Senior Application Security Engineer
$97.1k - $161.8kM&T Bank
Overview: Responsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration. Provides advanced working guidance to technology teams and leadership in the areas of secure coding, application authentication, encryption, and quickly research and become competent in other areas as needed. Primary Responsibilities:
Clanton, Alabama, United States of America
- Develop and implement engineering's technical security policies and procedures, and performance of security measures,
- Scan and test applications for potential vulnerabilities and non-compliance with security standards,
- Partner with engineering teams during code reviews to identify potential security vulnerabilities and advise strategies to develop more secure code,
- Integrate security tools and processes into the software development and operations (DevOps) pipeline, including automation of security checks and scans to identify and fix vulnerabilities early in the development process.
- Lead training sessions for technology teams in one-on-one coaching and large team training sessions on secure coding practices and information system security best practices.
- Configure and manage automated tools and solutions to address security weaknesses in applications, systems, and infrastructure.
- Partner closely with incident response teams to mitigate the impact of incidents from application security vulnerabilities and identify necessary steps to remediate findings.
- Proactively recommend process enhancements and implement prioritized improvements within Cybersecurity team to enhance application security capabilities.
- Track current events, technological advancements, and changes in the secure application development landscape to anticipate how attackers may change their tactics, and implement adjustments to internal technologies, policies, and procedures.
- Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
- Complete other related duties as assigned.
- Partners primarily with individual contributors and leaders within Cybersecurity and Technology, and occasionally senior leaders within Cybersecurity.
- Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met.
- Proficient ability to use multiple Cybersecurity tools, specific to function.
- This role is used within Cybersecurity, typically in one of the following ways:
- Application Security - partners with engineers and developers to secure first-party and third-party code by reviewing the application, data, and systems it interacts with.
- Product Security - secures products by ensuring they are designed, developed, and delivered in a secure manner".
- Bachelor's degree and a minimum of 3 years' relevant work experience, or in lieu of a degree, a combined minimum of 7 years' higher education and/or work experience, including a minimum of 5 years software development or application security
- Prior experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
- Intermediate understanding of the Software Development Life Cycle (SDLC)
- Ability to train technologist and people leaders at various levels on secure application development, both in person and virtually
- Excellent communication and interpersonal skills
- Intermediate experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
- Understanding of common software weaknesses that impact cloud and web applications, beyond the Open Worldwide Application Security Project (OWASP) Top 10
- Demonstrable experience developing and maintaining automation for application security tasks and defect identification
- Experience developing enterprise applications
- Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments
- Certifications in the area of Application Security
- Proficient persuasive communication skills to gain buy-in of others in cybersecurity and technology teams
- Ability to create an effective learning environment that allows for maximum learner results
- Must be comfortable with providing 1-1 coaching for all levels of individual contributors and up to SVP management
- Ability to build and maintain effective relationships within and across multiple technical teams
- Prior experience utilizing continuous integration and continuous deployment (CI/CD) pipeline instrumentation
- Highly proficient at coding with one or two programming languages
- Highly proficient with Agile development methodologies and version control systems
- Experience defining and reviewing software security features and capabilities
Clanton, Alabama, United States of America
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer in United States vacancy
$150k - $196k
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States. This role offers the opportunity to strengthen application security across a...SeniorFull timeTemporary workRemote workWorldwide$125k - $160k
...0.00 - $160,000.00 / Year Other Compensation Annual Performance Bonus Eligible Job Category Cybersecurity, Application Security, Security Engineering Relocation Expense Covered No Employee Type FT Exempt Travel 5% Manage Others No Contact Information...SeniorRemote workRelocation- ...however, we are looking for someone with a stronger Application Security background. Certifications like DevSecOps and CISSP... .... Overall, the client is looking for a strong Senior Application Security Engineer with DevSecOps Team Lead-level experience . App Sec...Senior
- ...~6-8+ years of experience in Application Security, Product Security, or DevOps with a strong security focus. ~ Extensive hands-on experience with SAST, SCA, DAST , IaC scanning, and integrating security tools into modern CI/CD pipelines. ~ Proven ability to...SeniorRemote work
