First Advantage is an equal opportunity employer. We are committed to providing a workplace and recruitment process that is free from unlawful discrimination, harassment, and retaliation. Employment decisions at First Advantage are based solely on qualifications, merit, and business needs. We do not discriminate in any aspect of employment on the basis of race, color, national origin, ancestry, citizenship, religion, creed, sex, gender identity, gender expression, sexual orientation, marital or family status, pregnancy, age, physical or mental disability, medical condition, genetic information, veteran or military status, or any other characteristic protected by applicable law.
Senior Application Security Engineer
Location
Germany
Posted
6 days ago
Salary
0
Seniority
Senior
Job Description
Senior Application Security Engineer
First Advantage Global operating Centre
Role Description The Senior AppSec Engineer is an individual contributor role reporting to the Senior Manager of Application Security. The person in this position will drive security assessments for many different First Advantage product applications to consistently enhance security posture and reduce risk across the enterprise. - Design and implement secure application code bases and processes to support the software development life cycle (SDLC) across the global enterprise. - Serve as a liaison between third-party penetration testing vendors and internal application teams, collaborating to schedule, scope, test, and remediate. - Review security findings from multiple tooling sources as well as customer inquiries, assessing validity and risk levels. - Perform threat modeling and application design reviews, working closely with stakeholders. - Configure SAST and DAST tooling, analyze findings, and address ticketing and remediation with multiple other teams. - Contribute to the development and automation of security testing tools and processes. - Assist with incident response (IR) activities that may relate to application security. - Partner with teams such as SecOps, Threat Intel/Hunt, Vulnerability Management, DevOps, AppDev, Networking, and Product to ensure a strong security posture across the organization. Qualifications - 3-5 years of experience with a combination of application security engineering, penetration testing, web application/API development (.NET/C#, Java, JavaScript), system administration, networking, and information security. Requirements - Relevant industry certifications from organizations such as OffSec, SANS, or isc2. - Familiarity with web application/API testing, static code analysis, threat modeling, and vulnerability scanners. - Practical knowledge with source code review to address common security issues. Benefits - Employee Impact Groups - FA Cares volunteer opportunities - Mentorship Advantage Program - SOAR, award-winning manager development program
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead secure Google Cloud architecture design and reviews across IAM, networking, workload protection, data protection, logging, monitoring, and compliance • Advise enterprise customers on Google Cloud security strategy aligned to business risk, regulatory requirements, and operating priorities • Lead Google Cloud security posture assessments to identify high-impact risks, misconfigurations, control gaps, and operational weaknesses • Advise customers on Google SecOps, Chronicle, SIEM strategy, cloud telemetry strategy, detection engineering, and SOC workflow design • Advise customers on Wiz use cases such as CNAPP, CSPM, vulnerability prioritization, attack path analysis, entitlement risk, and remediation workflows • Develop executive-ready findings, prioritized remediation roadmaps, and maturity-based security improvement plans • Lead Security Command Center and Security Command Center Enterprise implementation, configuration, tuning, and operationalization • Integrate Security Command Center findings into vulnerability management, compliance, security operations, and executive risk reporting workflows • Support SIEM modernization and migration planning, including log source rationalization, detection migration, alert tuning, and operational transition • Help customers move from fragmented monitoring approaches into scalable, cloud-native security operations models • Own complex technical workstreams from discovery through delivery, including technical direction, scope, risks, and stakeholder coordination • Translate technical security findings into clear business risks, investment priorities, and actionable recommendations for senior leaders • Guide customer teams through secure Google Cloud design, configuration, deployment, and operational maturity decisions • Advise on Vertex AI and AI workload security, including identity, access control, data protection, governance, logging, and monitoring • Create architecture diagrams, assessment deliverables, roadmaps, implementation documentation, and operational runbooks • Develop repeatable methodologies, assessment frameworks, implementation patterns, reference architectures, and reusable technical assets • Mentor consultants and help raise the overall capability of the Google Cloud Security practice • Provide technical leadership during client reviews, executive briefings, architecture discussions, and operational meetings • Contribute to process improvement and automation initiatives that improve consistency, scalability, and delivery quality
