Lead Application Security Engineer

2 months ago


Plano, United States Fortune 500 Companies Full time

Job Description


Location- Plano, TX

Work mode- Hybrid


*No sponsorship is provided*


Overview

Global Application Security Program is responsible for integrating automated security testing into both CI/CD pipelines and continuous monitoring to identify and manage security risks in applications. Our mission is to make security risks visible and actionable to the business and ensure that vulnerabilities are addressed promptly and effectively. This role involves leading a team of application security engineers, driving the integration of automated security tools into CI/CD pipelines, and developing innovative scalable full-stack solutions, middleware, and automation solutions. This role will be responsible for translating strategic application security objectives into actionable plans, providing expert guidance on vulnerability triage and remediation, and fostering a culture of proactive security across the organization. This role’s leadership will be key in defining plans, developing metrics and KPIs, and continuously improving our security practices to ensure the highest standards of protection for our applications.


Responsibilities

  • Drive the development and execution of the application security strategy by translating high-level objectives into actionable plans. Lead and inspire the team to achieve these goals, ensuring alignment with overall organizational security initiatives and fostering a culture of proactive security.
  • Develop technical documentation (i.e. system design, architecture diagrams, data flows, functional specifications).
  • Contribute to defining the future state of cybersecurity within the organization by conducting technical assessments between current state and the desired state across security tools and services.
  • Develop program metrics, continuously measure progress and Impact and drive improvements.
  • Collaborate with the Senior leadership and cross-functional teams including DevOps, development teams, security operations, data and analytics, enterprise architecture, Platform team, and sector functions.
  • Implement and manage automated security tools within CI/CD pipelines. Ensure seamless integration and operation to enhance security posture.
  • Integrate and operate a centralized findings management system to efficiently manage and track security vulnerabilities and remediation efforts.
  • Define and implement a strategy to ensure automated security tools are configured to operate in an optimal fashion. Establish and monitor key performance indicators (KPIs) to constantly measure effectiveness and make necessary adjustments for continuous improvement.
  • Develop and maintain green field automation solutions and full stack applications to support and enhance application security.
  • Provide expert triage and remediation guidance for security vulnerabilities. Assist and mentor team members and other engineering teams in understanding and addressing security issues.
  • Foster a collaborative environment, promote knowledge sharing, and mentor junior engineers to build a strong, skilled security team.
  • Continuously research and raise novel concepts to improve the application security posture of the business. Stay updated with the latest security trends, tools, and practices.
  • Execute projects, objectives, and deliverables in alignment with the team's vision, mission, and goals.
  • Create and deliver training sessions; mentor junior team members; and engage in knowledge transfer sessions, technical design reviews, security reviews, and business review meetings.


Differentiating Behaviors

  • Demonstrated ability to innovate and drive continuous improvement.
  • Strong mentorship and coaching capabilities.
  • Ability to handle high-pressure situations with a calm and methodical approach.
  • Ability to lead globally dispersed teams to achieve a unified outcome.
  • Experience driving large-scale risk reduction initiatives across Fortune 500 organizations.
  • Ability to weigh the relative costs/benefits/trade-offs of potential actions and identify the best resolution.
  • Information Security certifications such as CISSP, OSCP, GPEN, GWAPT, GXPN, GSE are a plus.
  • Ability to organize tasks, manage time, and prioritize actions to meet business needs.


Qualifications

Years of experience

  • 7+ years in software development; or master’s degree in computer science/engineering or related cyber field, and 5 years of relevant experience.
  • 2+ years in a leadership or senior role within application security.


Mandatory Technical Skills

  • Proficient in at least one programming language (Java, C#, Go) and scripting language (Python, bash, PowerShell).
  • Proficient in at least one database management system and query language (MSSQL, PostgreSQL, etc.)
  • Proficient in developing full-stack applications and rapidly prototyping solutions to support automated data collection, aggregation, and analysis.
  • Proficient in integrating and managing automated security tools within CI/CD pipelines.
  • Proficient in application security vulnerabilities and remediation techniques (e.g., OWASP Top Ten).
  • Proficient in developing and monitoring metrics and KPIs.
  • Experience with application security testing tools (Synopsys, OpenText Fortify, Invicti, Snyk, Semgrep, etc.)
  • Experience with modern CI/CD tools and practices, and their integration into the development lifecycle (Jenkins, Azure DevOps, GitHub Enterprise, Circle CI, Heroku, etc.)
  • Experience with public cloud services (Azure, AWS, Alibaba).
  • Experience with Centralized Findings Management Systems (e.g., ServiceNow VR/AVR, PlexTrac, DefectDojo, ThreatFix).
  • Experience with implementing and managing Web Application Firewalls (Fortinet FortiWeb, Imperva Cloud WAF, Cloudflare WAF, Akamai Kona, MS Azure WAF, AWS WAF, etc.) is a plus.
  • Experience with CMS application security (Wordpress, Drupal, Joomla, Elementor, OpenText TeamSite, Concrete CMS, etc.) is a plus.
  • Experience with generative AI technologies is a plus.