$100k - $130k
...organizations and over 50 percent of Fortune 100 companies. Learn more at bonterratech.com. About the Role As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to...SeniorFull timeLocal areaImmediate start- ...Joining the Information Security team, the full-time Senior Application Security Engineer will secure the platform throughout the software development lifecycle by defining secure coding practices, performing application security testing, and collaborating with engineering...SeniorFull timeRemote work
- ...Senior Application Security Engineer Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in web security, applied cryptography, software security vulnerabilities, IAM solutions, including federation...SeniorRemote work
$180k - $210k
...Senior Application Security Engineer At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products bring together users from across...SeniorWork at officeRemote work- ...Senior Application Security Engineer Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across...SeniorWork at officeRemote workWork from homeWeekend work
- ...Senior Application Security Engineer Poland The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global...SeniorPermanent employmentContract workRemote workWorldwideFlexible hours
- ...Senior Application Security Engineer This role has been designed as 'Hybrid' with an expectation that you will work on average 2 days per week from an HPE office. Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people...SeniorWork experience placementWork at office2 days per week
$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorContract workLocal areaRemote work- ...Senior Application Security Engineer Intapp is growing our application security team and is looking for a Senior Application Security Engineer. You'll focus on a subset of our products to understand them deeply and help development teams build products that are secure...SeniorRemote workHome officeFlexible hours
$60 - $62 per hour
...experience — talk with your recruiter to learn more. Base pay range $60.00/hr - $62.00/hr Hello We are looking for Senior Application Security Engineers Locations: Hybrid Roles in Charlotte, NC, Westlake, TX, Chandler, AZ and Minneapolis, MN – 3 days Onsite and 2 days...SeniorContract workH1bRemote work$180k - $225k
...Senior Application Security Engineer United States - Remote Opportunity About Us Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster...SeniorFull timeTemporary workPart timeRemote workWork from homeHome office$130k - $190k
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States. The Sr. Application Security Engineer will serve as the technical authority...SeniorTemporary workRemote workHome office$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management...SeniorFull timeWork experience placement$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorFull timeRemote work- ...prioritizing risks specifically related to application security. ? Develop, socialize, and implement... ...on application vulnerabilities, to senior management. ? Perform/coordinate... ...: Senior Application Security Engineer Mandatory Skills/Experience • 12...SeniorFlexible hours
$150k - $196k
Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and...SeniorFull timeTemporary work$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...SeniorFull timeFlexible hours- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...SeniorFull timeFlexible hours
- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...SeniorFull timeRemote work
$180k - $210k
Role Description We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: ~Set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities...SeniorFull timeFlexible hours- Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development...SeniorFull timeRemote work
- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...SeniorFull timeRemote workFlexible hours
- ...Job Description Job Description As a member of the Application Security team, you will help prevent and mitigate vulnerabilities by collaborating... ...all of these areas as needed: ● Manage the end-to-end engineering and integration of AI/ML-driven security solutions into our...SeniorFull timeTemporary workFlexible hours
$120k - $258.5k
...Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn... ...we build with AI. You’ll report to the Senior Manager of Application Security and partner closely with product engineering and DevOps, alongside our security peers...SeniorFull time$200k - $235k
...founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence... ...and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security...SeniorFull timeWork at officeWorldwide$180k - $205.5k
Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established...SeniorFull timeWork experience placementRemote workSleeping nights
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
Related searches
- network applications engineer United States
- hydraulic application engineer United States
- application engineering manager United States
- project application engineer United States
- application security engineer United States
- senior application security engineer United States
- application operations engineer United States
- application system engineer United States
- technical application engineer United States
- senior application support engineer United States







