customers.
12+ YOE12+ years in cybersecurity or infrastructure engineering, 8+ years with enterprise security technologies, 5+ years with enterprise browsers or browser-based DLP, a bachelor's degree, and CISSP, CCSP, CISM, or comparable certification.
Island, Palo Alto Prisma Browser, Chrome Enterprise Premium, Microsoft Edge for Business, Menlo Security, Microsoft Purview DLP, Netskope DLP, Symantec DLP, Forcepoint DLP, Digital Guardian, Microsoft Intune, MECM/SCCM, Tanium, Jamf, Entra ID, Active Directory, Okta, CyberArk, Ping Identity, Microsoft Defender XDR, CrowdStrike, Splunk, Microsoft Sentinel, Zscaler, Palo Alto, Cisco Secure Access, PowerShell, Python, REST APIs, Microsoft Graph, Git, Azure DevOps, GitHub, Terraform, DNS, TLS/HTTPS, SWG, CASB, SASE, ZTNA, VPN
2w
Save
Mark Applied
Hide
Senior Security Engineer
Austin or Boston or Charleston or Charlotte or Chicago or Dallas or Durham or Harrisburg or Houston or Irvine or Kansas City or Los Angeles or Miami or Nashville or New York or Newark or Palo Alto or Pittsburgh or Portland or Raleigh or San Francisco or Seattle or Washington or Wilmington
$112k-$209k/yr HybridFull Time
K&L Gates
K&L Gates: Global law firm providing comprehensive legal and regulatory counsel.
7+ YOE7+ years cybersecurity/security engineering experience; expertise in cloud and hybrid security, DevSecOps, detection engineering, automation, incident response; Bachelor\u0002s or equivalent; relevant certifications preferred.
PowerShell, Python, REST APIs, Microsoft Graph, Azure, Microsoft Defender, Sentinel, Entra ID, Purview, Splunk, CrowdStrike, SIEM, EDR/XDR, MITRE ATT&CK
2w
Save
Mark Applied
Hide
Security Engineer
Pittsburgh or Pennsylvania
RemoteFull Time
McNees Wallace & Nurick
McNees Wallace & Nurick: Provides comprehensive legal counsel and advocacy services.
5+ YOE5+ years in cybersecurity with experience in SIEM, EDR, firewalls, IDS/IPS, Azure, identity and access management, incident response, vulnerability management, and security frameworks; bachelor's degree or equivalent.
Azure, SIEM, EDR, IDS/IPS, PowerShell, Python, SAML, OAuth, LDAP, NIST CSF, CIS Controls, ISO 27001, SOC 2
1mo
Save
Mark Applied
Hide
Corporate Security Engineering – Lead Engineer Role
Pittsburgh or Lake Mary
HybridFull Time
BNY
BNYNYSE: BK: Global institution managing and servicing financial assets worldwide.
5+ YOE3+ Mgmt5+ years physical security engineering with 3+ years leading teams; Genetec expertise; experience migrating PACS/CCTV; Windows/Linux administration; SQL, PowerShell, Python; networking and cybersecurity familiarity.
Genetec, C-CURE, Victor, Windows, Linux, SQL, PowerShell, Python, SIEM
2mo
Save
Mark Applied
Hide
Senior Security Engineer
Cleveland or Pittsburgh or Dallas or Pennsylvania
$57k-$154k/yr OnsiteFull Time
CGI
CGINYSE: GIB: Provides information technology and business consulting services.
6+ YOERequires 6+ years of enterprise security engineering or operations, vulnerability remediation, access and identity controls, container and application security, ITSM, and banking or financial services experience.
CyberArk, Tanium, Sysdig, SecurityCenter, Java, Spring Boot, OCP, Kubernetes, Jira, Confluence, CISA KEV
4mo
Save
Mark Applied
Hide
Security Engineer 2 - Cyber Security
Uniontown or Ann Arbor or Cincinnati or Columbus or Defiance or Fairmont or Findlay or Fort Wayne or Frankfort or Huntington or Indianapolis or Ironton or New Albany or Parkersburg or Pittsburgh or Toledo or Wheeling or Youngstown or Chattanooga or Franklin or Knoxville
RemoteFull Time
WesBanco
WesBancoNasdaq: WSBC: Regional bank providing personal, business, and investment services.
4+ YOEBachelor's in Information Security or related (or equivalent) plus 4 years' related experience; professional knowledge of network protocols and at least three tech areas (networking, Windows, security products, virtualization, cloud); change management experience.
Citrix, VMware, Nutanix, Azure, AWS, TCP/IP, SIEM, NIST, CIS, Microsoft, IPS, IDS, firewalls
1d
Save
Mark Applied
Hide
Info Security Engineer I (20103)
Pittsburgh, Pennsylvania, United States
HybridFull Time
Duquesne Light Company
Duquesne Light Company: Provides electric energy transmission and distribution services in Pennsylvania.
7+ YOEBachelor's degree or equivalent experience and 7+ years in cybersecurity engineering, security operations, or compliance-focused security. Requires SIEM, Splunk, and configuration/file integrity monitoring experience.
Security Information and Event Management (SIEM), Splunk, Tripwire Enterprise, NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, IEC 62443
5d
Save
Mark Applied
Hide
Readiness, Response & Recovery Security AI Developer
United States or Albany or Arlington or Atlanta or Austin or Beaverton or Bentonville or Boston or Carmel or Charlotte or Chicago or Cincinnati or Cleveland or Columbus or Culver City or Denver or Des Moines or Detroit or Hartford or Houston or Irving or Kirkland or Miami or Milwaukee or Minneapolis or Morristown or Mountain View or Nashville or New York City or Oklahoma City or Overland Park or Philadelphia or Pittsburgh or Raleigh or Redmond or Sacramento or San Diego or San Francisco or Scottsdale or Seattle or St. Louis or St. Petersburg or Walnut Creek
$59k-$206k/yr FieldFull Time
Accenture
AccentureNYSE: ACN: Global professional services firm providing consulting and technology solutions.
3+ YOERequires 3+ years cybersecurity and data development, 4+ years client-facing consulting and tool building, 2+ years Azure, 4+ years Python, Power BI, Power Apps/Automate, SQL, or similar, and a relevant degree.
Python, Microsoft Power BI, Microsoft Azure, Power Apps, Power Automate, SQL, KQL, Sentinel Workbooks