Application Security Engineer

2 weeks ago


Las Vegas, United States IS3 Solutions Full time

Position Overview

The primary responsibility of the Application Security Engineer is to support technologies that enable the companies' cyber security goals and objectives, securing the confidentiality, integrity, and availability of software and computer information systems. The role will serve as a security engineer for software development, supporting technologies that facilitate the security of the software products and services. Additional key responsibilities of the role include; review of vulnerabilities identified by application security technologies and processes, providing true positive results to the appropriate software development teams, and coordination with those teams to support their triage and remediation efforts for identified, valid vulnerabilities. All duties are to be performed per Client's departmental policies, practices, and procedures.


Essential Duties & Responsibilities

• Act as a primary technical resource in the development of a comprehensive security program to support various Software Development Lifecycles (SDLCs) and ensure that software developed in this SDLC is free of security vulnerabilities.

• Manage application security program across multiple SDLCs.

• Ensure cybersecurity requirements are met before production release.

• Triage potential vulnerabilities identified by the application security program with the context of application and related business knowledge.

• Maintain understanding of core functionality of supported software and first-party applications.

• Review and understand code from both business logic and technical standpoints.

• Coordinate with developers to prioritize and remediate identified true positive vulnerabilities.

• Collaborate with software development and quality assurance teams to ensure code is free from security defects. • Communicate cybersecurity standards applicable to technology and coding workflows.

• Working with Application Security Engineers, optimize security with existing technologies and processes.

• Provide technical guidance to developers and engineers on cybersecurity best practices.

• Review performance of controls such as threat modeling, SCA, SAST, DAST, IAST, RASP, Secrets Scanning, Container Scanning, Misconfiguration Identification, Secure Code Review, CI/CD Pipeline Security, Deployment Environment Security.

• Coordinate with software development leadership, operations leadership, IT leadership, and cybersecurity leadership to integrate application security practices across departments.

• Actively seek ways to improve secure software development processes.


Additional Responsibilities:

• Develop and maintain security policies, standards, and guidelines.

• Conduct code analysis of first-party enterprise applications, through both manual and automation-enabled processes.

• Provide remediation guidance and recommendations to developers and administrators based on identified vulnerabilities and existing technology stack.

• Work with software development teams to prioritize and validate the urgency and mitigation of identified product vulnerabilities and security feature enhancement requests.

• Stay updated with the latest cybersecurity threats and trends and incorporate this knowledge into security architecture designs and practices.

• Conduct training and awareness programs to enhance the security posture of the organization. Participate in security audits and assist in regulatory compliance efforts.

• Work closely with IT operations and software development teams to ensure secure systems deployment and operations.

• Actively contribute to the organization's cybersecurity strategy and roadmap.


Minimum Qualifications

· Outstanding collaboration and communication skills.

•Any of the following combinations of education, professional experience, or both:

At least 2 years of experience in a relevant DevSecOps role and technical degree in computer / information science; or At least 4 years of experience in a relevant DevSecOps role; or At least 6 years of related field work experience, at least 1 year of which in a software development role, and at least 1 of which in a cyber security role and technical degree in computer / information science; or At least 8 years of relevant field experience, at least 1 year of which in a software development role, and at least 1 year of which in a cyber security role.

•Demonstrated experience working with technical and non-technical staff.

•Knowledge of application security, software development, and cyber security concepts.

•Basic knowledge of a broad range of IT, Security, Controls and Service Delivery standards and frameworks for example, International Standards Organization (ISO) 27001, IT Infrastructure Library (ITIL), Control Objectives for IT (CoBIT), and Capability Maturity Model Integration (CMMI).

•Experience with Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure or other cloud platforms, with experience in developing and implementing software.

•Experience developing software in various coding languages such as Java, C#, PHP, etc.

• Demonstrated knowledge of web applications, cyber security, and open-source technologies.

• Safety is an essential function of this job.

• Consistent and regular attendance is an essential function of this job.

•Ability to execute multiple projects and tasks under tight deadlines.

• Provide off-hours support on an infrequent but as needed basis. (Potential shifts may run 24/7 due to the needs of the business).

• Strong interpersonal skills with the ability to communicate effectively with guests and other Team Members of different backgrounds and levels of experience.

• Must be able to work varied shifts, including nights, weekends, and holidays.


Additional Experience Recommended

• Professional certification in multiple programming languages (C#, .NET, Java, etc.) recommended.

• Professional certifications in cyber security (CISSP, OSCP, etc.) recommended.

