Application Security Engineer
3 weeks ago
The Opportunity
We are seeking an experienced Application Security Engineer to join our Software Security team and take charge of ensuring the security and integrity of our software applications. The ideal candidate will have advanced knowledge of secure software development, extensive experience with identifying vulnerabilities, and the ability to implement robust security solutions. This role will require collaboration with development teams, security architects, and other stakeholders to integrate security best practices into all stages of the software development lifecycle.
The Impact
Your key responsibilities will consist of the following to ensure applications are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.
- Conduct in-depth security assessments, including vulnerability scanning, and code reviews.
- Leverage automated tools and manual testing techniques to identify, risk assess and prioritize and propose mitigation strategies for identified threats and application-level vulnerabilities (e.g., OWASP Top 10, etc.) ensuring our applications meet security standards and reducing exposure to data breaches.
- Collaborate with security architects to design secure application architectures that align with industry best practices.
- Ensure secure coding practices are followed, and security controls are incorporated into software designs.
- Conduct detailed threat modeling to identify attack vectors and potential weaknesses.
- Collaborate with our SDLC Council to develop and maintain secure coding standards, empowering developers to integrate security into the development process.
Partner with DevOps teams to implement security within CI/CD (continuous integration & delivery) pipelines for automated and seamless deployment of secure code. - Assist in incident response activities related to application security breaches, providing rapid identification and mitigation guidance.
- Ensure compliance with security regulations, frameworks, and industry standards such as OWASP.
- Leverage reporting tools to demonstrate the overall risk through metrics (KPIs, KRIs, OKRs) of vulnerabilities and code defects to MassMutual’s cyber assets for various team leaders and executive leadership for risk prioritization and enablement of risk-based decision-making.
- Stay up to date with the latest security threats, vulnerabilities, and industry trends to inform and improve security strategies.
- Strong problem-solving abilities and analytical thinking.
- Excellent communication skills to explain security issues to both technical and non-technical stakeholders.
- A team player with the ability to work in a collaborative, fast-paced environment.
The Minimum Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
- Minimum of 5+ years of experience in application security, penetration testing, or secure software development.
The Ideal Qualifications
- Relevant security certifications such as CEH, OSCP, or GWAPT) from an industry recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2, etc.)
- Strong knowledge of secure software development methodologies, including threat modeling, code reviews, and static/dynamic analysis.
- Experience in integrating security into DevOps (DevSecOps) and CI/CD environments.
- Strong technical knowledge of web application security, cloud security (AWS, Azure, GCP), mobile security, infrastructure as code (IaC), container security, and API security.
- Familiarity with SAST, DAST, and IAST tools.
- Deep understanding of common vulnerabilities (e.g., OWASP Top 10) and their mitigations.
- Advanced understanding and experience with writing source code (e.g., JavaScript, Java, C/C++/C#, Python, etc.) and familiarity with software security frameworks (e.g., Maven, Node, Gradle, etc.).
- Experience with identifying security vulnerabilities/defects in dockers, containers, and Kubernetes.
- Experience with cloud deployment and automation tools (Terraform, GitHub Actions, Jenkins, AWS Cloud Formation Templates, Secrets Managers).
- Knowledge of compliance and regulatory frameworks (SOC 2, etc.).
What to Expect as Part of MassMutual and the Team
- Focused one-on-one meetings with your manager
- Access to mentorship opportunities
- Networking opportunities including access to Asian, Hispanic/Latinx, African American, women, LGBTQ, veteran and disability-focused Business Resource Groups
- Access to learning content on Degreed and other informational platforms
- Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits
#LI-SC1
MassMutual is an Equal Employment Opportunity employer Minority/Female/Sexual Orientation/Gender Identity/Individual with Disability/Protected Veteran. We welcome all persons to apply. Note: Veterans are welcome to apply, regardless of their discharge status.If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.
-
Application Security
3 weeks ago
Springfield, United States Undisclosed Full timep>The OpportunityWe are seeking an experienced Application Security Engineer to join our Software Security team and take charge of ensuring the security and integrity of our software applications. The ideal candidate will have advanced knowledge of secure software development, extensive experience with identifying vulnerabilities, and the ability to...
-
Network Security Engineer, TS/SCI
2 days ago
Springfield, United States GuidePoint Security Full timeGuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...
-
Application Security Engineer
2 weeks ago
Springfield, MA, United States MassMutual Full timeThe OpportunityWe are seeking an experienced Application Security Engineer to join our Software Security team and take charge of ensuring the security and integrity of our software applications. The ideal candidate will have advanced knowledge of secure software development, extensive experience with identifying vulnerabilities, and the ability to implement...
-
Application Engineer
4 weeks ago
Springfield, Illinois, United States Emerson Full timeJob Title: Application Engineer - SoutheastWe are seeking a skilled Application Engineer to join our team in the Southeast region. As an Application Engineer, you will be responsible for overseeing and managing projects related to feeding systems in our organization.Key Responsibilities:Coordinate and lead projects from conception to completion, ensuring...
-
Security Engineer II
2 months ago
Springfield, United States Armavel, LLC Full timeJob DescriptionJob DescriptionSecurity Engineer IIThe Security Engineer II provides technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation. Responsible for designing and implementing solutions for protecting the confidentiality, integrity and availability of sensitive...
-
Security Engineering Manager
4 weeks ago
Springfield, Illinois, United States State of Illinois Full timeJob SummaryThe State of Illinois is seeking a highly skilled Security Engineering Manager to join our team. As a key member of our IT department, you will be responsible for creating and implementing a comprehensive cybersecurity program that protects our state's sensitive information and systems.Key ResponsibilitiesDevelop and implement security standards...
