Application Security Engineer (Experienced in applications security focusing on red, blue or purple team activities)
On-siteDublin, Leinster, Ireland
Job Summary
Conduct threat modelling and review application architectures to identify potential risks early in the SDLC. Oversee daily management of application security platforms to maintain comprehensive coverage, ensure compliance, and remediate findings. Support the identification and analysis of web application security vulnerabilities across the business to reduce risk. Implement and manage SAST/SCA tooling across application repositories to identify source code risks, while scaling automated DAST solutions to maximize testing coverage. Carry out penetration testing on internally developed applications and coordinate external assessments. Provide security guidance and remediation advice to engineers, validate fixes from development teams and third parties, and foster a secure-by-design approach across the business.
Required Qualifications
- Experienced in applications security focusing on red, blue or purple team activities
- Experienced in software development or experience contributing to Open-Source projects
- Experienced with DAST tools such as Burp Suite, OWASP Zap or similar
- Experience with SAST/SCA tools such as Snyk, Veracode, Checkmarx or similar
- Proficient in one or more of the following languages - Python, JavaScript, .NET or Java
- Well-versed in analysis of open source and third-party library vulnerabilities
- Well-rounded knowledge of the Software Development Life Cycle (SDLC) and agile methodologies
- Hold a strong understanding and experience testing of both REST and GraphQL APIs
- Demonstrated experience with development tools including GitLab/GitHub, Datadog, Jira, Docker, and various IDEs
- Previously worked very closely with development and DevOps teams to resolve security issues
- Have performed security-focused code reviews to identify code level issues
- Experience in creating custom security tooling or scripts
Desired Qualifications
- Experience in the financial sector or another heavily audited industry
- Experience with cloud services, particularly AWS services like WAF, Cognito etc
- Experience working with Infrastructure as Code, Kubernetes and Containers
- Experience with auth mechanisms like Open ID Connect, OAuth and identity providers
- Experience in creating custom CI/CD pipeline jobs to carry out security related reviews or scans
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.