• Experience with CI/CD and pipeline tools such as Jenkins, Docker, Kubernetes, and others.

• Knowledge of cloud platforms and services, with experience in cloud security.

• Experience with automated software and security testing tools and techniques.

• Ability to stay updated with the latest industry trends and advancements in cybersecurity.

• Understanding of enterprise software development practices.

• Experience working with software development teams.

• Experience identifying cybersecurity vulnerabilities and weaknesses in software.

• Experience reading, writing, and auditing software in multiple programming languages.

• Strong familiarity with common vulnerabilities and attack vectors.

• Knowledge of common encryption technologies (AES, PGP, SSH, SSL, etc.).

• Knowledge of common authentication protocols (OpenID Connect, OAUTH, SAML, RADIUS, LDAP, KERBEROS, etc.).

• Previous work experience as an Application/Product Security Engineer or Software Developer. •Experience integrating security testing into an SDLC.

• Experience with incident response and handling methodologies.

• Experience with security technologies such as intrusion detection/prevention systems (IDS/IPS), firewalls, SIEM, etc.


Physical Requirements

Must be able to:

• Lift or carry 20 pounds, unassisted, in the performance of specific tasks, as assigned.

• Physically access all areas of the property and drive areas with or without reasonable accommodation.

• Maintain composure under pressure and consistently meet deadlines with internal and external customers and contacts.

• Ability to interact appropriately and effectively with guests, management, other team members, and outside contacts.

• Ability for prolonged periods of time to walk, stand, stretch, bend and kneel. •

Work in a fast-paced and busy environment.

• Work indoors and be exposed to various environmental factors such as, but not limited to, CRT, noise, dust, and cigarette smoke.



  • Las Vegas, United States Servsys Corporation Full time

    Position OverviewThe primary responsibility of the Application Security Engineer – Cyber Security is to support technologies that enable the companies’ cyber security goals and objectives, securing the confidentiality, integrity and availability of software and computer information systems. The role will serve as a security engineer for software...


  • Las Vegas, United States The Boring Company Full time

    The Boring Company was founded to solve the problem of soul-destroying traffic by creating an underground network of tunnels. Today, we are creating the technology to increase tunneling speed and decrease costs by a factor of 10 or more with the ultimate goal of making Hyperloop adoption viable and enabling rapid transit across densely populated regions. ...

  • Security Technician

    2 weeks ago


    Las Vegas, United States Security 101 Full time

    Job DescriptionJob DescriptionJob Title: Security TechnicianCompany: Security 101Location: Las Vegas, NVJob Summary:Security 101 – Las Vegas is now recruiting an experienced Security technician with the ability to install and service access control, intrusion, and video systems. Take advantage of the opportunity to learn, increase your value and industry...


  • Las Vegas, United States ServiceNow Full time

    ServiceNow ServiceNow allows employees to work the way they want to, not how software dictates they have to. And customers can get what they need, when they need it. View company page At ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can’t wait, and we innovate in ways no one...


  • Las Vegas, United States VBG (Veteran Benefits Guide) Full time

    Job DescriptionJob DescriptionDescription:Who we are:VBG (Veteran Benefits Guide) was founded by a former active-duty United States Marine with the goal of ensuring that Veterans receive the correct disability benefits in a timely manner. VBG has successfully guided over 35,000 Veterans by submitting their VA (Veteran Affairs) disability claims, resulting in...

  • Engineer I

    1 month ago


    Las Vegas, United States Nevada National Security Site Full time

    Overview Mission Support and Test Services, LLC (MSTS) manages and operates the Nevada National Security Site (NNSS) for the . National Nuclear Security Administration (NNSA). Our MISSION is to help ensure the security of the United States and its allies by providing high-hazard experimentation and incident response capabilities through operations,...


  • Las Vegas, United States Veteran Benefits Guide Full time $117,000

    Who we are: VBG (Veteran Benefits Guide) was founded by a former active-duty United States Marine with the goal of ensuring that Veterans receive the correct disability benefits in a timely manner. VBG has successfully guided over 35,000 Veterans by submitting their VA (Veteran Affairs) disability claims, resulting in increased compensation benefits for...


  • Las Vegas, United States Arrow International Full time

    Description Arrow International is the world's largest manufacturer and supplier of charitable gaming products and solutions. We produce and distribute a wide array of products including consumables (pull tab tickets, bingo paper and ink, etc.) as well as world class, state-of-the-art, electronic gaming products. Our products are sold, installed, and...

