RSA Security logo
RSA Security

Identity-first solutions for security-first leaders.

Principal Application Security Engineer

Application EngineerApplication EngineerFull TimeRemoteLeadTeam 1,001-5,000H1B SponsorCompany SiteLinkedIn

Location

India

Posted

61 days ago

Salary

0

Seniority

Lead

Job Description

Principal Application Security Engineer

RSA Security

• Drive the development and implementation of advanced security practices, policies, and frameworks to ensure the integrity and confidentiality of our applications. • Provide principal leadership to the application security program, helping set the strategic direction, goals, and objectives to enhance the overall security posture of our applications. • Develop and implement advanced application security practices, including secure coding standards, threat modeling methodologies, and secure software development lifecycle (SDLC) processes. • Conduct in-depth application security assessments, including code reviews, architecture reviews, and penetration testing, to identify and remediate complex security vulnerabilities and risks. • Collaborate closely with development teams, architects, and stakeholders to provide expert guidance on secure coding practices, security design principles, and the selection and implementation of security controls. • Define and maintain application security policies, standards, and guidelines, ensuring alignment with regulatory requirements and industry best practices. • Drive the integration of security into the CI/CD pipeline and automated security testing tools and processes to enable secure and efficient application development and deployment. • Evaluate and recommend emerging technologies, frameworks, and security tools to enhance application security capabilities, scalability, and efficiency. • Lead incident response efforts for application security incidents, working with cross-functional teams to investigate, contain, and remediate security breaches or vulnerabilities. • Stay current with the latest application security threats, vulnerabilities, and attack vectors, and provide strategic recommendations and guidance to mitigate emerging risks. • Serve as a subject matter expert and thought leader on application security, representing the organization in external forums, conferences, and industry working groups.

Job Requirements

  • Bachelor’s degree in computer science, Information Security, or a related field - or equivalent work experience.
  • 10+ years of progressive experience in application security, with a focus on securing complex web and mobile applications.
  • Extensive expertise in application security principles, secure coding practices, secure architecture design, and vulnerability assessment techniques.
  • Strong knowledge of web and mobile application frameworks, languages, and technologies (e.g., Java, .NET, JavaScript, Python, Android, iOS).
  • Proven experience conducting advanced application security assessments, including code reviews, architecture reviews, and penetration testing.
  • Deep understanding of web application security vulnerabilities (OWASP Top Ten), advanced attack techniques, and mitigation strategies.
  • Demonstrated ability to develop and implement secure software development lifecycle (SDLC) processes and integrate security into DevOps and CI/CD practices.
  • Expertise in cloud security concepts and practices, with hands-on experience in cloud-native environments (e.g., AWS, Azure, GCP).
  • Strong scripting or programming skills for automation and tooling (e.g., Python, Bash, PowerShell).

Benefits

  • Equal employment opportunity
  • Work environment free of discrimination and harassment
  • Opportunities for innovation and sharing ideas

Related Categories

Related Job Pages

More Application Engineer Jobs

Meijer logo

Application Security Engineer

Meijer

As a family company, we serve people and communities. When you work at Meijer, you’re provided with career and community opportunities centered around leadership, personal growth and development. Consider joining our family – take care of your career and your community!

