
emaratech
About the job
- Lead Application Security Engineer
- The Lead Application Security Engineer will be responsible for overseeing the security aspects of software applications. This position requires to be involved in both leadership responsibilities and hands-on technical work.
- Responsibilities:
- One of the primary responsibilities of an application security engineer is to work closely with developers and operations teams. They play a pivotal role in the software development lifecycle (SDLC), ensuring that security is integrated at every stage
- Application security engineers provide guidance to developers on secure coding practices. They also participate in code reviews to identify potential security vulnerabilities and advise on remediation strategies
- Furthermore, they collaborate with operations teams to ensure that security measures are effectively implemented in production environments
- Secure Development Lifecycle Integration:
- Integrate security practices into the Software Development Life Cycle (SDLC)
- Work with development teams to ensure secure coding practices are followed
- Manage integration with AppSec vulnerabilities assessment techniques, including Static Code Analysis and Dynamic Code Analysis
- Assist the company in the evolution of its application security functions and services
- Take leadership of the organization’s bug intake and remediation process
- Discover security vulnerabilities through AppSec pipeline and devise mitigation strategies, as well as report and help resolve technical debt
- Act as a subject matter expert for application security mainly across Java, Angular, React and other languages and frameworks
Requirements
- Education: A bachelor’s degree in computer science, cybersecurity, or a related field
- Experience: 5-7 years of experience in application security or a related field, with a proven track record of handling complex security issues
- Technical Skills: Proficiency in security testing tools, understanding of secure coding practices, and knowledge of various security frameworks and compliance standards
- Soft Skills: Strong leadership and communication skills are crucial, as the role involves collaboration with various stakeholders and educating others on security matters
- Certification (Preferred)
- Offensive Security Certified Professional (OSCP)
- GIAC Web Application Penetration Tester (GWAPT)
Posted on Nov 4, 2023.