Application Security Engineer
airSlate
This job is no longer accepting applications
See open jobs at airSlate.See open jobs similar to "Application Security Engineer" General Catalyst.
Remote
What you'll be working on:
- Conduct comprehensive security testing of web, mobile, and network-based applications. This includes performing security assessments, identifying risks, and advocating for necessary fixes in collaboration with product and engineering teams.
- Collaborate with product and compliance teams to ensure adherence to security standards and frameworks (e.g., PCI DSS, SOC 2, CASA) and assist in audit and external assessment preparations.
- Provide guidance on secure development practices at all stages of the SDLC, including architecture reviews, threat modeling, and risk assessments, to support secure-by-design solutions.
- Manage and maintain security automation tools such as SAST, DAST, SCA, and others, ensuring effective vulnerability detection, reporting, and integration into CI/CD workflows.
- Support incident response efforts, including investigation, triage, containment, and post-mortem analysis across various scenarios (application-level, infrastructure, user-related, etc.).
- Configure and monitor CDN, Web Application Firewalls (WAF), and bot management solutions to enhance application security.
- Apply a strong generalist security foundation to various tasks, including:
- Cloud security best practices (AWS/GCP)
- Endpoint protection (e.g., antivirus, EDR solutions)
- User security awareness initiatives
- Development and enforcement of information security policies
- Threat modeling and risk assessment methodologies (e.g., STRIDE)
What we expect from you:
- Education: Bachelor's degree in a technical field (e.g., Computer Science, Information Security, Engineering) from a technical university.
- Experience: At least 2 years of professional experience in information security, application security, or a related domain.
- Hands-on experience in performing security assessments and understanding system architecture.
- Strong communication skills to effectively collaborate and drive remediation efforts.
- Experience with security automation tools and integrating them into CI/CD workflows.
- Knowledge of compliance standards and frameworks.
- Proficiency in incident response and post-mortem analysis.
- Ability to provide security guidance throughout the SDLC.
- С1 level English proficiency (both written and spoken) is required.
This job is no longer accepting applications
See open jobs at airSlate.See open jobs similar to "Application Security Engineer" General Catalyst.