As the pioneer in Zero Trust Data Security™, we enable cyber and operational resilience for enterprises and governments.
Application Security Engineer
Location
United States
Posted
110 days ago
Salary
$135.2K - $225.4K / year
Seniority
Senior
Job Description
Application Security Engineer
Rubrik, Inc.
• Integrate security controls and practices into Rubrik’s secure SDLC and collaborate with Engineering to embed security into every phase of the development process. • Perform security assessments of applications, identifying vulnerabilities and weaknesses through both automated and manual testing techniques. • Carry out detailed analysis of identified vulnerabilities to ensure high fidelity findings are provided to Engineering teams. • Assist in identifying and implementing frictionless "shift-left" strategies to seamlessly and proactively prevent vulnerabilities earlier in the SDLC. • Aid in the collection, management and reporting of key Application Security metrics to track progress and identify trends. • Analyze and harden existing applications, automation, and deployment processes • Participate in security design reviews and threat modeling of proposed products and feature releases • Work with development teams, operations, governance, and other stakeholders to document security guidance, processes and standards for Rubrik products and services
Job Requirements
- Bachelor’s degree required; BS or MS in Computer Science, Information Technology, or a related field
- 5+ years’ experience in Application Security, with experience across SDLC activities such as threat modeling, secure code review, vulnerability management, and penetration testing
- Knowledge of regulatory guidelines and standards such as FedRAMP, SOC2, ISO 27001 etc.
- Broad knowledge of web, application, and cloud attack vectors and exploits
- Comprehension in multiple programming languages (Python, Go, Scala, C/C++, Javascript/Typescript)
- Working experience with CI/CD pipeline, containerization (Kubernetes, Docker, etc) and MicroServices
- Working knowledge of at least one major public cloud provider (AWS, GCP, Azure)
- Understanding of application security maturity model frameworks and how to apply them
- Foundational knowledge of deploying and securing SaaS applications and cloud environments
- Team player, ability to establish priorities, deal with conflicts, work independently, proceed with objectives and can-do attitude
- A self-starter with excellent critical thinking and problem solving skills
- Strong written and verbal communication skills.
Benefits
- The role is eligible for bonus potential
- Equity
- Benefits
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
• Provide technical sales support & solutioning • Review project specifications and technical requirements • Act as the technical SME, partnering with Sales • Provide pre-sales technical support to sales and tendering teams • Design solutions for diesel generators and power plant projects • Develop and deliver technical proposals for bids and tenders • Participate in customer presentations and negotiations • Ensure compliance with local regulations, standards, and codes
Senior Enterprise Application Engineer
GE AerospaceGE Aerospace offers a great work environment, professional development, challenging careers, and competitive compensation. GE Aerospace is an Equal Opportunity Employer.
• Lead technical support and drive innovation for engineering tools and database systems while ensuring compliance with required standards and regulations • Collaborate with engineering teams to identify needs, develop solutions, and enhance design productivity • Administer and support ECAD tools and infrastructure (install, configure, debug; client/server issue resolution) • Integrate ECAD with enterprise systems (Windchill and/or Teamcenter PLM, ERP, manufacturing) and manage ECAD libraries/databases • Automate workflows and CI/CD (Ansible, Jenkins, OpenShift/Kubernetes, JFrog); script in Java/Python • Architect and operate AWS environments for servers/workstations; manage licensing and identity (LDAP/SAML) • Ensure cybersecurity compliance and network fundamentals (switching/routing); align to company standards • Support and optimize databases (MSSQL, MySQL, PostgreSQL, Oracle RDS, Cassandra) • Evaluate and implement new tools/technologies; provide documentation and training to engineering teams • Support key applications: Siemens Xpedition, EDM, HyperLynx, OneSim, Valor, Capital; Altium Designer; Relyence
• conduct security assessments using both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies • collaborate with software development teams to integrate security into the development life cycle • conduct security assessments of web, mobile, and other applications • analyze security assessment results to identify vulnerabilities and provide guidance on remediation • design and implement secure software development practices, including threat modeling and secure coding standards • stay current with security threats, trends, and technologies • conduct application security investigations and provide recommendations to mitigate risk • maintain security documentation
• Improve, update, and maintain cost library (Quote Resource Tool) for AE team to utilize; create standardization of this tool to create efficiencies and accuracy in quoting as well as design re-utilization. • Collect, organize, analyze, and report on historical data related to Applications Engineering activities. • Work with Applications Engineering team, managers and executive staff to determine types of reporting and data analysis needed to improve and streamline quoting activities, improve win rates, and other functional improvements. • Track KPI’s for Applications Engineering metrics and compare against targets. • Identify opportunities for standardization and cost reduction within Applications Engineering team; determine recommendations. • Track any available inventory that JR has left over from past projects. • Identify standard components for Application Engineering teams to use in concepting and maintain, as necessary. • Develop and implement methods to streamline cost development from suppliers and internal references; determine appropriate systems and tools to leverage in process improvements.




