Source description
About the role
LINKED IN MUST HAVE PHOTO AND LOCATION LISTED
On‑Call & Operational Support
Participate in a rotational on‑call schedule , including off‑hours, nights, weekends, and holidays , to support a 24/7 environment.
Respond to security incidents and operational escalations outside of standard business hours as required.
Support incident investigation, containment, eradication, and post‑incident reviews.
Senior Application Security Engineer – Blue Team
Who You Are
A defensive security practitioner with strong engineering fundamentals and the ability to write code when needed.
Deeply experienced in protecting applications, platforms, and data through detection, prevention, and response.
Passionate about operating secure, resilient systems at scale and improving security posture through automation.
Highly skilled in application, cloud, data, and network security from a Blue Team / defensive operations perspective.
Comfortable operating in complex environments, including modern cloud-native stacks and legacy platforms.
Able to respond calmly and effectively during incidents, including during off-hours.
Role Responsibilities
Blue Team Operations & Defense
Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and networks.
Monitor, detect, analyze, and respond to security events, vulnerabilities, and incidents.
Lead vulnerability assessment, remediation guidance, and verification across application and data platforms.
Develop and maintain incident response, detection, and recovery playbooks.
Security Engineering & Hardening
Develop and enforce application and data security standards, policies, and best practices.
Embed security controls into SDLC, CI/CD pipelines, and deployment automation.
Harden systems and services across Windows and Linux environments.
Implement security solutions across multi-cloud, on‑premises, and colocation environments to ensure confidentiality, integrity, and availability.
Automation & Tooling
Automate defensive security functions using code and security‑as‑code principles.
Integrate security tooling into CI/CD workflows and operational monitoring systems.
Improve detection, alerting, and response efficiency through automation and continuous improvement.
Collaboration & Advisory
Partner with Engineering, Infrastructure, and Business teams to embed secure-by-design practices.
Serve as a trusted advisor and subject matter expert for Application and Cloud Security.
Drive security awareness and promote operational readiness across teams.
Qualifications
-
Basic Qualifications
-
5+ years of experience in security engineering, application security, or defensive security operations.
-
Bachelor's degree in Computer Science, Software Engineering, or related field, or equivalent practical experience.
-
Strong experience with public cloud platforms (AWS, Azure, GCP) and network security.
-
Hands-on experience with Docker, Kubernetes, Infrastructure‑as‑Code, and Security‑as‑Code.
-
Proficiency in one or more programming or scripting languages (e.g., Python, Java, C#, JavaScript, Shell, PowerShell).
-
Experience implementing data protection controls and supporting compliance requirements (e.g., GDPR, CCPA).
Preferred Qualifications
-
Experience designing and operating defensive security controls in cloud-native and distributed systems.
-
Strong understanding of networking and software‑defined networking (SDN).
-
Ability to develop and interpret network, sequence, and data flow diagrams.
-
Familiarity with compliance and security frameworks such as NIST, PCI, HIPAA, HITRUST, or CSA.
-
Experience securing data platforms and warehouses, including technologies like Snowflake.
-
Experience defining and implementing cyber resilience, redundancy, and recovery standards.
More at 3B Staffing