Application Security Engineer (Perm - Hybrid or Remote)
Company: Alliant
Location: Chicago
Posted on: February 11, 2025
Job Description:
The Application Security Engineer will be responsible for
validating application services that are designed and implemented
with high security standards. Analyze the security (Red - Offense)
of applications in tandem with their underlying services, including
connected dependencies such as middle-tier systems and databases.
Address legacy and emerging security issues, and implement
repeatable secure development practices to reduce the introduction
of program design flaws that may lead to exploitation. Communicate
with technical and leadership teams to ensure a focus on risk
mitigation to allow for business continuity. Assess applications
for weaknesses and find resolutions before they can be abused and
the security of applications for business-to-business initiatives,
third-party relationships, outsourced solutions and vendors.
Recommend programmatic controls, and monitor and manage secure
development practices to address modern day
issues.Responsibilities
- Perform vulnerability and penetration testing (Red - Offense),
document security findings and focus on automation to aid
inefficiencies with both testing and remediation of findings.
- Collaborate with developers to provide repetitive validation
testing prior to production while allowing for a continuous cycle
of development followed by application security assessments.
- Monitor the security community for public-facing security
issues, as well as learn new tactics that can be used in
testing.
- Collaborate in application projects and change management
committees. Understand what is coming and how their projects can be
more secure from the start.
- Follow a security review process to ensure an automated and
repeatable process is managed. This can be through the use of
dynamic and static code analysis resources.
- Use security standards, implementation configurations and
common security frameworks to prepare for and manage bug bounty
programs. Document delivery and implementation advances that meet
defined service-level agreements (SLAs) and business metrics. Align
with architects and development teams for a mission of secure
design.
- Train developers and junior application security engineers on
secure coding practices. Participate and lead security team
meetings that facilitate secure design.
- Engage in information security projects that evaluate existing
security infrastructure and propose changes as defined by security
leadership and architects.
- Focus on application security that observes compliance such as
Health Information Portability and Accountability Act (HIPAA),
Gramm-Leach-Bliley Act (GLBA), Payment Card Industry (PCI),
Sarbanes-Oxley Act (SOX), etc. - and privacy laws.
- Handle service and escalation tickets within SLA
expectations.
- Develop security test plans from the architectural design.
Identify deficiencies and make enhancements to ensure production is
not impacted.
- Drive security efficiencies, enabling security team members to
work on more advanced tasks.
- Conduct performance testing to stress the limitations of
security solutions while ensuring business innovation and
day-to-day processes are not negatively impacted.Education:
- Bachelors Degree - Computer Science or related - Minimum
- Graduate Degree - Computer Science or related - PreferredYears
of Experience:
- 3 Years - Cybersecurity, application programming, compliance,
risk management, network security engineering, threat modeling
applications or related - MinimumIn Lieu of Education:
- 6 years - Cybersecurity, application programming, compliance,
risk management, network security engineering, threat modeling
applications or relatedLicense/Certifications/Training:
- Preferred: Security certifications GWAPT, CISSP, OSCP, or other
similarCompensation & Benefits:Typical hiring range: $113,000 -
$159,550 Annually. Actual compensation will be determined using
factors such as experience, skills & knowledge.Additional
Compensation: Annual performance bonusBenefits: Alliant provides a
benefits package including health care, vision, dental, and 401k
with employer match.Additional Benefits:
- Work from home up to 3 days a week
- Paid parental leave
- Employee discount programs
- Time off including paid personal and sick days
- 11 paid holidays
- Education reimbursement*Note that eligibility and cost of
benefits can vary depending on the number of regularly scheduled
hours, and job status such as regular full-time, regular part-time,
or temporary employment.
#J-18808-Ljbffr
Keywords: Alliant, Chicago , Application Security Engineer (Perm - Hybrid or Remote), Engineering , Chicago, Illinois
Didn't find what you're looking for? Search again!
Loading more jobs...