{"21349308":{"jobPath":"/jobs/21349308/senior-video-producer","source":"naylor","job":"21349308","jobTitle":"Senior Video Producer"},"21343500":{"jobPath":"/jobs/21343500/interventional-radiologist","source":"naylor","job":"21343500","jobTitle":"Interventional Radiologist"},"21348834":{"jobPath":"/jobs/21348834/work-from-anywhere-100-remote-dayshift-radiology-opportunity-in-indiana-competitive-salary","source":"naylor","job":"21348834","jobTitle":"WORK FROM ANYWHERE!! 100% REMOTE DAYSHIFT RADIOLOGY OPPORTUNITY IN INDIANA * Competitive Salary"},"21266386":{"jobPath":"/jobs/21266386/2-full-professors-of-business-administration-and-information-systems","source":"naylor","job":"21266386","jobTitle":"2 Full Professors of Business Administration and Information Systems"},"21352216":{"jobPath":"/jobs/21352216/postdoctoral-research-associate-cell-biology","source":"naylor","job":"21352216","jobTitle":"Postdoctoral Research Associate - Cell Biology"},"21349332":{"jobPath":"/jobs/21349332/program-manager-medical-informatics-hybrid","source":"naylor","job":"21349332","jobTitle":"Program Manager - Medical Informatics (Hybrid)"},"21348863":{"jobPath":"/jobs/21348863/work-from-anywhere-100-remote-dayshift-radiology-opportunity-in-indiana-competitive-salary","source":"naylor","job":"21348863","jobTitle":"WORK FROM ANYWHERE!! 100% REMOTE DAYSHIFT RADIOLOGY OPPORTUNITY IN INDIANA * Competitive Salary"},"21329681":{"jobPath":"/jobs/21329681/director-clinical-bioinformatics","source":"naylor","job":"21329681","jobTitle":"Director, Clinical Bioinformatics "},"21351949":{"jobPath":"/jobs/21351949/postdoctoral-research-associate-or-more-senior-researcher","source":"naylor","job":"21351949","jobTitle":"Postdoctoral Research Associate or More Senior Researcher"},"21349151":{"jobPath":"/jobs/21349151/postdoctoral-research-scholar-arizona-water-chatbot-arizona-state-university","source":"naylor","job":"21349151","jobTitle":"Postdoctoral Research Scholar - Arizona Water Chatbot - Arizona State University"},"21313328":{"jobPath":"/jobs/21313328/canada-excellence-research-chairs-multiple-disciplines","source":"naylor","job":"21313328","jobTitle":"Canada Excellence Research Chairs – Multiple Disciplines "},"21349592":{"jobPath":"/jobs/21349592/director-for-ai-systems-management-programs-at-heinz-college","source":"naylor","job":"21349592","jobTitle":"Director for AI Systems Management Programs at Heinz College"},"21351919":{"jobPath":"/jobs/21351919/postdoctoral-research-associate-program-on-science-and-global-security","source":"naylor","job":"21351919","jobTitle":"Postdoctoral Research Associate/Program on Science and Global Security"},"21352471":{"jobPath":"/jobs/21352471/senior-cloud-data-developer","source":"naylor","job":"21352471","jobTitle":"Senior Cloud Data Developer"},"21350075":{"jobPath":"/jobs/21350075/program-manager-digital-scheduling-and-access-remote","source":"naylor","job":"21350075","jobTitle":"Program Manager, Digital Scheduling and Access - Remote"},"21351777":{"jobPath":"/jobs/21351777/visiting-assistant-professor-of-computer-science","source":"naylor","job":"21351777","jobTitle":"Visiting Assistant Professor of Computer Science"},"21349426":{"jobPath":"/jobs/21349426/cancer-ai-alliance-caia-operations-director","source":"naylor","job":"21349426","jobTitle":"Cancer AI Alliance (CAIA) Operations Director"},"21351937":{"jobPath":"/jobs/21351937/postdoctoral-research-associate-construction-robotics","source":"naylor","job":"21351937","jobTitle":"Postdoctoral Research Associate (Construction Robotics)"},"21266409":{"jobPath":"/jobs/21266409/senior-application-security-engineer","source":"naylor","job":"21266409","jobTitle":"Senior Application Security Engineer"},"21351916":{"jobPath":"/jobs/21351916/postdoctoral-research-associate-ai-machine-learning-for-mass-spectrometry","source":"naylor","job":"21351916","jobTitle":"Postdoctoral Research Associate - AI/Machine Learning for Mass Spectrometry"},"21277776":{"jobPath":"/jobs/21277776/postdoctoral-project-staff-member","source":"naylor","job":"21277776","jobTitle":"postdoctoral Project Staff Member"},"21351856":{"jobPath":"/jobs/21351856/postdoc-research-associate-applied-linguistics-and-artificial-intelligence-ai","source":"naylor","job":"21351856","jobTitle":"Postdoc Research Associate - Applied Linguistics and Artificial Intelligence (AI)"},"21351855":{"jobPath":"/jobs/21351855/entrepreneur-in-residence-226-128-147-isu-startup-factory","source":"naylor","job":"21351855","jobTitle":"Entrepreneur-in-Residence â ISU Startup Factory"},"21351910":{"jobPath":"/jobs/21351910/multiple-tenure-line-faculty-positions-in-computing-25-26","source":"naylor","job":"21351910","jobTitle":"Multiple Tenure-Line Faculty Positions in Computing (25-26)"},"21351935":{"jobPath":"/jobs/21351935/postdoctoral-research-associate-generative-ai","source":"naylor","job":"21351935","jobTitle":"Postdoctoral Research Associate (Generative AI)"}}
Are you ready to elevate security practices to new heights? Our client is looking for a dynamicSenior Application Security Engineerwho will revolutionize our application security strategies. Thison-site roleis the perfect opportunity to collaborate with key stakeholders in Technology, Product, and Strategic Business Units to tackle the most pressing security challenges head-on.
