Autodesk logo
Autodesk

How the world gets designed and made. #MakeAnything

Senior Application Security Developer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+Since 1982H1B No SponsorCompany SiteLinkedIn

Location

Canada

Posted

1 day ago

Salary

$101K - $148.5K / year

Seniority

Senior

Bachelor Degree1 yr expEnglishCloudJavaJavaScriptMicroservicesPythonGo

Job Description

Senior Application Security Developer

Autodesk

• Partner with engineering teams to embed security throughout the software development lifecycle, including design reviews, threat modeling, implementation guidance, code review, and release readiness. • Identify, validate, and help remediate common application security vulnerabilities, including injection, broken access control, authentication and authorization flaws, data leakage, insecure deserialization, and server-side request forgery. • Support security reviews of AI-enabled applications and AI-assisted development workflows, including risks related to LLM-integrated systems, coding assistants, prompt injection, sensitive data exposure, and unsafe model or tool interactions. • Develop and maintain secure coding guidance, reusable security patterns, and engineering enablement materials for application, API, cloud, and data protection risks. • Integrate and improve application security testing in CI/CD pipelines, including SAST, DAST, SCA, secrets detection, infrastructure-as-code scanning, and other automated controls. • Provide developer education on secure coding, threat modeling, vulnerability remediation, secure use of third-party components, and safe adoption of emerging technologies. • Track, prioritize, and report application security risks and trends to continuously improve Autodesk's product security posture.

Job Requirements

  • Strong understanding of application security fundamentals, including the OWASP Top 10, secure software design, common vulnerability classes, and practical mitigation techniques.
  • Hands-on experience securing modern web applications, APIs, microservices, and cloud-native systems.
  • Experience performing secure design reviews, threat modeling, code reviews, vulnerability assessments, or penetration testing.
  • Practical knowledge of authentication, authorization, session management, data protection, input validation, output encoding, and secure API design.
  • Experience identifying and mitigating vulnerabilities such as injection, broken access control, insecure deserialization, server-side request forgery, cross-site scripting, data leakage, and insecure configuration.
  • Experience integrating security testing and controls into CI/CD pipelines and DevSecOps workflows.
  • Familiarity with common application security tooling, such as SAST, DAST, SCA, secrets scanning, container scanning, or API security testing tools.
  • Proficiency in scripting or programming, such as Python, JavaScript, Go, Java, or similar languages, for automation, testing, or prototyping.
  • Ability to communicate complex security risks clearly and translate them into practical, actionable guidance for engineering teams.
  • Familiarity with emerging AI/LLM security risks, such as prompt injection, data exposure, unsafe tool invocation, and secure use of AI coding assistants.

Benefits

  • Annual cash bonuses
  • Comprehensive benefits package

Related Categories

Related Job Pages

More Security Engineer Jobs

Ericsson logo

BO L2 Engineer - Security

Ericsson

We create limitless connectivity to improve lives, redefine business and pioneer a sustainable future. #ImaginePossible

Full TimeRemoteTeam 10,001+Since 1876H1B Sponsor

Join our Team About this opportunity: We are thrilled to announce an exciting opportunity for a skilled Back Office L2 Engineer - Security to become part of our dedicated Telecom Security team. In this pivotal role, you will be responsible for the operation and management of our IP-backbone security devices, playing a crucial part in safeguarding our network infrastructure. As a key member of our team, you will collaborate with experts in the field to ensure the integrity and reliability of our security systems. This position offers a unique chance to grow professionally within a dynamic environment that prioritizes innovation and excellence. Ideal for a security enthusiast eager to make a significant impact on telecom security standards and contribute to the advancement of industry-leading practices. What you will do• Manage and troubleshoot in Multi-vendor Firewalls, IPSs, Authentication servers, Token server, Load balancers, DDOS mitigation solution.• Managing & Securing Gi traffic from GGSNs to Etisalat-Misr Internet gateway firewalls.• Managing & Securing communications among IN, VAS, IT, IP-RAN, OSS, SS7/SIGTRAN, NOC, Gi ...etc. nodes!• Responsible for data traffic performance passing through firewalls and investigation/troubleshooting in case of incidents or any abnormalities.• Responsible for defining threats and put action plan for mitigation.• Implementation of all security access requests.• Responsible for all Security IP-backbone expansions, replacements & new plans.• Handling urgent cases out of business hours. (oncall hours)• Handling 3PP Cases with vendors. You will bring• +3 Years of experience in the Security domain.• BSc. degree in computer science or Engineering, major in IT/ Communication or equivalent • Has a proven history in Scripting and automation will be preferred.• Hands-on experience in installation and management for different Firewalls vendors (Juniper SRX, Fortinet, ...).• Hands-on experience in installation and management for F5 Modules (LTM, AFM, ASM, and GTM).• Familiar with Telecom operators Network.• Good presentation and communication skills.• Customer Relationship Management skills.• JNCIP-SEC is a must and F5 certificates will be considered. Why join Ericsson?At Ericsson, you'll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what's possible. To build solutions never seen before to some of the world's toughest problems. You'll be challenged, but you won't be alone. You'll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next. What happens once you apply? Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more. Primary country and city: Egypt (EG) || Cairo Req ID: 786598