Full TimeRemoteTeam 10,001

As a family company, we serve people and communities. When you work at Meijer, you’re provided with career and community opportunities centered around leadership, personal growth and development. Consider joining our family – take care of your career and your community! Grab the Good Stuff: - Weekly pay - Team member discount - 401(k) with company contributions - Paid parental leave - Paid education assistance - Development programs for advancement and career growth - Medical/dental/vision - And more! Please review the job profile below and apply today! The IT Application Security Engineer is adept at secure application design, threat modeling, and secure coding practices. The position assists software development teams in designing, creating, and implementing secure solutions by ensuring security checks are followed at each step of the software development life cycle (SDLC). This role will define and communicate application security standards to relevant stakeholders. Additionally, this role will identify security knowledge gaps and provide curated security training content to address these gaps. What You'll be Doing: - Develop and provide presentations on application security topics to both technical and non-technical audiences, including leadership. - Facilitate third-party penetration tests, triage findings, and create remediation plans with development teams. - Provide tailored remediation guidance to software developers to address security findings. - Provide architectural and security guidance for third-party platforms and services as they integrate into Meijer environments and/or code. - Review the security of third-party/open-source software used by Meijer. - Provide risk-based analysis of security posture to drive business decisions. - Foster relationships with key business partners to create a culture of security and achieve prioritization of security initiatives. - This job profile is not meant to be all inclusive of the responsibilities of this position.  May perform other duties as assigned or required. What You Bring with You (Qualifications): - Bachelor’s degree or above in Computer Science, Information Security, or related field. - At least 2-3 years of professional experience, including a minimum of one year writing code, with relevant experience in a security-related field preferred. - Familiar with object-oriented programming and have written code in at least one programming language (e.g. C#, Java, C++). - Familiarity with secure coding best practices such as the OWASP Top 10. - Agile/Scrum, SAFe, or Lean certification preferred. - Knowledge of common application architectures and the relative risks associated with them (e.g. single page apps, client-server, native mobile, microservices). - Foundational knowledge of security practices in one or more applied contexts, e.g. networking, cloud infrastructure, containerization, operations, audit, or governance. - Knowledge of relevant technology, tools, databases, and development techniques. - Strong focus on team dynamics and interpersonal relationships. - Strong sense of task ownership with consistent follow-through. - Ability to anticipate risks and devise solutions with limited information or context. - Excellent project management, organization, and team collaboration skills. - Curiosity to learn. - Capable of defining and measuring key performance indicators. - Able to work cross-functionally with IT and business partners across all areas of Meijer and vendor partners. - Adaptive, flexible, and responsive to challenges. - Awareness of how security controls influence both internal stakeholders and Meijer customers. - SANS/GIAC, CompTIA, ISC2 (CISSP) or other applicable industry certifications are a plus. We are committed to offering competitive pay that reflects market standards and ensures consistency within our organization. The pay range for this position is listed below. $100,000.00 - $156,000.00 This pay range represents the minimum and maximum base pay for the position, which is determined by factors such as market data, the qualifications required, the level of responsibilities associated with the role and other roles at this same level. Your specific pay rate within this range will be based on your experience, qualifications, and skills compared to the internal team you’ll be joining. We offer a comprehensive benefits package that includes medical, dental, vision, life insurance, a 401(k) plan with employer match, disability leave, and paid time off (PTO). In addition to these core benefits, we are committed to supporting your overall well-being and career growth. Our offerings include a variety of programs designed to support your personal and professional development, such as paid parental leave, paid education assistance (including free education), a childcare subsidy and more. We are dedicated to creating a work environment that promotes work-life balance, long-term health and financial security, and continuous professional development The interview process is intended to learn more about your personal skills and experience. To this end, we ask that candidates do not use AI tools during the hiring process. Please note: - Cameras must be turned on during all virtual interviews. - AI tools may not be used during any part of the interview process.

United States
$100K - $156K / year
Job Closed
Duck Creek Technologies logo

Application Support Administrator

Duck Creek Technologies

The intelligent solutions provider defining the future of property and casualty (P&C) and general insurance

