Senior Application Security Engineer
$97.1k - $161.8kM&T Bank
Overview: Responsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration. Provides advanced working guidance to technology teams and leadership in the areas of secure coding, application authentication, encryption, and quickly research and become competent in other areas as needed. Primary Responsibilities:
Clanton, Alabama, United States of America
- Develop and implement engineering's technical security policies and procedures, and performance of security measures,
- Scan and test applications for potential vulnerabilities and non-compliance with security standards,
- Partner with engineering teams during code reviews to identify potential security vulnerabilities and advise strategies to develop more secure code,
- Integrate security tools and processes into the software development and operations (DevOps) pipeline, including automation of security checks and scans to identify and fix vulnerabilities early in the development process.
- Lead training sessions for technology teams in one-on-one coaching and large team training sessions on secure coding practices and information system security best practices.
- Configure and manage automated tools and solutions to address security weaknesses in applications, systems, and infrastructure.
- Partner closely with incident response teams to mitigate the impact of incidents from application security vulnerabilities and identify necessary steps to remediate findings.
- Proactively recommend process enhancements and implement prioritized improvements within Cybersecurity team to enhance application security capabilities.
- Track current events, technological advancements, and changes in the secure application development landscape to anticipate how attackers may change their tactics, and implement adjustments to internal technologies, policies, and procedures.
- Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
- Complete other related duties as assigned.
- Partners primarily with individual contributors and leaders within Cybersecurity and Technology, and occasionally senior leaders within Cybersecurity.
- Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met.
- Proficient ability to use multiple Cybersecurity tools, specific to function.
- This role is used within Cybersecurity, typically in one of the following ways:
- Application Security - partners with engineers and developers to secure first-party and third-party code by reviewing the application, data, and systems it interacts with.
- Product Security - secures products by ensuring they are designed, developed, and delivered in a secure manner".
- Bachelor's degree and a minimum of 3 years' relevant work experience, or in lieu of a degree, a combined minimum of 7 years' higher education and/or work experience, including a minimum of 5 years software development or application security
- Prior experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
- Intermediate understanding of the Software Development Life Cycle (SDLC)
- Ability to train technologist and people leaders at various levels on secure application development, both in person and virtually
- Excellent communication and interpersonal skills
- Intermediate experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
- Understanding of common software weaknesses that impact cloud and web applications, beyond the Open Worldwide Application Security Project (OWASP) Top 10
- Demonstrable experience developing and maintaining automation for application security tasks and defect identification
- Experience developing enterprise applications
- Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments
- Certifications in the area of Application Security
- Proficient persuasive communication skills to gain buy-in of others in cybersecurity and technology teams
- Ability to create an effective learning environment that allows for maximum learner results
- Must be comfortable with providing 1-1 coaching for all levels of individual contributors and up to SVP management
- Ability to build and maintain effective relationships within and across multiple technical teams
- Prior experience utilizing continuous integration and continuous deployment (CI/CD) pipeline instrumentation
- Highly proficient at coding with one or two programming languages
- Highly proficient with Agile development methodologies and version control systems
- Experience defining and reviewing software security features and capabilities
Clanton, Alabama, United States of America
Vacancy posted 15 hours ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer in United States vacancy
- ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software...SeniorFull time
- Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Application Security Engineer for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD. The main function of senior application security engineer is to plan, coordinate...SeniorContract work
- ...available! The details are below. Beware of scams. S3 never asks for money during its onboarding process. Job Title: Senior Application Security Engineer (AI/ML) Contract Length: 6+ months Location: Iselin NJ 08830/ Charlotte, NC/ Dallas, TX/ Phoenix, AZ 3 days...SeniorContract workRemote workVisa sponsorshipShift work3 days per week
- ...7+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has... ...meet you! ABOUT THE ROLE We are looking for a Senior Application Security Engineer to develop AI-enabled secure code scanning and integrate...SeniorFlexible hours
$80 - $85 per hour
...risks specifically related to application security. ? Develop, socialize, and implement... ...vulnerabilities, to senior management. ? Perform/coordinate application... ...Requirements Senior Application Security Engineer Mandatory Skills/Experience...SeniorContract workFlexible hours- ...Senior Application Security Engineer We are seeking a highly skilled and proactive Senior Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This...SeniorRemote work
- ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution...SeniorRemote workAll shiftsShift work
- ...Senior Application Security Engineer Become a founding member of the Application Security team at CookUnity. You'll work closely with disparate groups inside of CookUnity's engineering organization, ranging from our Infrastructure and Software Engineering teams to...SeniorRemote workFlexible hours