Egypt + 1 moreAll locations: Egypt | United Kingdom
HICX logo

Head of Security

HICX

The platform for supplier experience management

Full TimeRemoteTeam 51-200Since 2008H1B No Sponsor

• Set up and drive the overall information security strategy. • Own the ISMS standards and their adoption, ensuring compliance with company and external requirements including SOC 2 and ISO 27001. • Organise and manage ISMS-related scheduled activities and drive continuous improvement of the ISMS. • Contribute to security architecture and design decisions. • Oversee security tooling such as EDR, SIEM, MFA, password managers, device management, and access review processes. • Act as the primary escalation point, during and outside business hours, for all major security-related incidents and events. • Coordinate and manage corrective actions and responses to security incidents. • Own security documentation including policies, standards, exceptions, risk registers, and control evidence. • Oversee the internal risk-assessment and audit programme, supporting internal and external audits, remediating findings, and tracking control improvements to closure. • Support vendor and supplier risk management, including due diligence, sub-processor oversight, and security assessments. • Own the access control process, validate and audit access across divisions and functions. • Provide management reporting on risk posture, incidents, audit status, metrics, service trends, and improvement plans. • Work with engineering, DevOps, HR, and customer-facing teams to embed controls into everyday processes. • Drive ongoing security governance improvements. • Address data privacy and data protection concerns, and manage responses to customer data privacy requests. • Act as Data Protection Officer (DPO) for the organisation if and as required. • Help enforce security policies, building adoption, embedding them in the company culture, and introducing regular checks on departmental compliance. • Own and deliver security awareness training and campaigns to strengthen the security culture. • Complete security-related sections of RFPs and customer questionnaires, build and maintain a security knowledge base, and provide assurance of the integrity, confidentiality, and availability of information owned, controlled, and processed by the organisation. • Attend meetings with customers and prospects to provide insights into how HICX implements security across the organization. • Manage a small team of IT support admins providing internal IT support to HICX employees and contractors. • Act as the escalation point for complex IT issues, incidents, and problems requiring cross-team coordination. • Ensure IT support activities align with security controls, access management, and acceptable use requirements. • Oversee onboarding, offboarding, account lifecycle management, and device provisioning/deprovisioning. • Own and maintain standard operating procedures and the operations platform. • Help balance usability, cost, and security when selecting or renewing SaaS and IT tools. • Carry out other reasonable duties as required by the Company.

United Kingdom
Dragos logo

Staff Product Manager, Security Configuration Management

Dragos

Dragos is a computer and network security company specializing in industrial cybersecurity, incident response, threat intelligence, and security software. Past flexible jobs at Dra

Role Description Dragos is seeking a staff-level Product Manager to join the Product team building OT/ICS cybersecurity products, with a focus on security configuration management across extended operational technology (xOT) environments, which span traditional OT and ICS control systems, industrial IoT devices, and the enterprise-connected IT infrastructure that supports and influences physical operations. You will work closely with the product team, leadership, internal stakeholders, and customers to drive an effective product roadmap using product discovery, customer requests, internal requirements, use case validation, prioritization, definition, and execution for assigned products. Responsibilities - Own and evolve the product vision and strategy for Security Configuration Management (SCM) within the Dragos Platform, focused on securing the full xOT environment. - Translate customer needs, compliance mandates, and market trends into a clear quarter-over-quarter SCM roadmap. - Drive the development and management of core SCM capabilities, including configuration hardening and remediation, continuous drift detection, and compliance reporting. - Define and evolve the configuration policy engine, including logic for evaluating device configurations against security baselines and industry frameworks. - Partner with asset intelligence and data collection teams to ensure the SCM product has accurate device profiles, firmware intelligence, and vulnerability context. - Define requirements for device data normalization, configuration baseline management, and enrichment pipelines. - Engage directly with customers and customer-facing teams to discover and validate use cases, gather feedback, and iterate on product direction. - Develop a deep understanding of xOT device security posture, hardening methodologies, and the threat landscape. - Represent Dragos’s perspective on security configuration management capabilities to customers, analysts, and industry groups. - Collaborate with internal stakeholders to identify business opportunities and communicate solutions. - Make decisions regarding prioritization, trade-offs in features, timelines, resources, and quality. - Communicate product requirements with a clear business rationale to Engineering teams. - Independently measure, track, and develop plans to improve product KPIs. - Support Sales with product insights for POCs and technical guidance. - Play a key role in shaping the go-to-market strategy for SCM. Qualifications - 8+ years of Product Management experience building or maintaining enterprise security products in cybersecurity, device security, configuration management, endpoint security, or adjacent security domains. - Strong understanding of security configuration management concepts. - Experience with active device profiling and discovery methods. - Understanding of how configuration policy engines evaluate device state against security frameworks. - Exceptional analytical skills with the ability to extract valuable insights from complex data. - Technical fluency with APIs, data models, asset graphs, and backend workflows. Requirements - Salary: 200,000.00 - Competitive Equity Package - Comprehensive Benefits Plan Company Description Dragos is on a relentless mission to defend industrial organizations that provide us with the necessities of modern civilization; running water, functioning electricity, and safe industrial working environments. As the market leader in ICS/OT Cybersecurity, we are dedicated to arming our customers with best-in-class technology, threat intelligence, and services to protect their systems as effectively and efficiently as possible. We’re a remote-first culture with operations in North America, Europe, the Middle East, and APAC.

