Staff Application Security Engineer

2 weeks ago


Jefferson City, Missouri, United States EDB Full time
About Us

EDB is a leading provider of data and AI platforms that enable organizations to harness the full power of Postgres for transactional, analytical, and AI workloads across any cloud, anywhere.

We empower enterprises to control risk, manage costs, and scale efficiently for a data and AI-led world. With over 1,500 customers globally and as the leading contributor to the vibrant and fast-growing PostgreSQL community, EDB supports major government organizations, financial services, media, and information technology companies.

Job Description

As a Staff Application Security Engineer at EDB, you will report directly to the Director of Information Risk Management as a trusted member of the CISO staff. Your role will lead the transformation of the security and development processes within EDB, helping the organization identify, repair, and protect against vulnerabilities throughout a secure software development lifecycle (SDLC).

You will be responsible for understanding multiple security frameworks, translating objectives, partnering with stakeholders, and promoting best practices across all EDB products. The ideal candidate must be comfortable working in a global environment that supports flexible work schedules and a distributed security model.

Key Responsibilities
  1. Support the development and implementation of EDB's application security services to be consumed by product teams and within our global infrastructure.
  2. Serve as an expert on application security frameworks and objectives by assisting owners as they define new control activities and seek maturity in their development processes.
  3. Build tools, processes, and solutions that improve the security of EDB's products and data.
  4. Collaborate with internal engineering stakeholders on addressing systemic security issues.
  5. Grow and mature relationships with internal security SMEs in a way that bridges the gap between product teams and information security.
  6. Support Vulnerability Disclosure Program, triage, assess, and analyze vulnerability reports submitted through the VDP, prioritizing them based on severity, risk, and exploitability.
  7. Coordinate vulnerability remediation, work with internal development teams to reproduce, validate, and prioritize vulnerabilities, and facilitate timely patch development and deployment, ensuring efficient resolution.
  8. Produce application security metrics that demonstrate a continually improving application security posture.
  9. Partner with InfoSec Program Management on the roadmap and execution of security initiatives.
  10. Support and manage EDB's Vulnerability Disclosure program.
Requirements
  • Extensive experience working with developers and driving application security standards.
  • Experience securing CI/CD pipelines enabling strong security controls through the implementation of commercial and custom-built tooling.
  • Conduct application design reviews and support the development of compensating security solutions.
  • Drive the integration of secure development standards, tools, and processes into the development lifecycle.
  • Experience in threat modeling frameworks and processes.
  • Experience performing code audits on internal and open-source libraries.
  • Experience with DAST, SAST, SCA, as well as manual testing techniques.
  • Ability to demonstrate strategic thinking beyond the specific responsibilities of the role.
  • Effective communication skills with the ability to translate technical concerns into business risk impacts.
  • Personal management of multiple projects, security events, and incidents as required for the role.
  • Seek to understand, lead with a collaboration-first approach.
  • Experience assessing technical footprints found within on-prem and cloud environments.
  • Strong experience in NIST SSDF, BSIMM, OWASP SAMM, or similar frameworks.
What Will Give You an Edge
  • RedTeam knowledge and experience.
  • Experience performing security code reviews.
  • Experience with IaaS cloud infrastructure, Infrastructure as Code, Kubernetes container technologies, and software-oriented architecture.
  • Knowledge of the MITRE ATT&CK Framework and attack chains.
  • Experience building and operating security tools in multiple operating systems and various languages (C, Go, JavaScript, Python, Ruby, etc).
About EDB

EDB is committed to supporting our employees' overall well-being by offering a range of benefits and resources to promote a healthy work-life balance and wellness. We provide access to CuraLinc to aid employees in health and wellness tips and practices, as well as Wellness Fridays extending to December 2024. Check out our career site for more information on perks and benefits and reach out to our Talent Acquisition team for region-specific benefits.

We know it takes a unique mix of people and skills to help us in our mission to supercharge Postgres, and we understand that not everyone will check every box. We'd love to hear from you and want you to apply.

EDB is proud to be an equal opportunity workplace. We celebrate diversity and are committed to creating an inclusive environment for all employees. EDB was built on a commitment to trust and respect each other and to embrace an array of people and ideas. These values remain at the center of our culture and are key to our company's integrity.



  • Jefferson City, Missouri, United States Oracle Full time

    Job DescriptionWe are seeking a highly skilled Senior Application Security Engineer to join our team at Oracle. As a key member of our Security Tools organization, you will play a critical role in advancing the state-of-the-art for developers through Static Application Security Testing (SAST) and Software Composition Analysis (SCA)...


  • Jefferson City, Missouri, United States State of Missouri Full time

    Job SummaryThe State of Missouri is seeking a highly skilled Applications Security Manager to join our Information Technology Services Division (OA-ITSD). This role will play a critical part in assessing and improving our application security posture and secure coding processes across the enterprise.Key ResponsibilitiesPartner with Application Development...


  • Jefferson City, Missouri, United States Walden Security Full time

    About the RoleWalden Security is seeking a highly skilled and experienced Court Security Officer to join our team. As a Court Security Officer, you will be responsible for providing armed security to courthouses under the USMS contract.Key ResponsibilitiesPerform entrance control, enforcing the District's entry and identification system, and operating...


  • Kansas City, Missouri, United States Valiant Solutions Full time

    Job Title: Senior Application Security EngineerWe are seeking a highly skilled Senior Application Security Engineer to join our team at Valiant Solutions. As a key member of our security team, you will be responsible for designing and implementing our client's AppSec program, including tool deployment and configuration.Key Responsibilities:Design and...


  • Jefferson City, Missouri, United States Walden Security Full time

    About Walden SecurityWe are a leading provider of integrated contract security services, offering physical and virtual guarding to commercial and government clients across the United States. Our company is built on a foundation of family values, treating our employees like family and providing them with the support and training they need to succeed.Job...


  • Kansas City, Missouri, United States Valiant Solutions Full time

    About the RoleWe are seeking a highly skilled Senior Application Security Engineer to lead our AppSec program. As a key member of our team, you will be responsible for designing, implementing, and operating our client's SAST product, with a SaaS tool as the foundation.Key ResponsibilitiesDesign and implement the client's AppSec program, including tool...


  • Jefferson City, Missouri, United States Highmark Health Full time

    Job SummaryThe Senior Enterprise Security Architect will serve as the most senior security architect and advanced technology analyst in the company. The incumbent will synthesize and simplify complex needs such as business capability, operational efficiency, regulatory, security and privacy considerations into architecture and system design, and present...


  • Kansas City, Missouri, United States Zelis Healthcare Full time

    About the RoleZelis Healthcare is seeking a highly skilled Application Security Engineer to join our team. As a key member of our corporate application development teams, you will be responsible for ensuring the security of our applications and data.Key ResponsibilitiesCollaborate with corporate stakeholders to understand regulatory, industry, and...


  • Jefferson City, Missouri, United States Highmark Health Full time

    Job SummaryThe Chief Information Security Officer (CISO) serves as the most senior security architect and advanced technology analyst in the company. The incumbent synthesizes and simplifies complex needs such as business capability, operational efficiency, regulatory, security and privacy considerations into architecture and system design, and presents...


  • Jefferson City, Missouri, United States Centene Full time

    Job Title: Cloud Platform Engineering ManagerCentene is seeking a highly skilled Cloud Platform Engineering Manager to lead our cloud services unit and oversee the design and management of our cloud systems, applications, policies, and strategy.Key Responsibilities:Lead a team of cloud engineers to manage and maintain our cloud infrastructureDevelop and...

  • Security Specialist

    2 weeks ago


    Jefferson City, Missouri, United States SSM Health Full time

    Job SummaryAs a Security Officer at SSM Health, you will play a critical role in maintaining a safe and secure environment for patients, visitors, and staff. Your primary responsibilities will include conducting regular rounds to identify potential safety and security risks, responding to incidents, and promoting a culture of safety and security throughout...

  • Security Officer

    6 days ago


    Kansas City, Missouri, United States Citadel Security USA Full time

    Job Title: Security OfficerCitadel Security USA is seeking a highly skilled and experienced Security Officer to join our team. As a Security Officer, you will be responsible for maintaining a safe and secure environment for our clients and their properties.Key Responsibilities:Conduct regular patrols of the facility to detect and deter potential...

  • Security Professional

    4 weeks ago


    Jefferson City, Missouri, United States SSM Heath Full time

    Job Summary:At SSM Health, we are seeking a highly skilled Security Officer to provide a safe and secure environment for our staff, patients, and visitors. As a Security Officer, you will be responsible for monitoring and responding to urgent facility matters, ensuring the well-being and safety of everyone on our premises.Key Responsibilities:Provide...

  • Security Specialist

    1 week ago


    Jefferson City, Missouri, United States SSM Heath Full time

    Job SummarySSM Heath is seeking a highly skilled Security Officer to provide a safe and secure environment for staff, patients, and visitors. As a first responder to urgent facility matters, this role is critical to the well-being of our community.Key ResponsibilitiesProvide security services to ensure a safe and secure environmentRespond to emergency...


  • Jefferson City, Missouri, United States SHI GmbH Full time

    Position OverviewThe Presales Solutions Engineer for Security will serve as a client-facing expert in security solutions. This role requires a consultative mindset towards security initiatives and a comprehensive understanding of how security technologies facilitate business operations. The Solutions Engineer will also be responsible for developing and...


  • Jefferson City, Missouri, United States Rose International Full time

    Job DescriptionWe are seeking a highly skilled Mobile App Developer to join our team at Rose International. As a key member of our IT department, you will be responsible for managing mobile devices and ensuring the security and compliance of our mobile infrastructure.Key ResponsibilitiesManage mobile devices using multiple mobile device management...

  • Security Officer

    1 week ago


    Kansas City, Missouri, United States Marksman Security Full time

    {"title": "Security Officer", "description": "Job SummaryAt Marksman Security, we are seeking a highly skilled and dedicated Security Officer to join our team. As a Security Officer, you will play a critical role in maintaining the safety and security of our clients\u2019 properties and assets.ResponsibilitiesPatrol designated areas to detect and prevent...


  • Kansas City, Missouri, United States Sunstates Security Full time

    Security Operations ManagerSunstates Security is seeking a highly skilled and experienced Security Operations Manager to lead our Kansas City area operations. As a key member of our team, you will be responsible for the daily functioning of a portfolio of contract sites, including operations, customer service, personnel management, security, and safety in...


  • Jefferson City, Missouri, United States Computer Service Professionals Inc Full time

    Job Title: Technical Services EngineerWe are seeking a highly skilled Technical Services Engineer to join our team at Computer Service Professionals Inc. in Jefferson City, MO.Job Summary:The Technical Services Engineer will be responsible for analyzing, installing, and maintaining various types of hardware and software, including PC's, Servers, Switches,...


  • Jefferson City, Missouri, United States Centene Corporation Full time

    Job Title: Senior Site Reliability EngineerCentene Corporation is seeking a highly skilled Senior Site Reliability Engineer to join our team. As a key member of our technology team, you will be responsible for leading projects that focus on managing and maintaining optimum platform infrastructure performance, reliability, and security.Key...