Full TimeRemoteTeam 1,001-5,000Since 2000H1B Sponsor

Helping careers take flight. Reshaping an industry. Enable your career to be Made on Duck Creek.   WHO WE ARE:  Duck Creek Technologies is the intelligent solutions provider defining the future of the property and casualty (P&C) and general insurance industry. We are the platform upon which modern insurance systems are built, enabling the industry to capitalize on the power of the cloud to run agile, intelligent, and evergreen operations. Our modern SaaS solutions help insurers set a new standard and revolutionize how consumers interact with insurance companies.   Authenticity, purpose, and transparency are core to Duck Creek, and we believe insurance should be there for individuals and businesses when, where, and how they need it most. Our market-leading solutions are available on a standalone basis or as a full suite, and all are available via Duck Creek OnDemand. With more than 1,000 successful implementations to date, Duck Creek removes the IT burden for insurers so they can focus on the business of insurance.  We have a flock of more than 1,800 employees across the globe and are proud to be a Flexible-First employer. We empower our employees with the choice to work from an office, from home, or on a hybrid schedule. Our flexible-first environment fosters productivity, inclusion, collaboration, and ensures a consistent employee experience regardless of location. If working in a fast-paced, rapidly evolving company that is transforming one of the world’s oldest and largest industries sounds exciting, let us know. We are excited you are considering Duck Creek as a future employer and hope you decide to join “The Flock”!  To learn more about us, visit www.duckcreek.com and follow us on our social channels for the latest information – LinkedIn and Twitter. Title: Application Support Administrator WHAT YOU’LL DO: The Application Support Administrator is responsible for providing a successful and efficient support journey to all Duck Creek customers. The Analyst acts as the primary point of contact, facilitates the intake, qualification, resolution, and routing of all external and internal support cases - Responds to cases submitted by customers via the customer portal. Performs case qualification, ensures that all necessary information is present, and the appropriate severity is determined. - Provides First Point of Resolution when applicable relying on Knowledge Base articles containing Known Issues and Related Case records. - Based on the available information routes the case to the appropriate group for resolution. - Assumes accountability to the requestor of the case for its entire life cycle. Responds to questions, escalations, and update requests as necessary. - Ensures that incident response SLOs are met and customer communication is consistent, clear and comprehensive. - Recommends and implements performance improvements to meet SLA's and increase overall efficiency. - Perform all other duties and activities as required. - Act in accordance with and as a good steward of Duck Creek Technologies mission, vision, and core values: - Mission: To empower insurers to reimagine the future of insurance - Vision: To transform insurance technology, helping insurers be smarter, faster, and more efficient, and ultimately provide the best protection for people and businesses - Values: We Prioritize Respect, We Listen, We Care, We Add Value, and We Lead Competencies: - Core Employee: - Communication: Effective communication, both verbal and written; includes ability to express ideas clearly, listen actively, and collaborate with colleagues and clients. - Collaboration: Work effectively in teams, build positive relationships, and contribute to achieving common goals​; includes the ability to recognize and incorporate a broad range of diverse perspectives ​ - Problem Solving: Can analyze complex situations, identify problems, ask important questions, and generate creative solutions; involves critical thinking, adaptability, and the ability to make informed decisions​. - Accountability: Willingness to accept responsibility for your actions and work​; ability to set and achieve meaningful outcomes for oneself - Adaptability: ​Can adapt to change, embrace new technologies, and learn quickly; embracing a growth mindset, being flexible and open to different approaches is highly valued​ - Integrity: Conducts themselves with integrity and professionalism, understands and models our core values, and is obsessed with doing the right thing; incorporates this mindset in how they behave, in the products or services they provide, and how they treat others​ - Cultural Agility: Ability to effectively and comfortably adapt to different cultural contexts. It involves the capacity to understand, communicate, and interact with people from diverse cultural backgrounds in a respectful and inclusive manner. WHAT YOU’VE DONE: - Bachelor’s degree, or foreign equivalent, in Software/Computer Engineering, Computer Science, Communications, Business Administration or related degree - Work Experience: Minimum 1 year - Customer Management Experience: Minimum 1 year Knowledge, Skills, Abilities & Behaviors: - Awareness of: - ServiceNow or other ITSM systems - Reporting and analyzing data - Knowledge of: - The Duck Creek solution - Reporting tools for issue tracking systems - Strong communication & collaboration skills - Complex problem-solving skills - Effective negotiation skills - Escalation mitigation skills - Time & Priority management skills - Ability to facilitate client meetings with effective outcomes - Ability to create trusted relationships - Ability to provide critical timeline reporting for leadership - Understanding the Duck Creek release process - Understanding of the Duck Creek product licensing site and execution per contracts WHAT ADDITIONAL INFORMATION YOU MAY WANT TO KNOW: - Travel: [X] 0-10% [] 11-25% [] 26-50% [] 51-75% [] 76-100% - Special Hours: - Work Authorization: Must be legally authorized to work in the country of the job location - Physical Requirements: [X] Sedentary Work [] Light Work - Sedentary work: Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally and all other sedentary criteria are met. - Light Work: Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly to move objects. If the use of arm and/or leg controls requires exertion of forces greater than that for sedentary work and the worker sits most of the time, the job is rated for light work WHAT WE STAND FOR:  Our global company celebrates & leverages the differences each employee brings to the table. Our success is a direct result of an inclusive culture where opportunities to learn from one another occur regardless of title, seniority, or background. This collaborative and team-oriented approach is at the core of how we operate and continuously improve our products, services, and systems.  As such, Duck Creek is committed to providing equal opportunity to all employees and applicants – to recruit, hire, train, and reward employees for their individual abilities, achievements, and experience without regard to race, colour, gender, religion, sexual orientation, age, national origin, disability, marital, military, or any other protected status.  - We strive to be an example to the world of inclusion, diversity, and equity in all things – where employees are free to be their authentic selves in the workplace and in the communities in which we live. We believe in leading by example and are proud of the diversity of our team and our shared commitment to our Core Values: We Prioritize Respect; We Listen; We Care; We Add Value; and We Lead. - To learn more about our inclusive company culture, values, DE&I initiatives, and people, please visit: https://www.duckcreek.com/life-at-duck-creek/. - Please let us know if you encounter accessibility barriers with our web content by sending an email to accessibility@duckcreek.com. Privacy Notice: By submitting your application, you acknowledge that Duck Creek Technologies may collect and process your personal data for recruitment purposes in accordance with our Privacy Notice and applicable data protection laws. Duck Creek Technologies does not accept, nor will we pay a fee for any hires resulting from unsolicited head-hunter or agency resumes.  #LI-JJ1 # LI-Remote

India
Job Closed
Mayo Clinic logo

IT Application Analyst

Mayo Clinic

Headquartered in Rochester, Minnesota, Mayo Clinic is a nonprofit medical institution ranked first in more specialties than all other hospitals in America. The company employs arou

