Snr Assoc, Application Security Engineer, Information Security Services, Group Technology
On-siteEast, Sichuan, People’s Republic of China
Job Summary
Provide advisory on application security tools and processes, including SAST, DAST, IAST, and secure coding guidelines. Drive the integration of security activities into the Software Development Life Cycle (SDLC), promoting secure design principles and testing methodologies. Participate in vulnerability analysis and root cause investigations for identified security findings. Develop automation scripts using Python or Go to streamline processes like vulnerability scanning orchestration and metric reporting. Explore Generative AI tools to enhance security testing, code analysis, and threat modeling. Contribute to continuous improvement of secure SDLC frameworks and train developers on secure coding best practices. Stay updated with industry developments to recommend innovative solutions.
Required Qualifications
- Bachelor's or master's degree in computer science, Information Technology, or a related field
- Minimum 5 years of experience in a cybersecurity engineering, information security, or software development role
- Strong focus on secure software development practices
- Experience in the financial services industry
- Deep technical understanding of common application security vulnerabilities (e.g., OWASP Top 10), attack vectors, and mitigation strategies
- Strong experience with secure coding principles and security best practices for various programming languages and frameworks
- Proficiency in utilizing and interpreting results from application security testing tools (SAST, DAST, IAST) and manual penetration testing techniques
- Experience applying DevSecOps principles including CI/CD, configuration, and infrastructure (Unix/Linux) as code, and auto-remediation
- Practical development experience with Python and one or more languages such as Java and/or JavaScript/TypeScript
- Familiarity with Generative AI concepts and their potential applications in cybersecurity, especially in areas like code analysis, vulnerability detection, and threat intelligence
- Comprehensive understanding of secure software development lifecycle methodologies and frameworks
Desired Qualifications
- Candidates with experience in financial institutions and familiarity with regulatory landscapes are strongly preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.