Application Security Engineer

2 months ago


Aurora, United States BridgeView Full time

BridgeView is currently seeking an Application Security Engineer for one of our clients. If you love building and supporting technology solutions that make businesses successful, then read on for more details.


TITLE: Application Security Engineer

LOCATION: Denver, CO (hybrid)

BENEFITS & PERKS: Medical, Dental & Vision, 401(k)


OVERVIEW

The Application Security Engineer plays a crucial role within the cybersecurity team, overseeing the management and fortification of web-based applications both on-premises and in the cloud. In this capacity, this role is tasked with crafting resilient web application firewall (WAF), Bot Mitigation/Defense, and DDoS mitigation configurations, ensuring robust defense against threats and vulnerabilities while preserving seamless business operations and customer experiences.


HOW YOU WILL MAKE AN IMPACT

  • Serve as the primary authority and subject matter expert on Web Application Firewall (WAF), Bot Mitigation (BotM), and DDoS Mitigation platforms.
  • Assess and devise cybersecurity architectures and designs that strike a balance between implementing robust security controls and fulfilling the functional requirements of the business.
  • Define and cultivate security requirements through meticulous risk assessments, comprehensive threat modeling, rigorous testing, and insightful analysis of existing systems.
  • Lead web application security functions, spearheading strategic initiatives to proactively tackle external, internal, and emerging application security risks across the organization.
  • Set up new sites and applications for WAF/BotM safeguarding, conducting thorough traffic analysis to eliminate false positives and optimize protection efficacy.
  • Collaborate closely with engineering and architecture teams to assess the security readiness of both new and existing applications introduced into the environment.
  • Devise, test, and implement solutions and configurations with rule sets specifically crafted to safeguard against vulnerabilities and threats targeting both web-based and mobile applications.
  • Lead compliance hardening governance across cloud and application landscapes, conducting meticulous checks on device configurations to ensure version compliance, and identifying and promptly mitigating weaknesses.
  • Analyze reports stemming from vulnerability scans, penetration tests, web testing, to pinpoint areas of exposure and enhance application security posture in collaboration with application developers.
  • Develop, oversee, and ensure compliance with the Secure Software Development Lifecycle (sSDLC) processes, aligning with industry best practices.
  • Collaborate closely with cybersecurity and development teams to manage a comprehensive sSDLC process, integrating security testing functions (SAST, DAST, IAST, pen test) while balancing security and usability concerns.
  • Develop and implement application security strategy throughout the CI/CD lifecycle.
  • Document and maintain policies, standard operating procedures, and OWASP best practices for application and host integrity.
  • Create and implement WAF/BotM rules and signatures to mitigate threats and adhere to best practices.
  • Liaise with cybersecurity, threat intelligence, IT, software development, and third-party teams to address organizational cybersecurity architecture and system security engineering requirements throughout their lifecycles.


REQUIRED EXPERIENCE

  • 7 + years of enterprise security or application security experience.
  • 7+ years of deploying, configuring, and managing Web Application Firewall (WAF) platforms.
  • 5+ years of deploying, configuring, and managing Bot Mitigation (BotM) platforms.
  • 5+ years of deploying, configuring, and managing DDoS Mitigation platforms.
  • 2 + years of hands-on experience in a cloud-native environment, such as Azure, AWS, or GCP
  • Hold an active cybersecurity certification, such as a CSSLP, CISSP, CISA, CCP, CSSLP, GCSA MCP, MCSE, SANS, or Microsoft AZ (highly desired, or equivalent experience is acceptable).
  • Hold an active cybersecurity certification, such as: CSSLP, SANS, CISSP, CCNA, CISA, CCP, GCSA, MCP, MCSE, SANS, or Microsoft AZ (required, or willing to attain within 3 months of start date).
  • Familiarity with tools like Fastly, Akamai, Radware, F5, or HumanSecurity preferred.
  • Experience installing, configuring, and supporting Web Application Firewalls (WAFs) in complex enterprise environments.
  • Proficiency in Web Application Firewall (WAF) configuration, policy management, and related tools.
  • Proficiency in Bot Mitigation (BotM) configuration, policy management, and related tools.
  • Experience with DDoS Mitigation deployments (IPSec/GRE tunnels), configuration, policy management, and related tools.
  • Strong understanding of applications, databases, web services, authentication, and middleware servers.
  • Knowledgeable about mobile application and device security (iOS, Android, Mobile SDKs).
  • Familiarity with security concepts and tools such as SAST, DAST, IAST, Web Application Penetration Testing, and Open-Source Analysis.
  • Understanding of OWASP Top Ten, threats, vulnerabilities, and tactics used to compromise applications.
  • Experience in secure CI/CD pipeline design, architecture, automation, and secure code gating.
  • Experience securing cloud IAAS and PAAS environments (Azure, AWS, Google Cloud).
  • Ideally familiar with regulatory requirements and laws such as: Sarbanes-Oxley Act (SOX), PCI-DSS, TSA, SEC Amended Rule, HIPAA, GDPR, CCPA, and GLBA.
  • Knowledge of industry compliance standards and frameworks such as: HIPAA, NIST, ISO, ITIL, COSO, COBIT, SOC1/2, NIST 800-53, NIST CSF, ITIL, and/or Cybersecurity Maturity Model.
  • Proficiency in one or more scripting languages (e.g., Python, PowerShell, JavaScript, Bash).
  • Ability to work independently and collaboratively with others.


