Application Security Engineer

3 weeks ago


Springfield, United States MassMutual Full time

The Opportunity

We are seeking an experienced Application Security Engineer to join our Software Security team and take charge of ensuring the security and integrity of our software applications. The ideal candidate will have advanced knowledge of secure software development, extensive experience with identifying vulnerabilities, and the ability to implement robust security solutions. This role will require collaboration with development teams, security architects, and other stakeholders to integrate security best practices into all stages of the software development lifecycle.

The Impact

Your key responsibilities will consist of the following to ensure applications are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.

  • Conduct in-depth security assessments, including vulnerability scanning, and code reviews.
  • Leverage automated tools and manual testing techniques to identify, risk assess and prioritize and propose mitigation strategies for identified threats and application-level vulnerabilities (e.g., OWASP Top 10, etc.) ensuring our applications meet security standards and reducing exposure to data breaches.
  • Collaborate with security architects to design secure application architectures that align with industry best practices.
  • Ensure secure coding practices are followed, and security controls are incorporated into software designs.
  • Conduct detailed threat modeling to identify attack vectors and potential weaknesses.
  • Collaborate with our SDLC Council to develop and maintain secure coding standards, empowering developers to integrate security into the development process.
    Partner with DevOps teams to implement security within CI/CD (continuous integration & delivery) pipelines for automated and seamless deployment of secure code.
  • Assist in incident response activities related to application security breaches, providing rapid identification and mitigation guidance.
  • Ensure compliance with security regulations, frameworks, and industry standards such as OWASP.
  • Leverage reporting tools to demonstrate the overall risk through metrics (KPIs, KRIs, OKRs) of vulnerabilities and code defects to MassMutual’s cyber assets for various team leaders and executive leadership for risk prioritization and enablement of risk-based decision-making.
  • Stay up to date with the latest security threats, vulnerabilities, and industry trends to inform and improve security strategies.
  • Strong problem-solving abilities and analytical thinking.
  • Excellent communication skills to explain security issues to both technical and non-technical stakeholders.
  • A team player with the ability to work in a collaborative, fast-paced environment.

The Minimum Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
  • Minimum of 5+ years of experience in application security, penetration testing, or secure software development.

The Ideal Qualifications

  • Relevant security certifications such as CEH, OSCP, or GWAPT) from an industry recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2, etc.)
  • Strong knowledge of secure software development methodologies, including threat modeling, code reviews, and static/dynamic analysis.
  • Experience in integrating security into DevOps (DevSecOps) and CI/CD environments.
  • Strong technical knowledge of web application security, cloud security (AWS, Azure, GCP), mobile security, infrastructure as code (IaC), container security, and API security.
  • Familiarity with SAST, DAST, and IAST tools.
  • Deep understanding of common vulnerabilities (e.g., OWASP Top 10) and their mitigations.
  • Advanced understanding and experience with writing source code (e.g., JavaScript, Java, C/C++/C#, Python, etc.) and familiarity with software security frameworks (e.g., Maven, Node, Gradle, etc.).
  • Experience with identifying security vulnerabilities/defects in dockers, containers, and Kubernetes.
  • Experience with cloud deployment and automation tools (Terraform, GitHub Actions, Jenkins, AWS Cloud Formation Templates, Secrets Managers).
  • Knowledge of compliance and regulatory frameworks (SOC 2, etc.).

What to Expect as Part of MassMutual and the Team

  • Focused one-on-one meetings with your manager
  • Access to mentorship opportunities
  • Networking opportunities including access to Asian, Hispanic/Latinx, African American, women, LGBTQ, veteran and disability-focused Business Resource Groups
  • Access to learning content on Degreed and other informational platforms
  • Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits

#LI-SC1

MassMutual is an Equal Employment Opportunity employer Minority/Female/Sexual Orientation/Gender Identity/Individual with Disability/Protected Veteran. We welcome all persons to apply. Note: Veterans are welcome to apply, regardless of their discharge status.
If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.
  • Application Security

    3 weeks ago


    Springfield, United States Undisclosed Full time

    p>The OpportunityWe are seeking an experienced Application Security Engineer to join our Software Security team and take charge of ensuring the security and integrity of our software applications. The ideal candidate will have advanced knowledge of secure software development, extensive experience with identifying vulnerabilities, and the ability to...


  • Springfield, United States GuidePoint Security Full time

    GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...


  • Springfield, MA, United States MassMutual Full time

    The OpportunityWe are seeking an experienced Application Security Engineer to join our Software Security team and take charge of ensuring the security and integrity of our software applications. The ideal candidate will have advanced knowledge of secure software development, extensive experience with identifying vulnerabilities, and the ability to implement...

  • Application Engineer

    4 weeks ago


    Springfield, Illinois, United States Emerson Full time

    Job Title: Application Engineer - SoutheastWe are seeking a skilled Application Engineer to join our team in the Southeast region. As an Application Engineer, you will be responsible for overseeing and managing projects related to feeding systems in our organization.Key Responsibilities:Coordinate and lead projects from conception to completion, ensuring...

  • Security Engineer II

    2 months ago


    Springfield, United States Armavel, LLC Full time

    Job DescriptionJob DescriptionSecurity Engineer IIThe Security Engineer II provides technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation. Responsible for designing and implementing solutions for protecting the confidentiality, integrity and availability of sensitive...


