Application Security Engineer

3 weeks ago


New York, New York, United States Sirius XM Radio Inc Full time
Job Summary:

The Application Security Engineer will play a crucial role in supporting SiriusXM technology objectives by providing tools, guidance, and continuous support to ensure the security success of our software and applications.

Key Responsibilities:

Build and document security features to enable developers to write secure code.

Facilitate the implementation and continual improvement for a secure SDLC.

Secure tool creation, enabling security by default by building security and tooling into the software development process, conducting regular audits and tests to identify risks and prioritizing fixes.

Drive the technical implementation of our security solutions by providing necessary guidance and technical leadership to the SiriusXM engineering community.

Develop and improve the Application Security capabilities of SiriusXM by continually designing runbook procedures and expanding the scope and capabilities of security tools.

Consulting and systems development responsibilities for needs brought to the Application Security team by the business.

Write and design SDKs, containers images, guardrails, and testing suites.

Design, implementation, facilitation, and maintenance of tooling and frameworks to make adoption of security guardrails and best practices easier for developers when working in our code bases.

Participate in the design and implementation of applications, services, and infrastructure to ensure security and privacy design principles are being followed by performing security reviews and threat modeling.

Work within a collaborative team to develop scripts and software to solve for security automation and development needs.

Aid in secure code reviews, focused on security bug reduction.

Develop documentation, training, and security baselines to inform and educate the engineers, IT practitioners and developers on best practices.

Deploy, manage, and tune infrastructure used to protect our applications from common vulnerability exploitation, account takeover, and denial of service attacks.

Triage, escalate, and remediate vulnerabilities found as part of our vulnerability management program, bug bounty program and discovered in enterprise penetration tests.

Work with the product management teams to prioritize fixes for vulnerabilities and work with engineering teams to understand how to fix these issues.

Conducting root cause analysis of security findings to develop systematic improvements to develop processes, tooling, and security checks.

Fixing vulnerabilities, building in security telemetry/instrumentation, and adding security features to our products/applications.

Participate with the architecture and planning for company-wide security efforts.

Form a strong relationship with developer teams and serve as point of contact and security SME for questions arising around secure development.

Actively participate in all facets of the incident response lifecycle.

Requirements:

3+ years of software development experience, 2+ years of security (direct or adjacent) experience.

Proficient in at least one primary development language (preferably Python and Java/Scala).

Some experience with mobile application security preferred (Kotlin and Swift).

Experience with internal development for identity management, Cognito, OIDC, SAML, and SSO integration development.

Experience with AWS and/or GCP.

Experience calling REST and/or GraphQL APIs.

Experience administering application security tools such as SAST, SCA, DAST.

Knowledge of OWASP classifications and how to implement security checks for these vulnerabilities.

Ability to understand security code reviews.

Understanding of continuous integrations, testing, and delivery.

Ability to discover, document and fix security bugs.

Experience using Git and related, development processes in a professional setting.

Knowledge of JIRA (Issue/bug tracking), Confluence.

Experience writing educational documentation or knowledge bases.

Security mindset, self-starter, and ability to operate independently.

Be an organized and responsive problem solver.

Excellent oral/written presentation skills with the ability to teach and communicate effectively to developers and leadership.

Passionate about understanding complex systems.

Eager to learn, adapt, and improve your work.

Must have legal right to work in the U.S.

At SiriusXM, we carefully consider a wide range of factors when determining compensation, including your background and experience. These considerations can cause your compensation to vary.

We expect the base salary for this position to be in the range of $64,700 to $131,300 and will depend on your skills, qualifications, and experience.

Additionally, this role might be eligible for discretionary short-term and long-term incentives. We encourage all interested candidates to apply.

Our goal at SiriusXM is to provide and maintain a work environment that fosters mutual respect, professionalism and cooperation.

SiriusXM is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, national origin, ancestry, alienage or citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation or any other characteristic protected by applicable federal, state or local laws.


The requirements and duties described above may be modified or waived by the Company in its sole discretion without notice.

R


As an EEO/Affirmative Action Employer all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status.


Minimum Salary:

Maximum Salary:

Salary Unit:
Yearly

  • New York, New York, United States Genius Sports Full time

    About Genius SportsGenius Sports is a leading provider of sports data and technology solutions. We are at the forefront of the global sports industry, connecting sports, brands, and fans through official live data.The RoleWe are seeking an experienced Application Security Engineer to join our team. As a key member of our security team, you will be...


  • New York, New York, United States Sirius XM Radio Inc Full time

    Job Title: Application Security EngineerSiriusXM is seeking an experienced Application Security Engineer to join our team. As a key member of our security organization, you will play a critical role in ensuring the security and integrity of our software applications.Key Responsibilities:Design and implement secure software development lifecycle (SDLC)...


  • New York, New York, United States New Directions Staffing Full time

    Job Opportunity: Applications Security Sales EngineerWe are seeking a highly motivated and experienced Applications Security Sales Engineer to join our team at New Directions Staffing. As a key member of our sales team, you will be responsible for educating prospects and customers on SaaS-based applications security products.Key Responsibilities:Deliver...


  • New York, New York, United States MedReview Full time

    Job SummaryWe are seeking a seasoned Senior Application Security Engineer to lead MedReview's application security initiatives. As a key member of our team, you will be responsible for the strategic implementation of security measures to protect our applications and data, while mentoring junior engineers and shaping our security posture.Key...