The Clinical Decision Support Team within the EHR Technology Domain is seeking an IT Application Analyst to support Epic Clinical Decision Support (CDS) functionality, including emerging capabilities in Epic Cognitive Computing. Clinical Decision Support tools are used across the Mayo enterprise and rely heavily on integration with a wide range of Epic applications, including Orders, Clinical Documentation, ASAP, Ambulatory, Healthy Planet, Anesthesia, and Genomics (including pharmacogenomics and genomic indicators). These integrations require complex system design and build, as well as strong partnerships with Informatics, clinical stakeholders, and practice liaisons. This role supports both foundational and advanced CDS capabilities. Core responsibilities include the design, build, and maintenance of Our Practice Advisories (OPAs, formerly BestPractice Advisories [BPAs]), as well as other CDS interventions such as Care Paths and Health Maintenance. These tools play a critical role in delivering timely, actionable guidance within clinical workflows. In addition, this position will contribute to the advancement of Epic Cognitive Computing, supporting the design, implementation, and optimization of intelligent decision support solutions. This includes leveraging advanced CDS capabilities to enhance clinical decision-making, improve patient outcomes, and enable more data-driven and precision medicine approaches to care delivery across the enterprise. The position requires a high level of analytical and problem-solving skills, strong organizational capabilities, sound judgment and decision-making, and excellent verbal and written communication skills. The successful candidate will demonstrate the ability to work collaboratively across multidisciplinary teams and manage complex, integrated system workflows. This vacancy is not eligible for sponsorship/we will not sponsor or transfer visas for this position. Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program. Why Mayo Clinic Mayo Clinic is top-ranked in more specialties than any other care provider according to U.S. News & World Report. As we work together to put the needs of the patient first, we are also dedicated to our employees, investing in competitive compensation and comprehensive benefit plans – to take care of you and your family, now and in the future. And with continuing education and advancement opportunities at every turn, you can build a long, successful career with Mayo Clinic. Benefits Highlights - Medical: Multiple plan options. - Dental: Delta Dental or reimbursement account for flexible coverage. - Vision: Affordable plan with national network. - Pre-Tax Savings: HSA and FSAs for eligible expenses. - Retirement: Competitive retirement package to secure your future. Just as our reputation has spread beyond our Minnesota roots, so have our locations. Today, our employees are located at our three major campuses in Phoenix/Scottsdale, Arizona, Jacksonville, Florida, Rochester, Minnesota, and at Mayo Clinic Health System campuses throughout Midwestern communities, and at our international locations. Each Mayo Clinic location is a special place where our employees thrive in both their work and personal lives. Learn more about what each unique Mayo Clinic campus has to offer, and where your best fit is. Equal Opportunity All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, protected veteran status or disability status. Learn more about the "EOE is the Law". Mayo Clinic participates in E-Verify and may provide the Social Security Administration and, if necessary, the Department of Homeland Security with information from each new employee's Form I-9 to confirm work authorization.

United States
$88.4K - $123K / year
Job Closed
Switzerland Global Enterprise logo

Senior Engineer – Customer Application Engineering

Switzerland Global Enterprise

We support Swiss SMEs in their international business and help innovative foreign companies to establish in Switzerland.

Full TimeRemoteTeam 51-200Since 1927H1B No Sponsor

• Customer facing staff responsible for winning business • Impacts approaches, projects and programs in the functional area or affected business organization and ways of working • Impacts quality, efficiency and effectiveness of own team • Guided by commercial practices and policies that may be shaped by the role • Has significant control/influence over commercial priorities • There is moderate autonomy within the role to enter into/execute Commercial arrangements • High levels of Commercial judgement are required to achieve outcomes required • Technical lead for BESS proposals • Review customer specification and standards (grid compliance, cybersecurity, etc) versus GE Vernova standard platform and clearly document clarifications and/or exceptions to customer specification • Align with product development team on feasibility of exceptions, including associated cost and cycle time to ensure alignment with execution priorities and backlog • Develop GE Vernova technical proposal to best suit the customer's use case and requirements for proposals, reference architecture, risk assessment matrix, features and accessories list, cost of materials, grid model development and customer project engineering work estimates • Facilitate development of dynamic models for grid system simulation studies by providing technical inputs on control system design and capabilities • Lead the creation and maintenance of the technical commercial documentation related to the product in coordination with the different stakeholders • Support Sales with delivering technical presentations to customers • Complete customer technical fill-in datasheet and answer customer questions • Report status and problems to tendering team members in a timely fashion • Present technical proposal to GE Vernova leadership team detailing system performance capability and risks • After winning project, support a clean hand over of technical solution to the project execution team • Participate in the development of multi-generation product plans by summarizing and prioritizing emerging customer / market requirements and gathering competitive intelligence • Provide mentorship and knowledge transfer to fellow team members • Lead and define process improvement activities

United States
$113.2K - $188.8K / year
Job Closed