  • Security Engineer

    2 weeks ago


    Las Vegas, United States Insight Global Full time

    Role: Security EngineerPR: $50 -70/hrLocation: hybrid phx azContract: 12 month contract (possible extensions)* 2-4 Years of professional experience as a Security Engineer or equivalent position.* Professional experience utilizing Palo Alto.* Professional Experience working with Cisco technologies.* In-depth experience with Firewall technologies and best...

  • Armed Security

    1 month ago


    Las Vegas, United States Protect-US Private Security Full time

    Job DescriptionJob DescriptionDescriptionProtect-US is hiring for an Armed Security Guard in the Las Vegas, Nevada area !We are looking for an experienced and reliable Armed Security Officer to join our company. Armed security officers are responsible for protecting designated people and places and should report noteworthy incidents to the company as they...


  • Las Vegas, United States Planet Technologies Full time

    Planet Technologies, the Nation’s leading Microsoft services provider, is looking for a highly motivated individual to join our growing team as an Information Systems Security Engineer. In this role, you will be supporting impactful projects that make a difference for our country. The Information Systems Security Engineer has primary responsibilities to...


  • Las Vegas, United States Silver State Schools Credit Union Full time

    Network Security Engineer Full Time (40 Hours)Monday - Friday Headquarters 630 Trade Center DriveLas Vegas, NV 89119 PURPOSE: The primary purpose of this position is to assist Silver State Schools Credit Union to live out its Mission, "Excellent Member Service and Financial Solutions - For Life," by providing outstanding service to both members and internal...


  • Las Vegas, United States MacStadium Full time

    This is a hybrid role that requires to be onsite. You must be located close to one of our data centers in Las Vegas, NV or Atlanta, GA to be considered for the role. Meet MacStadium. We build cloud solutions to simplify Mac for business. We actively participate in and influence the Apple ecosystem in a cool way and have been a part of it since day one....


  • Las Vegas, United States Saransh Full time

    Role: Infrastructure Security Engineer Location: Las Vegas, NV (Onsite from Day 1) Contract Job Description: A minimum of 5+ years experience working in site-reliability engineering, cloud security, or system engineering. A minimum of 5+ years experience working with incident response. Good written and verbal communication skills. Experience using log...


  • Las Vegas, United States Silver State Schools Credit Union Full time

    Network Security Engineer Full Time (40 Hours) Monday - Friday Headquarters 630 Trade Center Drive Las Vegas, NV 89119 PURPOSE: The primary purpose of this position is to assist Silver State Schools Credit Union to live out its Mission, "Excellent Member Service and Financial Solutions - For Life," by providing outstanding service to both members and...


  • Las Vegas, United States Marksman Security Corporation Full time

    Job DescriptionJob DescriptionNow Hiring an Unarmed Security Officer! **Multiple Shifts Available**Weekend and holiday availability is required The ideal candidate will have previous experience in security or customer service fields. State training and licensing assistance may be available for qualified candidates. Benefits: Insurance: medical, vision...


  • Las Vegas, United States Link Technologies Full time

    JOB-6937 Cyber Security Engineer II (C) Las Vegas, NV Contract Link Technologies (LinkTechConsulting.com), a Las Vegas based IT consulting firm, is currently seeking a Cyber Security Engineer II to join our team. Employer asks for I-9 information. QUALIFICATIONS Experience with installation of network switches AND network taps is REQUIRED Knowledgeable...


  • Las Vegas, United States MacStadium Full time

    This is a hybrid role that requires to be onsite. You must be located close to one of our data centers in Las Vegas, NV or Atlanta, GA to be considered for the role.  Meet MacStadium. We build cloud solutions to simplify Mac for business. We actively participate in and influence the Apple ecosystem in a cool way and have been a part of it since day one....


  • Las Vegas, United States MacStadium Full time

    Job DescriptionJob DescriptionThis is a hybrid role that requires to be onsite. You must be located close to one of our data centers in Las Vegas, NV or Atlanta, GA to be considered for the role. Meet MacStadium. We build cloud solutions to simplify Mac for business. We actively participate in and influence the Apple ecosystem in a cool way and have been a...


  • Las Vegas, United States MacStadium Full time

    This is a hybrid role that requires to be onsite. You must be located close to one of our data centers in Las Vegas, NV or Atlanta, GA to be considered for the role. Meet MacStadium. We build cloud solutions to simplify Mac for business. We actively participate in and influence the Apple ecosystem in a cool way and have been a part of it since day one....