• Lead secure Google Cloud architecture design and reviews across IAM, networking, workload protection, data protection, logging, monitoring, and compliance • Advise enterprise customers on Google Cloud security strategy aligned to business risk, regulatory requirements, and operating priorities • Lead Google Cloud security posture assessments to identify high-impact risks, misconfigurations, control gaps, and operational weaknesses • Develop executive-ready findings, prioritized remediation roadmaps, and maturity-based security improvement plans • Lead Security Command Center and Security Command Center Enterprise implementation, configuration, tuning, and operationalization • Integrate Security Command Center findings into vulnerability management, compliance, security operations, and executive risk reporting workflows • Advise customers on Google SecOps, Chronicle, SIEM strategy, cloud telemetry strategy, detection engineering, and SOC workflow design • Support SIEM modernization and migration planning, including log source rationalization, detection migration, alert tuning, and operational transition • Help customers move from fragmented monitoring approaches into scalable, cloud-native security operations models • Own complex technical workstreams from discovery through delivery, including technical direction, scope, risks, and stakeholder coordination • Translate technical security findings into clear business risks, investment priorities, and actionable recommendations for senior leaders • Guide customer teams through secure Google Cloud design, configuration, deployment, and operational maturity decisions • Advise customers on Wiz use cases such as CNAPP, CSPM, vulnerability prioritization, attack path analysis, entitlement risk, and remediation workflows • Advise on Vertex AI and AI workload security, including identity, access control, data protection, governance, logging, and monitoring • Create architecture diagrams, assessment deliverables, roadmaps, implementation documentation, and operational runbooks • Develop repeatable methodologies, assessment frameworks, implementation patterns, reference architectures, and reusable technical assets • Mentor consultants and help raise the overall capability of the Google Cloud Security practice • Provide technical leadership during client reviews, executive briefings, architecture discussions, and operational meetings • Contribute to process improvement and automation initiatives that improve consistency, scalability, and delivery quality
Identity Security Sales Specialist
BeyondTrustProtect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.
• Own and execute a strategic territory plan focused on net-new commercial acquisition. • Drive full-cycle sales motions from prospecting through close within your assigned accounts. • Operate as an overlay specialist across aligned Commercial Account Executives, identifying and advancing Entitle opportunities within their territories. • Build strong internal partnerships with Commercial AEs to create joint account plans and pipeline acceleration strategies. • Generate pipeline through proactive prospecting, executive outreach, partner collaboration, and targeted account strategies. • Lead complex, multi-threaded sales engagements within commercial organizations. • Engage C-level and senior security stakeholders (CISO, CIO, VP Security, Cloud Security leaders) in outcome-driven security conversations. • Deliver consultative discovery centered on privilege risk reduction, identity governance, and cloud security posture. • Coordinate cross-functional resources (Sales Engineering, Channel, Marketing, Professional Services, Customer Success) to accelerate deal progression and ensure successful outcomes. • Develop compelling business cases and ROI-driven proposals aligned to customer security initiatives. • Accurately forecast and manage pipeline using Salesforce, maintaining disciplined deal inspection and territory hygiene. • Consistently meet and exceed quarterly and annual revenue targets across both direct and overlay motions. • Represent the company at industry events, executive briefings, and partner engagements.
• Develop and execute on joint strategy with your direct salesperson which is tied to your partners and Fortinet Goals. • Support your partners in various ways such as though POCs, for internal consumption or managed offerings, develop labs for technical enablement, custom presentations, etc. • Be onsite with your partners to develop relationships across your partners internal business units. • Be the primary technical point of contact for your partners(s) in close collaboration with your sales partner. • Collectively work with Fortinet’s teams (account sales/ technical, marketing, specialization overlays) + your partners teams (sales/ technical/ professional services, managed services, etc) to develop “go to market” offerings to address Fortinet and our partners goals. • Continuously strive to improve knowledge around the Fortinet products and solutions, along with maintaining a deep understanding of the competitive landscape and Fortinet’s ability to provide long lasting protection against the ever-evolving threats. • Have a strong ability to position Fortinet solutions to the partner, whether this be remotely or in person. This requires strong communication skills and the ability to confidently present through whiteboarding, technical white papers, technical plans, or customer discussions. • Manage your time effectively when working on multiple projects simultaneously, ensuring a positive customer experience is maintained. • Maintain accurate activity, contact, and account technical information of all customers and prospects in our CRM (Salesforce).