As a Senior Application Security Engineer, you will spearhead the secure software development lifecycle, embedding cutting-edge security practices at every step of our DevOps pipelines and application security processes. Your expertise in maturity models like DSOMM (DevSecOps Maturity Model), CI/CD pipelines, and vulnerability management tools will be crucial in transforming our security landscape. Join forces with our engineering, DevOps, Product, and Technology teams to implement automated security controls, threat modeling, and risk mitigation strategies that will shape the future of our software development lifecycle.
Key Responsibilities
DevSecOps & Maturity Measurement Implementation:
Assess, report, and assist with improving application security and DevSecOps Maturity, utilizing a measurement framework such as DSOMM or BSIMM, across the organization.
Define and implement security policies, standards, and best practices for DevOps, CI/CD pipelines, and cloud security.
Work with development and DevOps teams to integrate automated security testing (SAST, DAST, SCA, IaC security scanning, etc.) into pipelines.
Establish security gates in CI/CD workflows to prevent deployment of vulnerable code.
Application Security & Code Vulnerabilities:
Perform code reviews, static/dynamic security testing (SAST/DAST), and secure coding guidance to developers.
Identify and remediate vulnerabilities in application code, libraries, containers, and infrastructure as code (IaC).
Develop and enforce secure coding standards in alignment with OWASP, NIST, and other frameworks.
Conduct threat modeling and security architecture reviews for applications and services. For example, assist application teams with developing accurate data flow diagrams and developing appropriate identity management solutions.
Manage and mature Bot Management services for all applications. Assist with WAF management and maturity.
Improve secrets management and API security.
Vulnerability Management & Risk Reduction:
Manage and mature enterprise-wide Bug Bounty program (e.g. BugCrowd, HackerOne)
Track, assess, and coordinate the remediation of vulnerabilities across the application, infrastructure, and cloud environments.
Develop risk-based vulnerability management workflows and collaborate with engineering teams to drive fixes.
Monitor security dashboards and metrics, ensuring vulnerabilities are patched in alignment with SLAs.
Security CI/CD Automation & Tooling:
Implement security automation using APIs, scripts, and cloud-native security controls.
Work with DevOps engineers to integrate security tooling (like SemGrep, Snyk, Cycode) or within Jenkins, GitHub, GitLab CI/CD, or AWS DevOps.
Automate security findings triage, reporting, and prioritization processes.
Security Awareness & Collaboration:
Train and mentor developers on secure coding, threat modeling, DevSecOps, and vulnerability management best practices.
Collaborate with security operations, incident response, and compliance teams on security initiatives.
Participate in security assessments, penetration testing, and security incident investigations.
Qualifications & Experience
Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, or a related field OR a minimum of 8 years’ experience in lieu of a degree. Master’s Degree in Cybersecurity, Information Technology, Business Administration, or a related field is preferred.
5+ years of experience in application security, DevSecOps, and security engineering.
Strong knowledge of secure coding principles and frameworks such as OWASP Top 10, SANS CWE Top 25.
Experience with integrating security solutions within CI/CD pipelines.
High proficiency in at least one programming language (Python, Java, Go, PHP, JavaScript, etc.).
Experience with vulnerability management and tools (Tenable, Qualys, or Rapid7).
Experience with web app penetration testing tooling (BurpSuite, Acunetix, or Zap).
Experience with implementing maturity measurement frameworks such as DSOMM (DevSecOps Maturity Model) or BSIMM (Building Security in Maturity Model) in an enterprise setting.
Familiarity with cloud security best practices (AWS, Azure/Entra, GCP).
Familiarity with Bot Management tooling (DataDome, HUMAN, CloudFlare, or reCAPTCHA) and client-side monitoring tooling (FullStory, Source Defense, or Reflectiz).
Familiarity with AI machine learning or LLM usage within security tooling.
Security certifications like CISSP, OSCP, GCPN, GCSA, AWS Security Specialty, or CSSLP is preferred.
Experience with Infrastructure as Code (Terraform, CloudFormation, Kubernetes security) is preferred.
Knowledge of compliance frameworks such as NIST, ISO 27001, SOC 2, PCI DSS, and PCI Card Production is preferred.
Technical Aptitude: Ability to understand and communicate best-practice system architectures, data flows, and security controls within modern web applications and cloud (SaaS/PaaS, IaaS).
Communication: Excellent verbal and written communication skills, with the ability to communicate complex security concepts to technical and non-technical stakeholders.
Strategic Thinking: Ability to develop and implement strategic cybersecurity plans that align with business goals and product advancements.
HDJ + Associates is consistently named one of the top recruiting firms in the Pittsburgh area. We are a professional employment and search solutions company focused on recruiting the best possible talent available in today’s demanding market place.
Our clients often tell us that finding the right candidates to join their company is one of the most difficult tasks on their already overburdened task list.
Likewise, our candidates often tell us that finding the right position in today’s crowded market place is frustrating and overwhelming.
Let HDJ + Associates take the pressure out of the recruiting process for both candidates and employers. We will hit the employment bullseye each time streamlining the recruiting process to success.