Source description
About the role
As a Senior Application Security Engineer at Strategy, you will be a key player in safeguarding Strategy's software applications using modern security and AI tooling. Your responsibilities will include: - Security Architecture: Design and implement application security architecture and processes in alignment with industry best practices and regulatory requirements. - Secure SDLC: Manage a risk-balanced SDLC by integrating threat modeling, secure code reviews, and security testing. - Vulnerability Management: Identify, triage, and remediate security vulnerabilities through static and dynamic application security testing (SAST/DAST) and software composition analysis (SCA) tools. - Security Assessments & Penetration Testing: Perform advanced penetration testing and red teaming across web, mobile, and cloud applications. Collaborate with engineering teams for effective remediation. - Secure Code Review: Analyze source code and provide security recommendations to developers to ensure adherence to secure coding best practices. - Threat Modeling & Risk Analysis: Perform threat modeling and enhance security architecture on complex components. - DevSecOps Enablement: Lead and enhance DevSecOps initiatives by integrating security automation within CI/CD pipelines. - Incident Response & Remediation: Lead security incident response related to applications and work with engineering teams to remediate threats. - Security Awareness & Training: Develop and lead customized security training programs for engineering teams. Qualifications: - Bachelor's degree in Computer Science, Engineering, or related field - Minimum 5 years of software development or software security experience - Hands-on experience with SAST, DAST, IAST, and SCA tools - Deep knowledge of API security and containerized applications - Experience with supply chain security risks and AI/ML security - Familiarity with programming languages and security tools - Understanding of security standards and regulations - Experience with cloud security best practices and AI security implementations - Strong communication and collaboration skills The recruitment process includes online assessments as the first step. Kindly check your email, including the SPAM folder, for further details. As a Senior Application Security Engineer at Strategy, you will be a key player in safeguarding Strategy's software applications using modern security and AI tooling. Your responsibilities will include: - Security Architecture: Design and implement application security architecture and processes in alignment with industry best practices and regulatory requirements. - Secure SDLC: Manage a risk-balanced SDLC by integrating threat modeling, secure code reviews, and security testing. - Vulnerability Management: Identify, triage, and remediate security vulnerabilities through static and dynamic application security testing (SAST/DAST) and software composition analysis (SCA) tools. - Security Assessments & Penetration Testing: Perform advanced penetration testing and red teaming across web, mobile, and cloud applications. Collaborate with engineering teams for effective remediation. - Secure Code Review: Analyze source code and provide security recommendations to developers to ensure adherence to secure coding best practices. - Threat Modeling & Risk Analysis: Perform threat modeling and enhance security architecture on complex components. - DevSecOps Enablement: Lead and enhance DevSecOps initiatives by integrating security automation within CI/CD pipelines. - Incident Response & Remediation: Lead security incident response related to applications and work with engineering teams to remediate threats. - Security Awareness & Training: Develop and lead customized security training programs for engineering teams. Qualifications: - Bachelor's degree in Computer Science, Engineering, or related field - Minimum 5 years of software development or software security experience - Hands-on experience with SAST, DAST, IAST, and SCA tools - Deep knowledge of API security and containerized applications - Experience with supply chain security risks and AI/ML security - Familiarity with programming languages and security tools - Understanding of security standards and regulations - Experience with cloud security best practices and AI security implementations - Strong communication and collaboration skills The recruitment process includes online assessments as the first step. Kindly check your email, including the SPAM folder, for further details.
More at Strategy