-
Cyber Security Engineer
4 weeks ago
Springfield, Virginia, United States The MITRE Corporation Full timeCyber Security Engineering ChallengesMITRE is a not-for-profit corporation committed to working for the public interest. Our R&D centers create lasting impact in fields like cybersecurity, healthcare, and defense.We offer competitive benefits, professional development opportunities, and a culture of innovation that values diversity, inclusion, and...
-
Transportation Security Officer
4 weeks ago
Springfield, Illinois, United States Transportation Security Administration Full timeJob SummaryAs a Transportation Security Officer with the Transportation Security Administration, you will play a critical role in ensuring the safety and security of the nation's transportation systems. Your primary responsibility will be to screen passengers and their belongings for prohibited items, while also providing excellent customer service to the...
-
Security Testing Engineer
1 week ago
Springfield, United States Foxhole Technology Full timeOverview Job Title: Security Testing Engineer Location: Springfield, VA Clearance: Secret Telework: Hybrid Discover an exciting career at Foxhole Technology, an innovative IT Engineering firm founded in 2007. As leaders in cybersecurity, DEVSEC OPS, Agile Developemnt, Cloud and IT support for federal civilian and defense agencies, we're at the...
-
Cyber Security Engineer
3 weeks ago
Springfield, United States TRIAEM LLC Full timeCyber Security Engineer (Expert)Overall Assignment Description: Expert Cyber Security Engineers capture and refine information security requirements and ensure that the requirements are integrated into information technology component products and information systems through purposeful security architecting, design, development, and configuration. Duties...
-
Cyber Security InfoSec Engineer
4 weeks ago
Springfield, Virginia, United States Leidos Full timeCyber Security Job DescriptionLeidos is seeking a Cyber Security InfoSec Engineer to provide support for a 150+ FTE technical development program. The Cyber Security Engineer will target, assess, exploit, and report risks and vulnerabilities of information systems to provide senior decision makers with actionable data.Key ResponsibilitiesIdentify and define...
-
Security Systems Engineer
4 weeks ago
Springfield, United States SAIC Full timeDescriptionThe DOS-Systems Integrity Division support team currently has an opening for a Security Systems Engineer to support the Department of State (DoS) Bureau of Diplomatic Technology (DT) PKI program. This program provides transparent security services in support of the Department’s goals to secure communications among Department staff and systems....
-
Applications Engineering Manager
4 weeks ago
Springfield, Missouri, United States The Timken Company Full timeAt The Timken Company, we are seeking a skilled Applications Engineering Manager to lead our Belt Engineering team. As a key member of our organization, you will be responsible for managing the team, ensuring they are trained in analysis tools and belt design, and providing expert consultation to customers on the right products for their needs.The ideal...
-
Applications Engineering Manager
4 weeks ago
Springfield, Illinois, United States The Timken Company Full timeApplications Engineering Manager Job SummaryWe are seeking an experienced Applications Engineering Manager to lead our Applications Engineering team in supporting belt customers. The successful candidate will have a strong background in engineering and leadership, with the ability to think strategically and provide input to the strategic planning process.Key...
-
Information Security Engineer
2 weeks ago
Springfield, United States INflow Federal Full timeAt INflow Federal, we're not just navigating the frontier of digital transformation; we're reshaping it. Our dedication to merging the prowess of humans and machines to solve complex problems has set us apart in designing and engineering solutions for the Department of Defense (DoD) networks. Here, every challenge is an opportunity to advance, and every...
-
Cyber Security Engineering Specialist
1 month ago
Springfield, Virginia, United States SITEC Consulting Full timeAbout SITEC ConsultingSITEC Consulting is an employee and customer-focused Information Technology and Professional Services Firm specializing in design, development, and delivery of state-of-the-art technology solutions, as well as cybersecurity, software, and systems engineering services.Job SummaryWe are seeking a highly skilled Cyber Security Engineering...
-
Security Officer
4 weeks ago
Springfield, Nebraska, United States First Coast Security Full timeJob Summary We are seeking a highly skilled and experienced Security Officer to join our team at First Coast Security in Springfield, NE. As a Security Officer, you will be responsible for providing security patrols and services to the site on a 24/7 basis, maintaining order and facilitating the protection of all site personnel, client property, premises,...
-
IT Systems Engineer
4 weeks ago
Springfield, Illinois, United States Cherokee Nation Businesses Full timeJob Summary:Cherokee Nation Businesses is seeking a highly skilled IT Systems Engineer to support the INSCOM G2 User Activity Monitoring (UAM) team. The successful candidate will work closely with the INSCOM G6 and GISA teams to ensure the security, integrity, and availability of the organization's information systems and data.Key Responsibilities:Implement...
-
Cyber Security Detections Engineer, Senior
1 week ago
Springfield, United States ManTech Full time**ManTech** is seeking a motivated, career and customer-oriented **Cyber Security Engineer** to join our team in the **Chantilly, VA** area. **Responsibilities include, but are not limited to:** + Work closely with customers on onboarding, updates and troubleshooting issues with cybersecurity tools + Provides customer support via phone, email, or...
-
Cyber Security Detections Engineer, Senior
4 weeks ago
Springfield, Illinois, United States ManTech Full timeJob SummaryManTech is seeking a motivated Cyber Security Engineer to join our team in the Chantilly, VA area. As a Cyber Security Engineer, you will work closely with customers on onboarding, updates, and troubleshooting issues with cybersecurity tools. You will provide customer support via phone, email, or messaging services to resolve issues and answer...