$130k - $180k
...physicians, providing critical information about the right treatments for the right patients, at the right time. Senior Application Security Engineer Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to join our...Senior$160k - $240k
..., and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before... ...and integrity of our customers' data. As our first Application Security Engineer , you will take on a dynamic and high impact role. You will...SeniorHome officeFlexible hours- ...Title: Senior Application Security Engineer Location: Austin, TX / Dallas, TX (hybrid) Reports To: Sr. Manager, Cybersecurity About Hippo Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us....SeniorTemporary workFlexible hours
- ...Job Description Senior Application Security Engineer - Threat Modeling & AI Security *]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height...SeniorContract workRemote work
$165k - $190k
...Senior Application Security Engineer Los Angeles, California, United States Tatari is on a mission to revolutionize TV advertising. Founded in 2016 to help transform the antiquated world of TV advertising through the intelligent application of AI and machine learning...SeniorWork at office2 days per week- ...Senior Application Security Engineer Poland The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global...SeniorPermanent employmentContract workRemote workWorldwideFlexible hours
- ...Senior Application Security Engineer At CertiPath, you'll join a fast-moving team with a meaningful mission, delivering high-assurance identity and trust solutions that matter. We are seeking a Senior Application Security (AppSec) Engineer to strengthen our security...SeniorWork at officeLocal area2 days per week3 days per week
$120k - $150k
...Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware... ...delivering high quality patient care. IDEXX is seeking a Senior Application Security Engineer to join our Product & Application Security team...SeniorLocal areaRemote workWorldwideFlexible hours- A leading logistics and transportation services company in Atlanta is looking for a highly motivated Application Security Engineer to bolster their security team. This role involves conducting security assessments, collaborating with development teams, and ensuring security...Senior
- A leading software company in San Francisco is looking for an Application Security Engineer. This hybrid role requires strong experience in automated vulnerability scanning and penetration testing. Responsibilities include developing secure coding practices, conducting...Senior
- ...Application Security Engineer Position will be hybrid (4 days in office and 1 day remote (remote day can be flexible). 10+ years of experience Strong experience designing and implementing AppSec programs within DevSecOps, including integration of SAST, SCA, DAST, and...SeniorWork at officeRemote workFlexible hoursShift work
$165k - $225k
...Senior Application Security Engineer Denver, CO or Long Beach, CA or SF Bay Area, CA Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. True Anomaly delivers decisive capabilities for...SeniorShift work$128k - $181.25k
...Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life's experiences unforgettable. We believe there is extraordinary power in the self-expression. That's why our family of brands helps customers create products and capture moments...SeniorRemote work$110k - $130k
A logistics services company located in Boston is seeking an experienced Application Security Engineer to enhance security across its applications. The ideal candidate will possess a strong technical background in software development, secure coding, and vulnerability assessments...Senior$110k - $130k
A leading logistics company is looking for an Application Security Engineer to join their security team in Raleigh, North Carolina. The ideal candidate will ensure the security of applications and data throughout the software development lifecycle, conducting assessments...Senior$180k - $220k
...Senior Application Security Engineer, AI and Machine Learning San Francisco, California, United States; Seattle, Washington, United States Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing...SeniorWork at officeWork from homeFlexible hours2 days per week$325k - $405k
A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience...SeniorRemote job$62k - $141k
Phase2 Technology is looking for an Application Security Engineer to work with clients on maintaining application security. This role involves remediating security flaws, leading discussions on best practices, and conducting dynamic and static testing using tools like Burp...SeniorRemote job- A leading AI research firm is seeking a Security Engineer, Application Security. In this role, you will identify and mitigate security vulnerabilities through assessments and collaboration with development teams. The ideal candidate has extensive experience in cybersecurity...SeniorRemote job
- ...Senior Application Security Engineer This role has been designed as 'Hybrid' with an expectation that you will work on average 2 days per week from an HPE office. Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people...SeniorWork experience placementWork at office2 days per week
- ...Key Responsibilities:- Secure Software Development Lifecycle... ...Define and continuously improve application security quality gates and... ...in alignment with Modern Engineering SDLC practices. Lead the... ...consistent with expectations for senior Bank engineers. dvocate...Senior
$130k - $218k
A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants...SeniorRemote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!
Related searches
- application system engineer United States
- junior application support engineer United States
- hydraulic application engineer United States
- senior application security engineer United States
- application performance engineer United States
- application engineer United States
- application engineering manager United States
- network applications engineer United States
- cnc applications engineer United States
- field applications engineer United States


