Application Security Engineer

4 days ago


Irvine, United States Capital Group Full time

"I can succeed as an Application Security Engineer at Capital Group"

As the Application Security ("AppSec") Engineer you are an individual contributor in the Capital Group (CG) AppSec team. The CG AppSec team is part of Information Security in CG's Information Technology Group. In the role you will be reviewing the architectures and performing threat models, code reviews, validating cloud configurations, and validating the DAST, SAST, and SCA findings for web applications. You will be doing code reviews (Java, TypeScript/JavaScript, Python, Terraform) and creating POCs for DAST tooling where required or collaborating with the penetration testers, as appropriate. The team members are geographically dispersed with varying experience levels. You will help the teams understand how to fix issues and provide best practices or appropriate compensating controls. In this role, you will be using threat modeling tools, static analysis tools, cloud configuration tools. If you are good at software security, this role is for you.

A typical day in the life of the AppSec engineer may look like the following:

  • You will be performing AppSec reviews including threat modeling, and code reviews

  • You will be meeting with the software development teams to understand a new application they are building and providing them with feedback on their architecture

  • You leverage SAST, DAST, SCA tools to create findings and translating them to severity of risks to perform this in Capital Group's technology environment

  • You will write clear, succinct and effective technical documentation summarizing your findings, risks, and recommendations

  • You will write automated proof-of-concepts, and automated security tests by authoring security testing tools where needed

  • You will collaborate with technology stakeholders and advise on risks for technology solutions such as SaaS services and how they integrate with CG's environment

  • You will communicate effectively and have an empathetic outlook towards development teams by authoring clear, actionable guidance on writing secure code

  • You will effectively present to development teams educating them on secure development.

"I am the person Capital Group is looking for."

  • You have a bachelor's degree in computer science, a related field, or equivalent experience (preferably7+ years of experience)
  • You understand threat modeling, code reviews, network security, TCP/IP, DNS, TLS, HTTP, etc.
  • You have experience with technologies such as Threat modeler/Threat Dragon, Scoutsuite, Veracode, Checkmarx, Netsparker, DAST scanners like Burpsuite
  • You have the ability to automate tasks in Python, bash, Java, C/C#/C++, Rust, etc.
  • You have a strong understanding of attacks in AWS, Azure, OAuth
  • You have excellent communication skills (written, oral), with the ability to simplify and document complex technical details to both technical and non-technical audiences
  • You can learn quickly and have a track record of developing a deep understanding of systems and risks to the business
  • You can work independently and take the initiative to drive security initiatives forward
  • You can juggle multiple tasks and coordinate/delegate to achieve speedy resolutions to application security-related security incidents working with Security operations.
Southern California Base Salary Range: $121,652-$194,643 San Antonio Base Salary Range: $100,008-$160,013 New York Base Salary Range: $128,957-$206,331

In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.

You can learn more about our compensation and benefits here.

* Temporary positions in Canada and the United States are excluded from the above mentioned compensation and benefit plans.


We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.



  • Irvine, California, United States INTEGRITY Security Services Inc Full time

    About INTEGRITY Security Services IncWe are a company dedicated to delivering world-class end-to-end security solutions. Our team of experts works together to develop comprehensive web and server solutions using secure technologies.Job RequirementsBachelor's degree in software, computer, electronics, or other relevant engineering disciplines.4 years or more...

  • Security Engineer

    5 days ago


    Irvine, United States Turion Space Full time

    Security EngineerDepartment: Information Technology Employment Type: Full Time Location: Irvine, California Compensation: $110,000 - $150,000 / year Description Turion Space is seeking a Security Engineer to join our platform engineering team. Working across our cloud and on-premises infrastructure, you'll help design, implement, and maintain our security...

  • Security Engineer

    5 days ago


    Irvine, United States Amazon Full time

    Description Global Services Security is looking for an Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will build and automate security assessments into scalable tools to enable and inspect collaboration across AWS including Amazon partners. A Security...

  • Security Engineer

    7 days ago


    Irvine, United States Turion Space Full time

    Job DescriptionJob DescriptionDescriptionTurion Space is seeking a Security Engineer to join our platform engineering team. Working across our cloud and on-premises infrastructure, you'll help design, implement, and maintain our security solutions. While we currently operate primarily in AWS, you'll be instrumental in ensuring security across our...

  • Security Engineer

    5 days ago


    Irvine, United States Turion Space Full time

    Security EngineerApplication Deadline: 29 December 2024Department: Information TechnologyEmployment Type: Full TimeLocation: Irvine, CaliforniaReporting To: Pablo Da SilvaCompensation: $110,000 - $150,000 / yearDescriptionTurion Space is seeking a Security Engineer to join our platform engineering team. Working across our cloud and on-premises...


  • Irvine, United States Capital Group Full time

    "I can succeed as a Senior Security Engineer at Capital Group." As the senior security engineer, you will be responsible for enabling the secure use of Microsoft products at Capital Group. Additionally, you will be responsible for reviewing infrastructure enhancement and making recommendations to improve security. These will be instrumental in the design and...


