Sr. IT Application Security Engineer
$120,000–$150,000 year
On-siteSan Jose, California, United States or Kirkland, Washington, United States
Job Summary
Architect and manage application security controls, role-based access controls, and RBAC for Microsoft Dynamics 365, Azure, and IFS ERP platforms. Conduct regular security assessments, code reviews, vulnerability scans, and penetration tests across these systems. Lead application security reviews, threat modeling, and risk analysis for new product features, while advising development teams on secure architecture and coding practices. Build automation for access provisioning and compliance monitoring, and train engineering teams on secure coding and emerging threats. Respond to security incidents, drive remediation, and maintain documentation aligned with NIST, OWASP, and ISO 27001 frameworks. Collaborate with IT, DevOps, and audit teams to support compliance initiatives and integrate security deeply into the product lifecycle.
Required Qualifications
- In-depth experience with Microsoft Dynamics 365, Azure Active Directory, and IFS ERP security models
- Advanced knowledge of RBAC, access provisioning, least-privilege, and segregation of duties in enterprise/cloud environments
- Hands-on expertise in secure application development, vulnerability management, code reviews, and threat modeling
- Proficiency with security testing tools (SAST, DAST), CI/CD pipeline integration, and automation scripting (e.g., PowerShell, Python)
- Strong grasp of security standards and frameworks (e.g., OWASP Top 10, NIST, ISO 27001)
- Familiarity with cloud security best practices, secure REST API development, and modern authentication mechanisms
- Excellent communication, documentation, and stakeholder engagement abilities
- Ability to translate security concepts for technical and non-technical audiences
- Strong problem-solving, analytical, and incident investigation skills
- Collaborative approach with a drive for continuous improvement and knowledge sharing
- 3+ years of experience in application security roles (preferably in enterprise Microsoft or ERP environments)
- Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent professional experience)
- Certifications such as CISSP, CSSLP, or relevant Azure security credentials
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.