  • Springfield, Illinois, United States State of Illinois Full time

    Job SummaryThe State of Illinois is seeking a highly skilled Security Engineering Manager to join our team. As a key member of our IT department, you will be responsible for creating and implementing a comprehensive cybersecurity program that protects our state's sensitive information and systems.Key ResponsibilitiesDevelop and implement security standards...


  • Springfield, Virginia, United States The MITRE Corporation Full time

    Cyber Security Engineering ChallengesMITRE is a not-for-profit corporation committed to working for the public interest. Our R&D centers create lasting impact in fields like cybersecurity, healthcare, and defense.We offer competitive benefits, professional development opportunities, and a culture of innovation that values diversity, inclusion, and...


  • Springfield, Illinois, United States Transportation Security Administration Full time

    Job SummaryAs a Transportation Security Officer with the Transportation Security Administration, you will play a critical role in ensuring the safety and security of the nation's transportation systems. Your primary responsibility will be to screen passengers and their belongings for prohibited items, while also providing excellent customer service to the...


  • Springfield, United States Foxhole Technology Full time

    Overview Job Title: Security Testing Engineer Location: Springfield, VA Clearance: Secret Telework: Hybrid Discover an exciting career at Foxhole Technology, an innovative IT Engineering firm founded in 2007. As leaders in cybersecurity, DEVSEC OPS, Agile Developemnt, Cloud and IT support for federal civilian and defense agencies, we're at the...


  • Springfield, United States TRIAEM LLC Full time

    Cyber Security Engineer (Expert)Overall Assignment Description: Expert Cyber Security Engineers capture and refine information security requirements and ensure that the requirements are integrated into information technology component products and information systems through purposeful security architecting, design, development, and configuration. Duties...


  • Springfield, Virginia, United States Leidos Full time

    Cyber Security Job DescriptionLeidos is seeking a Cyber Security InfoSec Engineer to provide support for a 150+ FTE technical development program. The Cyber Security Engineer will target, assess, exploit, and report risks and vulnerabilities of information systems to provide senior decision makers with actionable data.Key ResponsibilitiesIdentify and define...


  • Springfield, United States SAIC Full time

    DescriptionThe DOS-Systems Integrity Division support team currently has an opening for a Security Systems Engineer to support the Department of State (DoS) Bureau of Diplomatic Technology (DT) PKI program. This program provides transparent security services in support of the Department’s goals to secure communications among Department staff and systems....


  • Springfield, Missouri, United States The Timken Company Full time

    At The Timken Company, we are seeking a skilled Applications Engineering Manager to lead our Belt Engineering team. As a key member of our organization, you will be responsible for managing the team, ensuring they are trained in analysis tools and belt design, and providing expert consultation to customers on the right products for their needs.The ideal...


  • Springfield, Illinois, United States The Timken Company Full time

    Applications Engineering Manager Job SummaryWe are seeking an experienced Applications Engineering Manager to lead our Applications Engineering team in supporting belt customers. The successful candidate will have a strong background in engineering and leadership, with the ability to think strategically and provide input to the strategic planning process.Key...


  • Springfield, United States INflow Federal Full time

    At INflow Federal, we're not just navigating the frontier of digital transformation; we're reshaping it. Our dedication to merging the prowess of humans and machines to solve complex problems has set us apart in designing and engineering solutions for the Department of Defense (DoD) networks. Here, every challenge is an opportunity to advance, and every...


  • Springfield, Virginia, United States SITEC Consulting Full time

    About SITEC ConsultingSITEC Consulting is an employee and customer-focused Information Technology and Professional Services Firm specializing in design, development, and delivery of state-of-the-art technology solutions, as well as cybersecurity, software, and systems engineering services.Job SummaryWe are seeking a highly skilled Cyber Security Engineering...

  • Security Officer

    4 weeks ago


    Springfield, Nebraska, United States First Coast Security Full time

    Job Summary We are seeking a highly skilled and experienced Security Officer to join our team at First Coast Security in Springfield, NE. As a Security Officer, you will be responsible for providing security patrols and services to the site on a 24/7 basis, maintaining order and facilitating the protection of all site personnel, client property, premises,...

  • IT Systems Engineer

    4 weeks ago


    Springfield, Illinois, United States Cherokee Nation Businesses Full time

    Job Summary:Cherokee Nation Businesses is seeking a highly skilled IT Systems Engineer to support the INSCOM G2 User Activity Monitoring (UAM) team. The successful candidate will work closely with the INSCOM G6 and GISA teams to ensure the security, integrity, and availability of the organization's information systems and data.Key Responsibilities:Implement...


  • Springfield, United States ManTech Full time

    **ManTech** is seeking a motivated, career and customer-oriented **Cyber Security Engineer** to join our team in the **Chantilly, VA** area. **Responsibilities include, but are not limited to:** + Work closely with customers on onboarding, updates and troubleshooting issues with cybersecurity tools + Provides customer support via phone, email, or...


  • Springfield, Illinois, United States ManTech Full time

    Job SummaryManTech is seeking a motivated Cyber Security Engineer to join our team in the Chantilly, VA area. As a Cyber Security Engineer, you will work closely with customers on onboarding, updates, and troubleshooting issues with cybersecurity tools. You will provide customer support via phone, email, or messaging services to resolve issues and answer...