Hello All,
Hope you are doing well,
We have the role of Application Security Engineer with our client. I have shared the detailed job description below. Let me know if you are interested in discussing this role further.
Title: Application Security Engineer
Location: Remote Position
Duration: 12+ Months
Job Responsibilities:
Strong Application Security background:
· Not just Cloud Security or DevSecOps.
· Candidate should understand how to protect applications from design through production.
Hands-on code-level security:
· Should be comfortable looking into application code and identifying security vulnerabilities.
· Strong understanding of Java and .NET application security is important.
· They don''t necessarily need to be a full-time developer, but they should understand the code well enough to perform meaningful security reviews.
Real-world AppSec experience:
· Secure code review
· OWASP Top 10
· API security
· Authentication/authorization
· Vulnerability validation and remediation
· SAST/DAST/SCA
· Dependency and supply-chain security
Know how to protect applications:
· Candidate should be able to explain how they would secure an application, not just operate a security tool.
· They should understand secure design, threat modeling, security controls, CI/CD security and runtime protection.
AWS + DevSecOps as supporting skills:
· AWS security, EKS, IAM, WAF, KMS, Secrets Manager, etc. are important.
· But these should support the Application Security skillset, not replace it.
Thanks and Regards,
Sai Punith,
M9 Consulting, Inc.
E-Verified | Women Owned | Minority Certified Business
Cell: +1
Email: