Application Security Engineer

2 weeks ago


Atlanta, Georgia, United States Sirius XM Radio Inc Full time
About the Role

SiriusXM is seeking a highly skilled Application Security Engineer to join our security organization. As a key member of our team, you will play a vital role in supporting our technology objectives and ensuring the security of our software and applications.

Responsibilities
  • Design and implement secure features to enable developers to write secure code.
  • Facilitate the implementation and continual improvement of a secure Software Development Life Cycle (SDLC).
  • Secure tool creation, enabling security by default by building security and tooling into the software development process, conducting regular audits and tests to identify risks and prioritizing fixes.
  • Drive the technical implementation of our security solutions by providing necessary guidance and technical leadership to the SiriusXM engineering community.
  • Develop and improve the Application Security capabilities of SiriusXM by continually designing runbook procedures and expanding the scope and capabilities of security tools.
  • Consulting and systems development responsibilities for needs brought to the Application Security team by the business.
  • Write and design SDKs, containers images, guardrails, and testing suites.
  • Design, implementation, facilitation, and maintenance of tooling and frameworks to make adoption of security guardrails and best practices easier for developers when working in our code bases.
  • Participate in the design and implementation of applications, services, and infrastructure to ensure security and privacy design principles are being followed by performing security reviews and threat modeling.
  • Work within a collaborative team to develop scripts and software to solve for security automation and development needs.
  • Aid in secure code reviews, focused on security bug reduction.
  • Develop documentation, training, and security baselines to inform and educate the engineers, IT practitioners and developers on best practices.
  • Deploy, manage, and tune infrastructure used to protect our applications from common vulnerability exploitation, account takeover, and denial of service attacks.
  • Triage, escalate, and remediate vulnerabilities found as part of our vulnerability management program, bug bounty program and discovered in enterprise penetration tests.
  • Work with the product management teams to prioritize fixes for vulnerabilities and work with engineering teams to understand how to fix these issues.
  • Conducting root cause analysis of security findings to develop systematic improvements to develop processes, tooling, and security checks.
  • Fixing vulnerabilities, building in security telemetry/instrumentation, and adding security features to our products/applications.
  • Participate with the architecture and planning for company-wide security efforts.
  • Form a strong relationship with developer teams and serve as point of contact and security SME for questions arising around secure development.
  • Actively participate in all facets of the incident response lifecycle.
Requirements
  • 3+ years of software development experience, 2+ years of security (direct or adjacent) experience.
  • Proficient in at least one primary development language (preferably Python and Java/Scala).
  • Some experience with mobile application security preferred (Kotlin and Swift).
  • Experience with internal development for identity management, Cognito, OIDC, SAML, and SSO integration development.
  • Experience with AWS and/or GCP.
  • Experience calling REST and/or GraphQL APIs.
  • Experience administering application security tools such as SAST, SCA, DAST.
  • Knowledge of OWASP classifications and how to implement security checks for these vulnerabilities.
  • Ability to understand security code reviews.
  • Understanding of continuous integrations, testing, and delivery.
  • Ability to discover, document and fix security bugs.
  • Experience using Git and related, development processes in a professional setting.
  • Knowledge of JIRA (Issue/bug tracking), Confluence.
  • Experience writing educational documentation or knowledge bases.
  • Security mindset, self-starter, and ability to operate independently.
  • Be an organized and responsive problem solver.
  • Excellent oral/written presentation skills with the ability to teach and communicate effectively to developers and leadership.
  • Passionate about understanding complex systems.
  • Eager to learn, adapt, and improve your work.
  • Must have legal right to work in the U.S.
About SiriusXM

SiriusXM is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, national origin, ancestry, alienage or citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation or any other characteristic protected by applicable federal, state or local laws.

The requirements and duties described above may be modified or waived by the Company in its sole discretion without notice.



  • Atlanta, Georgia, United States Sirius XM Radio Inc Full time

    About SiriusXMSiriusXM is a leading audio entertainment company in North America, delivering music, sports, talk, news, comedy, and podcasts to millions of listeners. Our vision is to shape the future of audio, where everyone can be effortlessly connected to the voices, stories, and music they love.Job SummaryWe are seeking an experienced Application...


  • Atlanta, Georgia, United States Cox Communications Full time

    About the RoleWe are seeking a highly skilled Senior Application Security Engineer to join our team at Cox Communications. As a key member of our Application Security and Testing CoE, you will play a critical role in evaluating the security of our in-house and third-party software and devices.Key ResponsibilitiesEvaluate the security of in-house and...


  • Atlanta, Georgia, United States Cox Communications Full time

    {"h2": "About the Role", "p": "We are seeking a highly skilled Senior Application Security Engineer to join our team at Cox Communications. As a key member of our Application Security and Testing CoE, you will play a critical role in evaluating the security of our in-house and third-party software and devices. Your expertise will help us identify and...


  • Atlanta, Georgia, United States Stefanini North America and APAC Full time

    Job Title: Application Security EngineerStefanini North America and APAC is seeking a highly skilled Application Security Engineer to join our team.About the RoleWe are looking for a talented individual to work closely with our client's product teams and engineering groups to ensure secure architectures, patterns, and solutions are created and maintained.Key...


  • Atlanta, Georgia, United States CAMP Full time

    Job Title: Application Security EngineerCAMP Systems is a leading provider of aircraft compliance and health management services to the global business aviation industry. As a pioneer in its field, CAMP has established itself as the pre-eminent brand in the industry, with a strong presence in 13 locations worldwide.Our company has grown significantly since...