Non-technical Skills

  • Excellent leadership and team management skills.
  • Strong communication skills, both verbal and written.
  • Ability to translate strategic vision into actionable plans.
  • High level of integrity and ethical standards.
  • Ability to lead and mentor junior engineers.
  • Excellent problem-solving, analytical, and critical thinking skills.
  • Demonstrated ability to autonomously make high-judgment decisions and take calculated risks.
  • A proactive and positive team player who is impact-focused, driven, curious, analytical, and a self-starter.
  • Ability to establish trust relationships and influence others to positively impact the security posture and the business.
  • Flexible and adaptive to support a dynamic and global environment with diverse stakeholders and ambiguity.
  • Solid customer orientation with excellent oral and written communication skills in English.
  • Must be able to operate extremely well under pressure.



  • Plano, United States Fortune 500 Companies Full time

    Job DescriptionLocation- Plano, TXWork mode- Hybrid*No sponsorship is provided*OverviewGlobal Application Security Program is responsible for integrating automated security testing into both CI/CD pipelines and continuous monitoring to identify and manage security risks in applications. Our mission is to make security risks visible and actionable to the...


  • Plano, Texas, United States Fortune 500 Companies Full time

    Job DescriptionJob SummaryWe are seeking a highly skilled and experienced Lead Application Security Architect to join our team at a Fortune 500 company. As a key member of our Global Application Security Program, you will be responsible for leading a team of application security engineers and driving the integration of automated security tools into CI/CD...


  • Plano, United States Motion Recruitment Full time

    Our client, a food and beverage company, is looking for an Application Security Engineer to join their team on a 6 month contract in Plano, TX.This role can pay $80-90/hour on a W-2 Contract.This person will join a team that is responsible for integrating automated security testing into both CI/CD pipelines and continuous monitoring to identify and manage...


  • Plano, United States Fortune 500 Companies Full time

    Job DescriptionOverviewGlobal Application Security Program is responsible for integrating automated security testing into both CI/CD pipelines and continuous monitoring to identify and manage security risks in applications. Our mission is to make security risks visible and actionable to the business and ensure that vulnerabilities are addressed promptly and...


  • Plano, Texas, United States Motion Recruitment Full time

    Job Description**Job Title:** Senior Application Security Engineer**Job Type:** Contract**Location:** Plano, TX**Job Description:OverviewMotion Recruitment is seeking a highly skilled Senior Application Security Engineer to join our client's team on a 6-month contract. As a key member of the security team, you will be responsible for driving the development...


  • Plano, United States Caresoft Inc. Full time

    Job DescriptionJob DescriptionTitle: Sr. Application Security Engineer Location: Plano, Texas (Hybrid)Durartion: Long Term Job Id : (028824)DescriptionSummary: As a Senior Application Security Engineer, you will play a critical role in ensuring the security of applications and infrastructure for connected services.This role is responsible for designing,...


  • Plano, Texas, United States Siemens Digital Industries Software Full time

    Job Family: Internal ServicesEmployer: Siemens Digital Industries SoftwarePosition: Lead Applications Engineer [MULTIPLE POSITIONS]Location: Remote and various locations throughout the U.S.Employment Type: Full TimeKey Responsibilities: - Implement and deploy innovative software and hardware solutions tailored for clients, guiding them through the design...


  • Plano, Texas, United States Toyota Tsusho Systems Full time

    Job OverviewIn the capacity of a Principal Engineer within the Product Security Incident Response Team (PSIRT), you will be tasked with managing and addressing security incidents that pertain to our products and services. The primary objective of this position is to detect, evaluate, prioritize, and respond to vulnerabilities or threats that could compromise...


