Principal Associate, Application Security Engineer

2 months ago


New York, United States Capital One Full time
Center 3 (19075), United States of America, McLean, Virginia

Principal Associate, Application Security Engineer

Application security is one of our highest priorities at Capital One. As a Capital One customer, you benefit from an environment built to meet the requirements of one of the most security-sensitive organizations in not only the financial industry, but also the technology landscape. As a Capital One Security team member, you will help secure our applications for our customers while working on cutting edge security products for a variety of platforms and technologies, all operating at massive scale. We are looking for an experienced security engineer to join our Capital One Application Security team.

Responsibilities:
  • Dynamic Application security testing of web assets and APIs
  • Mobile application security testing
  • Projects and research work as needed
  • Security training and outreach to internal development teams
  • Security guidance documentation
  • Security tool development
  • Security metrics delivery and improvements


Basic Qualifications:
  • High School Diploma, GED or equivalent certification
  • At least 3 years of experience working in cybersecurity or information technology
  • At least 2 years of experience in application security


Preferred Qualifications:
  • 3+ years of experience with dynamic application security and software testing
  • 2+ years of experience with penetration testing
  • 2+ years of experience with Kali Linux
  • 2+ years of experience with mobile testing
  • 2+ years of risk analysis experience
  • Experience with risk-based prioritization
  • One of the following cybersecurity certifications: (OSCP, CISSP, CEH)
  • Experience architecting, securing, and operating Amazon Web Services


At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).

The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.

New York City (Hybrid On-Site): $165,100 - $188,500 for Prin Assoc, Cyber Technical

San Francisco and San Jose, California (Hybrid On-Site): $174,900 - $199,700 for Prin Assoc, Cyber Technical

Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.

This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

  • New York, United States Capital One Full time

    As an Application Security Engineer, Principal Associate at Capital One, you will play a critical role in securing our applications to meet the high standards of one of the most security-focused organizations in finance and technology. You will work on cutting-edge security products for various platforms and technologies, operating at massive scale....


  • NEW YORK, United States Capital One Careers Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Application Security EngineerApplication security is one of our highest priorities at Capital One. As a Capital One customer, you benefit from an environment built to meet the requirements of one of the most security-sensitive organizations in not only the financial industry,...


  • New York, New York, United States Gusto Full time

    About GustoGusto is a modern, online people platform that helps small businesses take care of their teams. Our mission is to create a world where work empowers a better life, and it starts right here at Gusto. We're committed to building a collaborative and inclusive workplace, both physically and virtually.About the RoleWe're seeking a Principal Software...


  • New York, United States Gusto Full time

    About Gusto Gusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools. Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000 businesses nationwide. Our mission is to create a...


  • New York, United States Alloy Full time

    Alloy is where you belong! Alloy solves the identity risk problem for companies that offer financial products by enabling them to outpace fraud and confidently serve more people around the world. Banks and Fintechs turn to Alloy to take control of fraud, credit, and compliance risk, and grow with the clearest picture of their customers. Through our values:...


  • New York, New York, United States Sirius XM Radio Inc Full time

    Job Summary:The Application Security Engineer will play a crucial role in supporting SiriusXM technology objectives by providing tools, guidance, and continuous support to ensure the security success of our software and applications.Key Responsibilities:Build and document security features to enable developers to write secure code.Facilitate the...


  • New York, United States Sirius XM Radio Inc Full time

    Who We Are: SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices. Our vision is to...


  • New York, United States Emergent365 Full time

    Senior Application Security Engineer*This position is highly technical. As a Senior Application Security Engineer, your role involves close collaboration with software development teams to ensure the safety of our customers during the development of innovative services. On any given day, your tasks may include code inspections to identify security issues,...


  • New York, United States Tbwa ChiatDay Inc Full time

    Headway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled national network of providers accepting insurance.1 in 4 people in the US have a treatable mental health condition, but the majority of providers don’t accept...


  • New York, United States Montash Full time

    Location: New York, In-OfficeSalary: Very competitive, with equity options and benefitsAbout the CompanyWe are a Series A Generative AI-driven Fintech startup that has secured $20 million in funding to transform the financial services sector. Our mission is to leverage cutting-edge AI to deliver scalable, intuitive, and data-driven financial solutions. We...


  • New York, United States Randstad Full time

    cyber security principal. new york , new york (remote) posted 4 days ago job details summary $74.35 - $84.35 per hour contract bachelor degree category computer and mathematical occupations reference1071021 job details job summary: Enterprise Healthcare client has an immediate opening for a highly motivated Cyber Security Principal to join...


  • new york city, United States Emergent365 Full time

    Senior Application Security Engineer*This position is highly technical. As a Senior Application Security Engineer, your role involves close collaboration with software development teams to ensure the safety of our customers during the development of innovative services. On any given day, your tasks may include code inspections to identify security issues,...


  • new york city, United States Emergent365 Full time

    Senior Application Security Engineer*This position is highly technical. As a Senior Application Security Engineer, your role involves close collaboration with software development teams to ensure the safety of our customers during the development of innovative services. On any given day, your tasks may include code inspections to identify security issues,...


  • New York, United States CareAbout Health Full time

    Company Description  CareAbout Health is a managed services organization (MSO) that provides expert advice, resources, tools, and other support to its portfolio of medical groups and healthcare focused companies. CareAbout Health is helping align incentives to create a world where patients, providers, and payers work together in a seamless, coordinated...


  • New York, United States Your IT & Corporate Recruiter Full time

    Job DescriptionYour IT Recruiter is looking for a Principal Electrical Engineer for our client.Are you a visionary Electrical Engineer with a passion for innovation and a proven track record of successful project leadership? We are seeking a highly skilled and experienced Principal Level Engineer to join our client's dynamic team. As a Principal Engineer,...


  • New York, United States Your IT & Corporate Recruiter Full time

    Job DescriptionYour IT Recruiter is looking for a Principal Electrical Engineer for our client.Are you a visionary Electrical Engineer with a passion for innovation and a proven track record of successful project leadership? We are seeking a highly skilled and experienced Principal Level Engineer to join our client's dynamic team. As a Principal Engineer,...

  • Software Engineer II

    3 weeks ago


    New York, United States Abnormal Security Full time

    Job DescriptionJob DescriptionAbout the RoleAbnormal Security is hiring a Software Engineer to join the Threat Response Engine team, an essential part of our mission to protect global enterprises from diverse and evolving email threats. At Abnormal, we've taken a novel approach to email security, utilizing behavioral AI to identify and counter complex...


  • York, United States Johnson Controls Full time

    What you will doJohnson Controls has an exciting opportunity available! The Principal Mechanical Engineer position is part of the Building Efficiency AirSide product engineering team based in York, PA. As a Principal Mechanical Engineer, you will have a full range of engineering responsibilities requiring application of standard techniques, procedures, and...


  • york, United States Johnson Controls Full time

    What you will doJohnson Controls has an exciting opportunity available! The Principal Mechanical Engineer position is part of the Building Efficiency AirSide product engineering team based in York, PA. As a Principal Mechanical Engineer, you will have a full range of engineering responsibilities requiring application of standard techniques, procedures, and...


  • New York, United States Pursuit of Talent Full time

    About the job Principal Electrical Engineer Are you a visionary Electrical Engineer with a passion for innovation and a proven track record of successful project leadership? Our client is seeking a highly skilled and experienced Principal Level Engineer to join their dynamic team. As a Principal Engineer, you will play a pivotal role in providing technical...