  • New York, New York, United States Blackbird Full time

    Job DescriptionWe are seeking a highly skilled Principal Application Security Engineer to join our team at Blackbird.AI. Reporting directly to the CISO, you will play a critical role in securing our applications and infrastructure hosted on AWS and Kubernetes. Your expertise will be instrumental in helping us achieve key security certifications such as SOC...


  • New York, New York, United States Genius Sports Full time

    About UsGenius Sports is a leading sports technology company that connects sports, brands, and fans through official live data. Our mission is to create a sustainable sports data ecosystem that benefits all parties.We're looking for a talented Application Security Engineer to join our team. As a key member of our security team, you will play a crucial role...


  • New York, New York, United States Abnormal Security Full time

    About the RoleAbnormal Security is seeking a Senior Software Engineer to join the Inbound Email Products - Systems (IEPS) team. The IEPS team is responsible for Abnormal's core Inbound Email Security product backend systems, including Remediation and Threat Log (data processing and storage). Our objective is to enhance stability and scalability, as well as...


  • New York, New York, United States SysLogic Full time

    Job DescriptionWe are seeking a highly skilled Application Security Architect to join our team at SysLogic. As a key member of our managed security offering, you will be responsible for developing enterprise architectural security deliverables that drive significant value to our clients.You will work closely with key client decision makers and business...


  • New York, New York, United States SAS Full time

    About the JobThe Product Security team in our R&D division is seeking an Application Security Architect to contribute to software security design efforts across all of Research and Development.Suitable candidates will solve complex technical problems, work closely with engineering teams, and communicate clearly and effectively with technical audiences.This...


  • New York, New York, United States MarketAxess Full time

    About UsMarketAxess is a leading financial technology company that is revolutionizing the way the world trades. Our platform enables the shift from analog, phone-based trading to a fully electronic marketplace, making trading fixed-income more accessible and improving transparency, efficiency, and competition in the marketplace.We are on a mission to...


  • New York, New York, United States Amazon Services LLC Full time

    About the RoleWe are seeking a highly skilled Senior Security Engineer to join our Application Security Testing Automation team at Amazon Services LLC. As a key member of our team, you will play a critical role in helping us provide automated security testing solutions for all of Amazon.Key ResponsibilitiesDefine and drive strategy, act as a technical lead...


  • New York, New York, United States Amazon Full time

    About the RoleAs a Security Engineer II, you will play a critical role in ensuring the security of Amazon's Stores applications. You will collaborate with software development teams to identify and mitigate security risks, and develop secure coding practices to prevent vulnerabilities.Key Responsibilities Conduct threat modeling and risk assessments for...


  • New York, New York, United States Akraya Full time

    Job Summary:As a seasoned Application Security Engineer II, you will play a pivotal role in enhancing our defensive security posture by identifying and remediating vulnerabilities across our clients' services and assets.This role requires a proactive approach to cybersecurity tasks, including secure code review, automated testing of APIs and endpoints, and a...

  • Field Sales Engineer

    3 weeks ago


    New York, New York, United States acre security Full time

    Job OverviewAcre security is seeking a skilled Field Sales Engineer to provide pre-sales support and technical expertise to our sales team. As a key member of our sales team, you will work closely with regional sales teams to deliver technical demonstrations, configure products, and manage Proof of Concept.Key Responsibilities:Support sales and channel...

  • Resident Engineer

    3 weeks ago


    New York, New York, United States Armis Security Full time

    About the Role:Armis Security is seeking a highly skilled Resident Engineer to join our team. As a Resident Engineer, you will be responsible for full platform management, including health checks, deployment and configuration alignment, and driving Armis adoption and implementation plans.Key Responsibilities:Collaborate with the Armis TAM and CEM to refine...

  • Security Engineer

    4 weeks ago


    New York, New York, United States Datadog Full time

    About DatadogWe're on a mission to build the best platform in the world for engineers to understand and scale their systems, applications, and teams. Our platform operates at a high scale, providing always-on alerting, metrics visualization, logs, and application tracing for tens of thousands of companies.The OpportunityUser safety and platform integrity is...

  • Security Engineer

    4 weeks ago


    New York, New York, United States Figma Full time

    Job DescriptionFigma is a design tool company that is growing its team of passionate people who are on a mission to make design accessible to all. Our team is responsible for ensuring the security of Figma's product, platform, and IT systems.We are looking for a Security Engineer who will help identify and drive impactful projects to improve the security of...


  • New York, New York, United States Zip Security Full time

    About the RoleWe're seeking a highly skilled Backend Engineer to join our team at Zip Security. As a Founding Backend Engineer, you'll play a key role in designing and implementing secure APIs that harmonize functionality across multiple enterprise software providers.You'll be responsible for building a first-class, multi-tenant, cloud-native product, and...


  • New York, New York, United States Bitcoin Devs Company Full time

    Job Title: Senior Security EngineerJob Description:The Senior Security Engineer plays a vital role in ensuring the security and integrity of Bitcoin Devs Company’s platform, systems, and applications. This position is crucial in protecting the organization from potential security threats and vulnerabilities, as well as implementing and maintaining best...


  • New York, New York, United States Gusto Full time

    About GustoGusto is a modern, online people platform that helps small businesses take care of their teams. Our mission is to create a world where work empowers a better life, and it starts right here at Gusto. We're committed to building a collaborative and inclusive workplace, both physically and virtually.About the RoleWe're seeking a Principal Software...