Application Security Engineer
Indexed description
Security Clearance: No clearance needed
Job Type: Full-Time
Target Salary Range*: $90,000-110,000
- This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary
You will join our team in partnership with New York State of Health (NYSoH) to provide comprehensive health coverage to more than 7.2 million New Yorkers through its Health Benefit Exchange (HBE)
Key Responsibilities
- You’ll join our talented Development Team. Our project is built on a multi-tier architecture including Service Oriented architecture, multi-tier web applications using Java and various other COTS products.
- Work closely with development teams to diagnose, document, and remediate application security vulnerabilities and identify appropriate security checkpoints in SDLC.
- Perform risk-based, technical assessments/penetration tests of applications, using dynamic and static scanning tools, and audits ensuring compliance with industry standards
- Consult with Development leadership on application development training.
- Research new attack vectors and stay current with cybersecurity news and trends.
Required Experience
- 8+ years Information Technology.
- Hands-on experience designing and executing a repeatable process to aggressively prioritize issue dispositions and remediations of security findings — while providing clear, concise status updates and risk reporting to leadership and stakeholders.
- Hands-on experience integrating AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities and insecure coding patterns before deployment.
- Hands-on experience assessing new code commits, pull requests, and architecture changes for vulnerabilities, misconfigurations, and compliance risks.
- 3+years with Application Security Engineering conducting assessments, penetration testing, implementing tools for dynamic /automated code review, dynamic and static application scanning (Fortify, SonarQube); consulting on security designs of applications, potential vulnerabilities, and remediation, and creating training materials on key security concepts.
- Java/Web development with strong secure coding background in RHEL and JBoss.
- 5+ years in software development role as a Developer, or Architect
- Strong oral and written communication skills, with a demonstrated ability to communicate complex topics to colleagues, and management.
- Critical thinking and creative problem solving
- Identify and resolve problems in a timely manner; gather and analyze information skillfully; develop alternative solutions.
- Strong analytical skills.
- Demonstrated collaboration and teaching abilities.
- CISSP, CEH, CISA, OSCP, OSCE, or OSWE Certifications
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search