  • Atlanta, Georgia, United States Warner Bros. Discovery Full time

    About the RoleWe are seeking a highly skilled Sr. Application Security Engineer to join our team at Warner Bros. Discovery. As a key member of our Global Information and Content Security (GICS) team, you will play a critical role in ensuring the security of our mobile applications.Key ResponsibilitiesMaintain knowledge of current and emerging secure mobile...


  • Atlanta, Georgia, United States Insight Global Full time

    Job Title: Application Security EngineerWe are seeking a skilled Application Security Engineer to join our team remotely. As a key member of our security team, you will be responsible for ensuring the security and integrity of our software applications.Job Summary:The successful candidate will have a strong background in application security, with experience...


  • Atlanta, Georgia, United States CAMP Systems International, Inc. Full time

    About CAMP Systems International, Inc.CAMP Systems International, Inc. is a leading provider of aircraft compliance and health management services to the global business aviation industry. With a strong presence in 13 locations worldwide, the company has grown from a single location in 2001 to over 1,300 employees. CAMP's relationships with business aircraft...


  • Atlanta, Georgia, United States Genesis10 Full time

    Job Title: Application Security EngineerGenesis10 is seeking an experienced Application Security Engineer to join our team in Atlanta, GA. This is a 12+ month contract position.Description:We are looking for a skilled Application Security Engineer to conduct Static Application Security Test (SAST), Dynamic Application Security Test (DAST), and Source Code...


  • Atlanta, Georgia, United States Better Hire Full time

    About the RoleWe are seeking a highly skilled Application Security Engineer to join our team at Better Hire. As a key member of our security team, you will be responsible for ensuring the security and integrity of our cloud-based applications and infrastructure.Key ResponsibilitiesDesign and implement secure solutions for authentication and authorization,...


  • Atlanta, Georgia, United States FIRST SOFTSOLUTIONS INC Full time

    Job Title: Application & Cloud Container Security EngineerWe are seeking a highly skilled Application & Cloud Container Security Engineer to join our team at First SoftSolutions Inc.Job Summary:The successful candidate will have a deep understanding of cybersecurity and application security testing expertise to identify vulnerabilities in applications. They...


  • Atlanta, Georgia, United States Zelis Healthcare Full time

    Job Title: Application Security EngineerZelis Healthcare is seeking a highly skilled Application Security Engineer to join our team. As a key member of our corporate application development teams, you will be responsible for ensuring the security of our applications.Responsibilities:Partner with corporate stakeholders to understand regulatory, industry, and...


  • Atlanta, Georgia, United States ImagineX Consulting Full time

    Job OverviewImagineX Consulting is a software company that helps clients transform their businesses by embracing emerging technologies. We're looking for an Application Security Engineer to join our team.This is a 100% remote position with aggressive salary and bonus packages, and 401K matching. Must be comfortable working standard west coast hours.Key...


  • Atlanta, Georgia, United States ImagineX Consulting Full time

    Job OverviewImagineX Consulting is a software company that helps clients transform their businesses by embracing emerging technologies. We're looking for an Application Security Engineer to join our team.Key ResponsibilitiesProvide guidance and assistance to development personnel in understanding security vulnerabilities and remediation options.Collaborate...


  • Atlanta, Georgia, United States Saxon Global Full time

    Job Title: Application Security TesterWe are seeking a highly skilled Application Security Tester to join our team at Saxon Global. As an Application Security Tester, you will be responsible for identifying weaknesses and vulnerabilities in our applications and systems.Key Responsibilities:Identify and assess vulnerabilities in our applications and...


  • Atlanta, Georgia, United States Cloud Security Services Full time

    About the OpportunityCloud Security Services is seeking an experienced Azure DevOps Engineer to join our team. The ideal candidate will have a strong background in developing, testing, and integrating complex applications that leverage Azure B2C for authentication, Microsoft Graph API, and Azure B2C Custom Policies.ResponsibilitiesEnable customers to migrate...


  • Atlanta, Georgia, United States Compunnel Inc. Full time

    Job Title: Cloud Security EngineerWe are seeking a highly skilled Cloud Security Engineer to join our team at Compunnel Inc. The ideal candidate will have a strong background in cloud security, container security, and DevOps, with a focus on securing cloud-based applications and infrastructure.Key Responsibilities:Identify and mitigate security risks in...


  • Atlanta, Georgia, United States Osaic Full time

    Job Title: Director, Security EngineeringOsaic is seeking a highly skilled and experienced Director of Security Engineering and Operations to lead our security team. In this role, you will be responsible for developing and executing the overall security strategy, managing security engineering projects, and overseeing day-to-day security operations.Key...


  • Atlanta, Georgia, United States Innova Solutions Full time

    Job Title: Senior Security EngineerWe are seeking a highly skilled Senior Security Engineer to join our team at Innova Solutions. As a Senior Security Engineer, you will be responsible for designing, developing, and implementing secure cloud-based solutions for our clients.Key Responsibilities:Design and implement secure cloud-based architecturesDevelop and...


  • Atlanta, Georgia, United States Compunnel Inc. Full time

    Job Title: Cloud Security EngineerWe are seeking a highly skilled Cloud Security Engineer to join our team at Compunnel Inc. The ideal candidate will have a strong background in cloud security, container security, and DevOps, with a focus on securing cloud-based applications and infrastructure.Key Responsibilities:Identify and mitigate security risks in...