Application Security Engineer

2 months ago


Raleigh, United States Genworth Full time

At Enact Mortgage Insurance (Nasdaq: ACT), we understand that there is no place like home. That is why we bring our deep expertise, insightful offerings, and extra mile service to work every day to help lenders put more people in homes and keep them there.

We are seeking an Application Security Engineer in Raleigh, NC to join our team. In this role, you will enhance our technical security vulnerability management processes, focusing on identifying, triaging, and addressing code, configuration, and patch-related vulnerabilities within our application delivery pipelines and production environments, both on-premises and in the cloud. Join us to advance our mission with a commitment to excellence, continuous improvement, and strong connections.

LOCATION

Enact Headquarters, Raleigh, NC – Hybrid Schedule

YOUR RESPONSIBILITIES

  • Deploy and Operationalize Application Security Tools: Implement and manage a suite of application security tools such as SAST, DAST, and SCA, ensuring their seamless integration into the development pipeline.

  • Educate Application Delivery Team: Conduct training sessions and workshops to educate the application delivery team on secure coding practices, emphasizing the OWASP Top 10 for web apps and APIs, as well as the OWASP Cheat Sheet Series.

  • Support Transition to the Cloud: Define security requirements and evaluate design proposals to support the organization's cloud native approach to refactoring and re-platforming business critical web services in cloud, ensuring all cloud-based applications and services meet security standards.

  • Mentor Junior AppSec Engineer: Provide guidance and mentorship to a junior application security engineer, helping them develop their skills and grow within the organization.

  • Influence Requirements Analysis and Design: Participate in requirements analysis and design phases of new projects to ensure secure software delivery standards are integrated from the outset.

  • Address Security Issues: Identify, assess, and remediate security issues in applications and systems, ensuring vulnerabilities are resolved promptly and effectively.

  • Mediation Between Teams: Function as a mediator between the application delivery and security teams, ensuring clear communication and collaboration on application security matters.

  • Coordinate Penetration Tests: Coordinate and oversee web services penetration tests to identify vulnerabilities and ensure the security of applications.

YOUR QUALIFICATIONS

  • Bachelor's degree in computer science or equivalent and relevant industry experience.

  • Current or former software engineer with experience delivering business-critical web services, including application programming interfaces (APIs).

  • Practical experience working with scripting languages or popular web framework.

  • Strong grasp of the OWASP Top 10 for web apps and APIs, as well as the OWASP Cheat Sheet Series.

  • Experience with static application security testing (SAST) and dynamic application security testing (DAST).

  • Experience conducting secure code reviews for critical aspects of web services to ensure robust security and compliance.

  • Proven ability to influence requirements analysis and design, and address security deficiencies effectively.

  • Strong ability to educate software engineers in secure coding practices.

  • Proven ability to mediate between application delivery and security teams.

  • Experience mentoring junior engineers.

  • Effective communication and collaboration skills.

PREFERRED QUALIFICATIONS

  • Experience conducting or coordinating web services penetration tests.

  • Experience in securing serverless, containerized, and event driven environments.

  • Experience securing CI/CD pipelines.

  • Experience supporting industry leading web application firewalls through the creation of custom rules to filter and mitigate current and emerging threats.

COMPANY

Enact is a leading publicly traded U.S. private mortgage insurance provider, offering borrower-centric products that enable lenders and other partners across the U.S. to help people responsibly achieve and maintain the dream of homeownership.

By empowering customers and their borrowers, Enact seeks to positively impact the lives of those in the communities in which it serves in a sustainable way. Headquartered in Raleigh, North Carolina, we play an active role in supporting a healthier Triangle community. We also support our colleagues’ philanthropic efforts in their home communities across the U.S.

Enact values all perspectives, characteristics and experiences, and DEI remains at the forefront of what we do. We strive to create an environment where employees can bring their full, authentic selves to work to help each other and their customers.

We are proud to be an equal opportunity employer and all hiring decisions are based on merit, qualifications, and business needs. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

WHY WORK AT ENACT

We bring innovative thinking to the situations at hand.

We seek out and incorporate diverse views to strengthen our outcomes.

We work on challenging and rewarding projects.

We offer competitive benefits:

  • Hybrid work schedule (shared in-office days Tues/Wed/Thurs)

  • Generous Time Off

  • 40 Hours of Volunteer Time Off

  • Tuition Reimbursement and Student Loan Repayment

  • Paid Family Leave and Flexible Spending Accounts

  • 401k with up to 5% employer match

  • Fitness and Emotional Wellness Reimbursements



  • Raleigh, United States Genworth Full time

    At Enact Mortgage Insurance (Nasdaq: ACT), we understand that there is no place like home. That is why we bring our deep expertise, insightful offerings, and extra mile service to work every day to help lenders put more people in homes and keep them there. We are seeking an Application Security Engineer in Raleigh, NC to join our team. In this role, you will...


  • Raleigh, United States Trustmark Full time

    Trustmarks mission is to improve wellbeing for everyone. It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust. Trust established by ensuring associates feel respected, valued and heard. At Trustmark, youll work collaboratively to transform lives and help people, communities...

  • Security Engineer

    3 weeks ago


    Raleigh, United States The Judge Group Full time

    Our client is currently seeking a Security Engineer - I Security Analyst/Engineer Responsibilities: The Security team is responsible for management of Managed Security Services for customers in our Government Network Operations and Security Center (GNOSC). Typical duties include security event analysis/investigation/escalation and change management including...


  • Raleigh, North Carolina, United States DSI Security Full time

    Position OverviewAt DSI Security, we believe that employment is more than just earning a paycheck. Our motto, Do What You Say You Will Do, reflects our commitment to integrity and service. Joining our team means becoming part of a culture that values dedication and excellence.As we expand our operations, we are seeking dedicated Safety and Security...