United States
$200K / year
HICX logo

Information Security Manager

HICX

The platform for supplier experience management

Full TimeRemoteTeam 51-200Since 2008H1B No Sponsor

Role Description We are hiring for an Information Security Manager to manage our internal IT function reporting to the CFO, or such other person as the Company may appoint from time to time. Security Strategy & Compliance - Set up and drive the overall information security strategy. - Own the ISMS standards and their adoption, ensuring compliance with company and external requirements including SOC 2 and ISO 27001. - Organise and manage ISMS-related scheduled activities and drive continuous improvement of the ISMS. - Contribute to security architecture and design decisions. - Oversee security tooling such as EDR, SIEM, MFA, password managers, device management, and access review processes. Incident & Escalation Management - Act as the primary escalation point, during and outside business hours, for all major security-related incidents and events. - Coordinate and manage corrective actions and responses to security incidents. Governance, Risk & Audit - Own security documentation, including policies, standards, exceptions, risk registers, and control evidence. - Oversee the internal risk-assessment and audit programme, supporting internal and external audits, remediating findings, and tracking control improvements to closure. - Support vendor and supplier risk management, including due diligence, sub-processor oversight, and security assessments. - Own the access control process, validate and audit access across divisions and functions. - Provide management reporting on risk posture, incidents, audit status, metrics, service trends, and improvement plans. - Work with engineering, DevOps, HR, and customer-facing teams to embed controls into everyday processes. - Drive ongoing security governance improvements. Data Privacy - Address data privacy and data protection concerns, and manage responses to customer data privacy requests. - Act as Data Protection Officer (DPO) for the organisation if and as required. Policy, Awareness & Customer Assurance - Help enforce security policies, building adoption, embedding them in the company culture, and introducing regular checks on departmental compliance. - Own and deliver security awareness training and campaigns to strengthen the security culture. - Complete security-related sections of RFPs and customer questionnaires, build and maintain a security knowledge base, and provide assurance of the integrity, confidentiality, and availability of information owned, controlled, and processed by the organisation. - Attend meetings with customers and prospects to provide insights into how HICX implements security across the organization. Internal IT & Operations - Manage a small team of IT support admins providing internal IT support to HICX employees and contractors. - Act as the escalation point for complex IT issues, incidents, and problems requiring cross-team coordination. - Ensure IT support activities align with security controls, access management, and acceptable use requirements. - Oversee onboarding, offboarding, account lifecycle management, and device provisioning/deprovisioning. - Own and maintain standard operating procedures and the operations platform. - Help balance usability, cost, and security when selecting or renewing SaaS and IT tools. - Carry out other reasonable duties as required by the Company. Qualifications - Excellent track record of leading security audits; ISO 27001, SOC 2, Cyber Essentials Plus. - Proven experience in a senior information security leadership role (Head of Security, Information Security Manager, or similar), ideally within a SaaS or technology business. - Demonstrable experience building, operating, and maturing an ISMS, including achieving and maintaining SOC 2 and ISO 27001 certification. - Strong, hands-on knowledge of security tooling and controls; EDR, SIEM, MFA, identity and access management, device/endpoint management, and vulnerability management. - Solid understanding of cloud security (AWS, Azure, and Microsoft 365 admin suite). - Experience leading end-to-end security incident response, including out-of-hours management of major incidents. - Knowledge of UK GDPR/GDPR and global data protection laws, with experience acting as, or working closely with, a Data Protection Officer. - Experience of third-party, vendor, and supplier risk management, including due diligence and sub-processor oversight. - Experience completing customer security questionnaires and RFPs, maintaining a security knowledge base, and presenting security posture to customers and prospects. - Excellent communication skills, with the ability to translate technical risk into clear business language for technical and non-technical audiences, including executives and customers. - Strong leadership and people-management skills, with a track record of developing and motivating a small team. - Pragmatic, risk-based mindset that balances security with business enablement, usability, and cost. - Highly organised, self-motivated, and comfortable working autonomously within a fully remote, international team. - Collaborative and influential, able to embed a strong security culture across the whole organisation. - Relevant professional certification is desirable (e.g. CISSP, CISM, CISA, or ISO 27001 Lead Implementer/Auditor). - Experience managing internal IT operations and a small IT support team, onboarding/offboarding, account lifecycle, device provisioning, and SaaS administration is desirable. Benefits - Work from anywhere within the UK - we are a fully remote company. - Private health insurance. - Flexible PTO - We offer 25 days of paid holiday per year + England Bank Holidays. - We celebrate special occasions with you - like your birthday! Additional PTO for all employees during their birthdays. - Receive Competitive Pay - Our team makes sure to provide a highly competitive rate based on your skills and location. - Work with a diverse, international team.

United Kingdom