Security Engineering Analyst — AppSec | Senior
Core
Strengthen application security across the software development lifecycle by defining secure practices, integrating automated controls into CI/CD pipelines, and supporting secure AWS architectures.
Role type
Senior AppSec Engineer (DevSecOps)
Builds
Secure software development lifecycle, automated security gates in CI/CD, and secure cloud architectures
Domain
Application Security, Cloud Security, DevSecOps
Required skills
SSDLC, Secure Software Development, Security by Design, Threat Modeling, OWASP Top 10, OWASP ASVS, Secure Coding, API Security, Microservices Architecture, DevOps, CI/CD, DevSecOps, Application Vulnerability Management
Preferred skills
AWS API Gateway, AWS Security Hub
Technologies
SAST, DAST, SCA, Secret Scanning, IaC Scanning, Container Security, SBOM, AWS
Responsibilities
Define and improve corporate SSDLC; Establish and implement Security Gates in CI/CD pipelines; Conduct security assessments and threat modeling during architecture stages; Integrate security tools (SAST, DAST, SCA, etc.) into pipelines; Support secure architecture initiatives in AWS environments; Conduct security-focused code reviews and assess APIs/microservices.
Seniority
Senior, hands-on IC