  • Plano, Texas, United States Toyota Tsusho Systems Full time

    Job OverviewThe Principal Engineer role within Toyota Tsusho Systems is a pivotal position focused on managing and responding to security incidents that affect our products and services. This position is crucial for identifying, evaluating, prioritizing, and addressing vulnerabilities or threats that could compromise the security of our offerings. By...


  • Plano, Texas, United States Toyota Tsusho Systems Full time

    Job OverviewAs a key member of the Product Security Incident Response Team (PSIRT), this position is responsible for managing and addressing security incidents associated with the organization's products and services. The primary objective of this role is to detect, evaluate, prioritize, and respond to vulnerabilities or threats that could compromise the...


  • Plano, Texas, United States Fortune 500 Companies Full time

    Job DescriptionJob SummaryWe are seeking a highly skilled and experienced Lead Application Security Engineer to join our team at a Fortune 500 company. As a key member of our Global Application Security Program, you will be responsible for leading a team of application security engineers and driving the integration of automated security tools into CI/CD...


  • Plano, Texas, United States TEK NINJAS Full time

    Exciting Opportunity: Lead Mobile Application EngineerCompany: TEK NINJASPosition Type: Contract (Hybrid)Contract Length: 6+ months with potential for extensionExperience Level: 6+ yearsEssential Skills:Kotlin programmingJetpack Compose frameworkDevelopment of native applicationsAndroid Software Development Kit (SDK)RESTful API integrationVersion control...


  • Plano, Texas, United States Fortune 500 Companies Full time

    Position OverviewLocation: RemoteWork Arrangement: HybridNote: Sponsorship is not available for this position.Role SummaryThe Global Application Security Program is dedicated to embedding automated security assessments within CI/CD workflows and ongoing monitoring to pinpoint and mitigate security threats in software applications. Our objective is to render...


  • Plano, Texas, United States TEEMA Group Full time

    Job OverviewPosition: Lead Software Engineer - Security SolutionsWork Arrangement: HybridCompensation: $60 per hourContract Type: This is a contract role with potential for extension based on performance and project requirements.Position Summary: The TEEMA Group is seeking a highly skilled Lead Software Engineer with a focus on Security Solutions. This...


  • Plano, United States JPMorgan Chase & Co. Full time

    Assume a vital position as a key member of a high-performing team that delivers infrastructure and performance excellence. Your role will be instrumental in shaping the future at one of the world's largest and most influential companies. As a Lead Infrastructure Engineer at JPMorgan Chase within the Infrastructure Platform Network Product Line, you apply...


  • Plano, Texas, United States Vital Tech Solutions Full time

    Job OverviewPosition Title: Android Product Security EngineerWork Arrangement: HybridRole Summary:The Product Security Engineer will oversee comprehensive security evaluations with a particular emphasis on Android and iOS application security. The ideal candidate will be a technically adept, motivated, and proactive individual who is eager to learn, tackle...


  • Plano, Texas, United States Toyota Tsusho Systems Full time

    Overview: In the capacity of a Lead Application Security Specialist, you will be pivotal in safeguarding the integrity of applications and infrastructure for interconnected services. This position entails the design, execution, and upkeep of security measures to address recognized vulnerabilities, necessitating active engagement in application development...


  • Plano, United States Diverse Lynx Full time

    Skill - Kubernetes, Application Security Platform on AWS cloud. •Conducts requirements gathering and analysis to understand the domain of the software problem and/or functionality, the interfaces between hardware and software, and the overall software characteristics. •Consults with systems engineers and architects on developing IT standards for the...


  • Plano, Texas, United States Toyota Tsusho Systems Full time

    As a key member of the Product Security Incident Response Team (PSIRT), this position is responsible for managing and addressing security incidents that pertain to the organization's products and services. The primary objective of this role is to identify, evaluate, prioritize, and respond to vulnerabilities or threats that could affect the security of the...


  • Plano, Texas, United States APN Consulting Full time

    APN Consulting is seeking talented individuals for an exciting opportunity:Position Title: Mobile Application EngineerWork Location:Work Location: Multiple locations available Contractual Engagement Onsite from Day 1 Openings Available: 20 Roles (10 in one location, 5 in another, and 5 in a third) Essential Skills Required: IOS, Swift, Xcode, SPM (Open...