ABOUT BRIDGEVIEW

BridgeView is a talent and technology consulting company that helps business leaders build exceptional technology teams and deliver complex projects with confidence.

Since 2005, BridgeView's tenured recruiting team has built a vast network of niche technologists and executive leadership candidates to help our clients solve their most complex talent challenges. Paired with strategic consulting services, BridgeView further delivers project collaboration in the areas of people, process, and technology.

This blended approach allows clients to adjust in real-time to align with their budgets while receiving Big 5 expertise to meet their objectives.

BridgeView. Within Sight.



We are an equal opportunity employer and value diversity. All employment decisions are made due to qualifications, merit, and business need. The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.



  • Aurora, CO, United States Raytheon Careers Full time

    CO109: 16510 E Hughes Drive, Aurora 16510East Hughes Drive Building S79, Aurora, CO, 80011 USA*Position Role Type:* OnsiteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned...


  • Aurora, CO, United States Raytheon Full time

    CO109: 16510 E Hughes Drive, Aurora 16510East Hughes Drive Building S79, Aurora, CO, 80011 USA Position Role Type: At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned...

  • Security Engineer

    3 weeks ago


    Aurora, United States Bayforce Full time

    Role Title: Security EngineerLocation: Onsite - Aurora, CORole Overview:We are seeking a highly skilled Security Engineer with a strong background in firewall engineering to join our team for a critical segmentation project. This role involves separating the Central Monitoring Center (CMC), including vital Life Safety areas, from the broader corporate...

  • Security Engineer

    4 weeks ago


    Aurora, United States Bayforce Full time

    About the ProjectJoin a significant remediation project aimed at addressing and filling gaps following a cyber incident last September. You will be part of the team, that operates a critical $10B segment within the client's $30B revenue structure, overseeing 33 sites and 1200 employees. This segment specializes in Life Safety operations including fire,...


  • Aurora, Colorado, United States DirectViz Solutions, LLC Full time

    Job OverviewDirectViz Solutions, LLC (DVS) is a dynamic government contractor dedicated to delivering strategic services that fulfill mission-critical IT requirements for government clients. We pride ourselves on providing innovative technology solutions through the expertise and commitment of our talented workforce. As an employee-focused organization, DVS...

  • Security Engineer

    4 days ago


    Aurora, United States Varite Full time

    This role is fully onsite. Address is below. 14200 E Exposition Ave, Aurora, CO 80012 Description: Security Engineer for CMC workstream Understand security (Firewalls) More focused on firewalls Fortinate firewalls exp Cisco firewalls exp routing, switching exp.

  • Security Engineer

    4 weeks ago


    Aurora, United States Codeworks L.L.C Full time

    Job DescriptionJob DescriptionPosition Overview:Manage and understand firewall security for network segmentation to ensure a secure network.This Firewall Engineer will work alongside AT&T for network analysis, implementation, and testing, etc.Senior-level with 5+ years of experienceMust have initiative and autonomy to manage projects with AT&T.Must have deep...

  • Security Engineer

    7 days ago


    Aurora, United States Codeworks L.L.C Full time

    Job DescriptionJob DescriptionPosition Overview:Manage and understand firewall security for network segmentation to ensure a secure network.This Firewall Engineer will work alongside AT&T for network analysis, implementation, and testing, etc.Senior-level with 5+ years of experienceMust have initiative and autonomy to manage projects with AT&T.Must have deep...