  • Irvine, United States eTeam Full time

    Job: Cyber Security Engineer Duration: 6 Months Location: 14600 Myford Road, Irvine California 92606 Schedule: M-W-F On site Tu/Th from home 9-6 with flex depending on business needs Pay Rate: $70/hr. W2Job Description: This team is responsible for reviewing modern applications, identifying potential security vulnerabilities and providing development teams...


  • Irvine, California, United States PSG Global Solutions Careers Full time

    Job Title: Cloud-Based Application EngineerEstimated Salary: $110,000 - $160,000 per yearCompany OverviewAs a leading provider of agile consulting and staffing services, PSG Global Solutions Careers has helped numerous organizations fulfill their most important initiatives and opportunities.Job DescriptionWe are seeking a talented Cloud-Based Application...


  • Irvine, United States Global Channel Management Full time

    About the job Application engineer Application engineer needs Bachelor's degree or higher in Chemical Engineering, Chemistry, Material Science, Mechanical Engineering or other related fields is preferred Application engineer requires: Packaging material Semiconductor packing material Ability to gather, understand, and interpret chemical, physical and...

  • Security Engineer

    1 month ago


    Irvine, United States TP-Link Systems Inc. Full time

    About Us: Headquartered in the United States, TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products, consistently ranked as the world’s top provider of Wi-Fi devices. The company is committed to delivering innovative products that enhance people’s lives through faster, more reliable connectivity. With a...

  • Application Engineer

    7 months ago


    Irvine, United States Global Channel Management, IncGlobal Channel Management, Inc. Full time

    Application engineer needs Bachelor's degree or higher in Chemical Engineering, Chemistry, Material Science, Mechanical Engineering or other related fields is preferred Application engineer requires:  Packaging material  Semiconductor packing material  Ability to gather, understand, and interpret chemical, physical and mechanical data....


  • Irvine, United States Belcan Full time

    Cyber Security Engineer Job Number: 353930 Category: Embedded Sys / Software Eng Description: Job Title: Cyber Security Engineer Pay rate: $78.87 /hr. Location: Irvine, CA Zip Code: 92606 Start Date: Right Away Keywords: #IrvineJobs; #CyberSecurityEngineerjobs; Job Description: This team is responsible for reviewing modern applications, identifying...


  • Irvine, United States Motion Recruitment Full time

    Our client, a leading vehicle manufacturer, is looking for a Cyber Security Engineer to join their team on a HYBRID model in Irvine, CA! *** This begins as a 6-month contract, with an opportunity to extend at any timeHybrid: M/W/F onsiteResponsibilitiesDevelop and implement automated security solutions to streamline cybersecurity processes, minimize manual...


  • Irvine, United States Motion Recruitment Full time

    Our client, a leading vehicle manufacturer, is looking for a Cyber Security Engineer to join their team on a HYBRID model in Irvine, CA! *** This begins as a 6-month contract, with an opportunity to extend at any timeHybrid: M/W/F onsiteResponsibilitiesDevelop and implement automated security solutions to streamline cybersecurity processes, minimize manual...

  • Application Engineer

    3 weeks ago


    Irvine, California, United States Cenergy International Full time

    Cenergy International is a leading provider of innovative solutions to the energy industry. We are seeking a highly skilled Application Engineer to join our team.Job DescriptionThe Application Engineer will be responsible for designing, developing, and testing software applications, as well as providing technical support to our internal teams. The ideal...


  • Irvine, United States InterEx Group Full time

    Position: [Senior] Security & Compliance EngineerLocation: Irvine, CA (5 days onsite) - RELOCATION SERVICES AVAILABLESponsorship is available if neededCome join one of the largest networking hardware manufacturers in the world as they endeavor to grow their presence in the US. With millions of customers in over 170 countries, they have become the world's top...


  • Irvine, United States InterEx Group Full time

    Position: [Senior] Security & Compliance EngineerLocation: Irvine, CA (5 days onsite) - RELOCATION SERVICES AVAILABLESponsorship is available if neededCome join one of the largest networking hardware manufacturers in the world as they endeavor to grow their presence in the US. With millions of customers in over 170 countries, they have become the world's top...


  • Irvine, California, United States Insight Global Full time

    **Job Summary**We are seeking an Enterprise Security Engineer to join our team at Insight Global in Irvine, CA. The successful candidate will serve as an architect for endpoint management within OIT, maintaining currency in related technologies and providing expertise in areas of new and emerging platforms.The role involves maintaining security design and...


  • Irvine, United States KORE1 Technologies Full time

    KORE1, a nationwide provider of staffing and recruiting solutions, has an immediate opening for a Senior Cyber Security Engineer. This Senior Engineer performs technical and operational tasks to design, develop, implement, and maintain security solutions using technologies and processes to uphold the confidentiality, integrity, and availability of company's...


  • Irvine, United States Mantek Solutions, Inc. Full time

    Seeking a Contract Network Security Engineer for our Client located in Irvine, CA A Network Security Engineer is responsible for conducting security assessments and ensuring the integrity of an organization's network infrastructure. They must have 5 to 10 years of relevant experience and hold appropriate certifications in network security. The main...