  • Raleigh, United States Vaco Full time

    Description: Reporting to the Corporate IT Manager, the Senior IT Security Engineer will serve as the primary IT security expert for the corporate IT environment. This role is responsible for the operational management of IT security infrastructure (such as Proxy, SIEM, EDR, Firewalls, Email-filter, VPN), enforcing standards, and creating and ensuring...


  • Raleigh, North Carolina, United States DSI Security Full time

    Position OverviewAt DSI Security, we offer more than just a paycheck; we provide a fulfilling career path that aligns with our core values. Our motto, Do What You Say You Will Do, is at the heart of our operations, ensuring that every team member contributes to a culture of integrity and commitment.We are dedicated to fostering a work environment that...


  • Raleigh, North Carolina, United States Novanta Full time

    Thank you for considering a career with Novanta. You are taking an important step towards a rewarding opportunity. We encourage you to proceed with your application. Your information will be securely stored for future job applications in accordance with Novanta's Data Privacy Policy. By continuing, you confirm that you have read and understood this policy....


  • Raleigh, United States First Citizens Bancshares, Inc. Full time

    This position is responsible for the planning, problem resolution, and advanced production support for multiple high-priority Bank applications. Provides expert guidance and mentorship on application technical support, maintenance, and enhancement. I Application Engineer, Application, Technical Support, Engineer, Technology, Banking, Business

  • Applications Engineer

    3 months ago


    Raleigh, United States ANDRITZ AG Full time

    Every day, ANDRITZ continues to deliver successful innovative solutions to our customers globally. Why are we so successful? Because we are passionate and love what we do! We are at the forefront of future engineering technologies, with solutions that ensure the success of our clients in key industries that are shaping the future of the world we live...


  • Raleigh, United States Southern Talent Specialists Full time

    Job DescriptionJob DescriptionAzure Cyber Security EngineerSummaryThe Cyber Security Engineer – Threat Management is responsible for second level security event/incident response along with the collection, analysis, and dissemination of cyber threat intelligence. These capabilities will include timely collection of advanced warning of impeding IT...

  • Software Engineer

    7 days ago


    Raleigh, North Carolina, United States InsideHigherEd Full time

    Posting Number:PG193566EPInternal Recruitment :NoWorking Title:Software Engineer - Web ApplicationsAnticipated Hiring Range:$65,000 - $69,558Work Schedule:8:00 am - 5:00 pmJob Location:Raleigh, NCDepartment :Engineering - Web ServicesAbout the Department:The Web Services division is dedicated to creating and enhancing digital platforms that facilitate the...


  • Raleigh, United States Virtual Full time

    Description: Reporting to the Corporate IT Manager, the Senior IT Security Engineer will serve as the primary IT security expert for the corporate IT environment. This role is responsible for the operational management of IT security infrastructure (such as Proxy, SIEM, EDR, Firewalls, Email-filter, VPN), enforcing standards, and creating and ensuring...


  • Raleigh, United States Ally Full time

    **General information** **Ref #** 17728 **Remote?** No **Ally and Your Career** * Ally Financial only succeeds when its people do - and thats more than some clich people put on job postings. We live this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health...


  • Raleigh, United States Greensboro Staffing Consultants Full time

    Job DescriptionJob DescriptionSeeking a Cloud Security Engineer with healthcare industry experience. Must have proven ability to secure cloud deployments and protect sensitive data. Skilled at working with senior management to develop and implement security strategy. Responsible for managing and supporting AWS Cloud infrastructure, creating technical...


  • Raleigh, United States Greensboro Staffing Consultants Full time

    Job DescriptionJob DescriptionSeeking a Cloud Security Engineer with healthcare industry experience. Must have proven ability to secure cloud deployments and protect sensitive data. Skilled at working with senior management to develop and implement security strategy. Responsible for managing and supporting AWS Cloud infrastructure, creating technical...

  • Software Engineer

    3 months ago


    Raleigh, United States Kelaca Full time

    Job DescriptionJob DescriptionKelaca is seeking a Full Stack Application Developer Consultant to work in a Hybrid capacity for a long-term engagement with our client partner in Raleigh, NC. We are actively seeking a qualified Software Engineer who will support our growing business in modeling and simulation of physical phenomena within a 3D geometric...

  • Applications Engineer

    4 months ago


    Raleigh, United States ANDRITZ Full time

    Summary: Reporting to the Director of Forming Technology, this position’s main objective is design and application of machine clothing products for Andritz. This position is directly responsible for providing support to Sales, Manufacturing, Customer Service, Research, and Marketing for machine clothing products. Job Responsibilities: Specifies...

  • Applications Engineer

    3 months ago


    Raleigh, United States ANDRITZ Full time

    Summary: Reporting to the Director of Forming Technology, this position’s main objective is design and application of machine clothing products for Andritz. This position is directly responsible for providing support to Sales, Manufacturing, Customer Service, Research, and Marketing for machine clothing products. Job Responsibilities: Specifies...


  • Raleigh, United States Bandwidth Full time

    Job DescriptionJob DescriptionWho We Are:Bandwidth (NASDAQ: BAND) is a global communications software company that helps enterprises connect people around the world with cloud-ready voice, messaging and emergency services. Backed by a network reaching 60+ countries covering 90 percent of global GDP, companies like Cisco, Google, Microsoft, RingCentral, Uber...


  • Raleigh, United States Bandwidth Full time

    Job DescriptionJob DescriptionWho We Are:Bandwidth (NASDAQ: BAND) is a global communications software company that helps enterprises connect people around the world with cloud-ready voice, messaging and emergency services. Backed by a network reaching 60+ countries covering 90 percent of global GDP, companies like Cisco, Google, Microsoft, RingCentral, Uber...