Senior Application Security Engineer
1 week ago
This role offers a hybrid work schedule at our Wilmington, DE Tech Hub.
Overview:
Responsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration. Provides advanced working guidance to technology teams and leadership in the areas of secure coding, application authentication, encryption, and quickly research and become competent in other areas as needed.
Primary Responsibilities:
- Develop and implement engineering's technical security policies and procedures, and performance of security measures,
- Scan and test applications for potential vulnerabilities and non-compliance with security standards,
- Partner with engineering teams during code reviews to identify potential security vulnerabilities and advise strategies to develop more secure code,
- Integrate security tools and processes into the software development and operations (DevOps) pipeline, including automation of security checks and scans to identify and fix vulnerabilities early in the development process.
- Lead training sessions for technology teams in one-on-one coaching and large team training sessions on secure coding practices and information system security best practices.
- Configure and manage automated tools and solutions to address security weaknesses in applications, systems, and infrastructure.
- Partner closely with incident response teams to mitigate the impact of incidents from application security vulnerabilities and identify necessary steps to remediate findings.
- Proactively recommend process enhancements and implement prioritized improvements within Cybersecurity team to enhance application security capabilities.
- Track current events, technological advancements, and changes in the secure application development landscape to anticipate how attackers may change their tactics, and implement adjustments to internal technologies, policies, and procedures.
- Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
- Complete other related duties as assigned.
Scope of Responsibilities:
- Partners primarily with individual contributors and leaders within Cybersecurity and Technology, and occasionally senior leaders within Cybersecurity.
- Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met.
- Proficient ability to use multiple Cybersecurity tools, specific to function.
This role is used within Cybersecurity, typically in one of the following ways:
Application Security – partners with engineers and developers to secure first-party and third-party code by reviewing the application, data, and systems it interacts with.
- Product Security – secures products by ensuring they are designed, developed, and delivered in a secure manner".
Manager Responsibilities:
No supervisory responsibilities
Education and Experience Required:
- Bachelor's degree and a minimum of 3 years' relevant work experience, or in lieu of a degree, a combined minimum of 7 years' higher education and/or work experience, including a minimum of 5 years software development or application security
- Prior experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
- Intermediate understanding of the Software Development Life Cycle (SDLC)
- Ability to train technologist and people leaders at various levels on secure application development, both in person and virtually
- Excellent communication and interpersonal skills
Education and Experience Preferred:
- Intermediate experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
- Understanding of common software weaknesses that impact cloud and web applications, beyond the Open Worldwide Application Security Project (OWASP) Top 10
- Demonstrable experience developing and maintaining automation for application security tasks and defect identification
- Experience developing enterprise applications
- Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments
- Certifications in the area of Application Security
- Proficient persuasive communication skills to gain buy-in of others in cybersecurity and technology teams
- Ability to create an effective learning environment that allows for maximum learner results
- Must be comfortable with providing 1-1 coaching for all levels of individual contributors and up to SVP management
- Ability to build and maintain effective relationships within and across multiple technical teams
- Prior experience utilizing continuous integration and continuous deployment (CI/CD) pipeline instrumentation
- Highly proficient at coding with one or two programming languages
- Highly proficient with Agile development methodologies and version control systems
- Experience defining and reviewing software security features and capabilities
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $102, $171, USD). The successful candidate's particular combination of knowledge, skills, and experience will inform their specific compensation.
Location
Wilmington, Delaware, United States of America
-
Senior Lead Software Engineer
2 weeks ago
Wilmington, Delaware, United States JPMorganChase Full timeJOB DESCRIPTIONBe an integral part of an agile team that's constantly pushing the envelope to enhance, build, and deliver top-notch technology products.As a Senior Lead Software Engineer - AWS/Agentic AI at JPMorgan Chase within Consumer and Community Banking-Home Loan Originations team, you are an integral part of an agile team that works to enhance, build,...
-
Senior Software Test Engineer
2 weeks ago
Wilmington, Delaware, United States CSC Full timeSenior Software Test EngineerWilmington, DEMonday to Friday, 8:00 a.m. – 5:00 p.m.Hybrid Onsite ( three days in office per week and 2 days' work from home)CSC is seeking a highly skilled and detail-orientedSenior Software Test Engineerwith a strong background in test automation to join our dynamic Quality Assurance team. In this role, you will play a...
-
Wilmington, Delaware, United States Jobs via Dice Full timeDice is the leading career destination for tech experts at every stage of their careers. Our client, Alltech Consulting Services, Inc., is seeking the following. Apply via Dice todayJob Title Senior Databricks Engineer With Python ExperienceLocation: Wilmington, DE 5 days onsite role, no hybridLong Term Contract roleJob Description:We are looking for a...
-
Senior Lead Software Engineer
1 week ago
Wilmington, Delaware, United States JPMorganChase Full timeJob DescriptionBe an integral part of an agile team that's constantly pushing the envelope to enhance, build, and deliver top-notch technology products.As a Senior Lead Software Engineer - Python/AWS/API/Django at JPMorgan Chase within the Corporate Sector, you are an integral part of an agile team that works to enhance, build, and deliver trusted...
-
Lead Web Application Penetration Tester
4 days ago
Wilmington, Delaware, United States M&T Bank Full time $121,699 - $202,831This role offers a hybrid work schedule at our Buffalo, NY Tech Hub.Overview: Searches for application and system weaknesses that are exploitable, and partners with technology, cybersecurity, and risk teams to remediate any found weaknesses. Partners with technology leaders to train engineering and infrastructure teams to develop new applications...
-
Senior Engineer
1 week ago
Wilmington, Delaware, United States GE Vernova Full time $111,200 - $213,200Job Description SummaryThe Senior Engineer performs a leadership role within GE Hitachi's Plant Systems Integration teams which focus on development of new advanced nuclear reactor projects (SMR and SFR). You will be responsible for engineering design support within a team environment, working with other disciplines, project/product stakeholders, partner...
-
Senior Software Engineer
6 days ago
Wilmington, Delaware, United States Vantaca+HOAi Full timeVantaca just achieved unicorn status with a $1.25B valuation, so it's safe to say we're past the "scrappy startup phase." We're not just building a successful company – we're building the category-defining platform that will transform how an entire industry operates. Here's the reality of our trajectory:Growing 100% year-over-yearOur AI product (HOAi)...
-
Wilmington, Delaware, United States Hubbell Incorporated Full timeJob Overview As an early member of the Hubbell Additive Manufacturing Center of Excellence (AM CoE) in Wilmington, MA, this role will serve as a subject matter expert in the application of polymer powder-based technologies (SLS / MJF), photopolymer 3D printing, and other polymer AM technologies. Our mission is to drive production-scale 3D printing of Hubbell...
-
Staff Engineer, Field Applications
2 days ago
Wilmington, Delaware, United States Analog Devices Full time $138,000 - $189,750About Analog DevicesAnalog Devices, Inc. (NASDAQ: ADI ) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, and software technologies into solutions that help drive advancements in digitized factories, mobility, and digital healthcare, combat climate...
-
Senior Engineer
1 week ago
Wilmington, Delaware, United States GE Vernova Full time $113,200 - $188,800Job Description SummaryThe Senior Engineer – Mechanical Component Design will be responsible for Mechanical Component Design activities that support GE Vernova Hitachi's (GVH) BWRX-300 Small Modular Reactor (SMR) Plant Equipment Design.They will develop design specifications, create, and mature design concepts, provide procurement support, generate...