  • IA Security Engineer

    1 month ago


    Aurora, United States The Computer Merchant, LTD. Full time

    JOB TITLE: IA SECURITY ENGINEER LOCATION: BUCKLEY AFB AURORA, CO RATE RANGE: $90.00-95.00 PER HOUR JOB#: 14361236 Long Term Contract TS/SCI CI Poly Required Description/Comment: Implement Information Assurance (IA) processes, provide guidance, and develop documentation throughout the system development life-cycle via the RMF tool in ServiceNOW. •...


  • Aurora, United States G&W Electric Full time

    Innovating since 1905, G&W Electric has grown into a global leader in engineered electrical power grid solutions. Working with us means joining a worldwide team of passionate manufacturing professionals striving to continually improve the technologies the world depends on to deliver safe, reliable electricity. Our culture is focused on employee success, so...


  • Aurora, United States Nightwing Full time

    Date Posted:2024-07-25Country:United States of AmericaLocation:CO112: Buckley AFB 18500 East 6th Ave 18500 East 6th Avenue Buckley AFB, Aurora, CO, 80011 USAPosition Role Type:OnsiteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling – to help our nation and allies defend freedoms and deter aggression. We bring the...

  • Application Engineer

    3 weeks ago


    Aurora, United States Civic Minds Full time

    Job DescriptionJob DescriptionJob: Application EngineerLocation: Aurora, IL Fulltime Direct hirePosition SummaryPerform functions to promote sales and effective use of our products by providing instructions, software demonstrations, and recommendations. Provide software support to cus tomers and our personnel. Reasonable Accommodations Statement To perform...

  • Application Engineer

    3 weeks ago


    Aurora, United States Civic Minds Full time

    Job DescriptionJob DescriptionJob: Application EngineerLocation: Aurora, IL Fulltime Direct hirePosition SummaryPerform functions to promote sales and effective use of our products by providing instructions, software demonstrations, and recommendations. Provide software support to cus tomers and our personnel. Reasonable Accommodations Statement To perform...


  • Aurora, United States Nightwing Full time

    Date Posted:2024-08-14Country:United States of AmericaLocation:CO109: 16510 E Hughes Drive, Aurora 16510East Hughes Drive Building S79, Aurora, CO, 80011 USAPosition Role Type:OnsiteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling – to help our nation and allies defend freedoms and deter aggression. We bring the...


  • Aurora, United States Nightwing Full time

    Date Posted:2024-07-31Country:United States of AmericaLocation:CO109: 16510 E Hughes Drive, Aurora 16510East Hughes Drive Building S79, Aurora, CO, 80011 USAPosition Role Type:OnsiteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling – to help our nation and allies defend freedoms and deter aggression. We bring the...

  • Senior Cyber Engineer

    1 month ago


    Aurora, United States Nightwing Full time

    Date Posted:2024-07-25Country:United States of AmericaLocation:CO109: 16510 E Hughes Drive, Aurora 16510East Hughes Drive Building S79, Aurora, CO, 80011 USAPosition Role Type:OnsiteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling – to help our nation and allies defend freedoms and deter aggression. We bring the...


  • Aurora, United States Nightwing Full time

    Date Posted:2024-08-13Country:United States of AmericaLocation:CO106: 16470 East Hughes Drive,Aurora 16470 East Hughes Drive Building S77, Aurora, CO, 80011 USAPosition Role Type:OnsiteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling – to help our nation and allies defend freedoms and deter aggression. We bring...


  • Aurora, United States Booz Allen Hamilton Full time

    Aerospace Systems EngineerThe Opportunity:Are you looking for an opportunity to combine your technical skills with big picture thinking to make an impact in the National Security sector? You understand your customer’s environment and how to develop the right systems for their mission. Your ability to translate real-world needs into technical specifications...


  • Aurora, United States Booz Allen Hamilton Full time

    DevOps Infrastructure Engineer, SeniorThe Opportunity:As a DevOps engineer, you know how to set up cloud environments and provision computer networking, storage, and virtual networks—ultimately, how to “harness the cloud.” We’re looking for a DevOps infrastructure engineer like you to support our clients as they modernize their IT infrastructures and...


  • Aurora, United States GeoLogics Corporation Full time

    Infrastructure Storage EngineerAurora, ColoradoRate: $70 to $78 an hour (partial benefits)Clearance Required: Active Top Secret/SCIGeoLogics is seeking a Server Center Storage Engineer for next generation of satellite command and control systems for one of our government customers. As part of a team of engineers, you will be responsible for managing storage...