Job Closed

This listing is no longer active.

WEXWEXUS

WEX simplifies the business of running a business through smarter workflows and financial intelligence. Our North America Mobility and OTR businesses power the fleets that keep commerce moving — from small owner-operators to large fleet enterprises. Pay Range $198,000.00 - $223,700.00

Application Security Architect

Location

United States

Posted

66 days ago

Salary

$109.3K - $133K / year

Seniority

Mid Level

Job Description

Application Security Architect

WEXWEXUS

Role Description Wex, Inc. is looking for an Application Security Architect with broad software development and application security experience. This individual would be responsible for designing, guiding, and assessing security solutions in software projects to ensure that security is built in from the beginning. With the assistance of tools including SAST, DAST and SCA, perform assessments of software projects to identify security issues and guide teams to effective remediations. We’re the Global Product Security Team at WEX, responsible for enabling a modern and effective Secure Software Development Lifecycle throughout WEX. We partner closely with internal teams and customers to assure WEX operates in a secure and compliant manner. Our team holds itself to a high standard and we collaborate closely with one another to ensure strong, reliable and effective relationships. We own our results and we take pride of ownership in everything we do. Qualifications - A highly motivated security architect who loves working on small, high performing teams that interface with the entire enterprise. - A collaborative, solid communicator who works well with your team and stakeholders to drive projects from inception to completion. - Someone who cares deeply for team results but is able to work independently to deliver high quality solutions for projects and operational tasks. - Comfortable balancing the need to move fast with the realities of working in a highly regulated organization. - Passionate about security, but pragmatic about delivering business value. - Customer focused - whether it’s internal teams that we’re supporting or the WEX partner, you prioritize ensuring they have a great experience with WEX and our team. - A skilled worker that has the motivation, expertise, and work ethic to operate independently across global time zones, and who is able to complete tasks and deliverables with minimal oversight. - A leader who builds consensus and drives change through buy-in and education rather than mandates. - Able to mentor other engineers & architects on your team and other teams both technically and professionally. - Champion of a shift-left and DevSecOps approach to security, but tenacious enough to build such a program from the ground up. - A lifelong learner that is excited by new technologies and challenges. Requirements - Subject Matter Expert in software development and software security, particularly with web applications, APIs, mobile apps and enterprise applications delivered in a SaaS model. - Perform manual and automated secure code reviews, assisted with commercial static and dynamic application security scanning tools (SAST, DAST, SCA, etc). - Do web application and mobile app penetration testing. - Deliver actionable security guidance to project teams. - Analyze security assessments and effectively communicate requirements to appropriate software development, network and configuration management teams. - Actively participate in Security Development Lifecycle efforts such as performing secure architecture reviews, secure code reviews, threat models and penetration testing through the software development lifecycle. - Keep abreast of security industry best practices and OWASP recommendations utilizing knowledge to contribute to remediation efforts across the platform, as well as security policies and procedures. - Identify and partner with security champions in the development organization to scale security expertise and awareness. - Write comprehensive reports including assessment-based findings, outcomes and recommendations for security enhancement. - Deep experience working with compliance and regulatory frameworks such as PCI-DSS, HIPAA/HITRUST, SOX, GDPR, NIST, etc. - 3-5+ years of progressive experience in software development. C#, Java, Go or Python preferred. - 3+ years experience with software security or information security. - 2+ years experience with application and container security tools such as SAST, DAST, SCA, IaC scanning and container image scanning, including integrating them to build and ticketing tools. - Very familiar with common application security issues, i.e., OWASP Top10, and appropriate mitigation strategies. - Able to troubleshoot security issues within a complex on-prem and multi-cloud environment. - A degree in Business, Computer Science or equivalent combination of education and relevant experience. - Experience working closely with many teams across departmental and business unit boundaries. - Can commit and deliver on very specific project/delivery timelines with minimal supervision. - Excellent communication skills, both written and verbal. Benefits - Health, dental and vision insurances. - Retirement savings plan. - Paid time off. - Health savings account. - Flexible spending accounts. - Life insurance. - Disability insurance. - Tuition reimbursement. - Comprehensive and market competitive benefits designed to support your personal and professional well-being. Pay Range $109,300.00 - $133,000.00

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Advocating best practices for the customer and internal teams during product implementation, and providing customer feedback to the Product team • Being the central point of contact for customers and leading the integrated account team delivering customer success • Partnering with the business to review and ensure integration efficiency, high quality service and keep customers engaged • Identifying service enhancements and potential problems to ensure continuous improvements to quality of customer service delivery • Communicating with internal, external customers and partners to share information and deliverables

United Arab Emirates
Form3 logo

Senior Cloud Security Engineer

Form3

We design, build and run the technology that powers the future of payments.

Full TimeRemoteTeam 501-1,000H1B No Sponsor

Senior Cloud Security Engineer Location: Germany, Netherlands, Spain, Portugal & UK 100% Remote You’ll design, implement, and maintain defensive security controls that protect our high-availability, multi-cloud payment systems built on modern technologies. Your deep understanding of current threats, exploitation methods, and risk trade-offs will enable you to guide engineering teams on effective security features and ensure the right defensive measures are prioritised. WE’RE LOOKING FOR Essential - You live on the linux command line - Your current research and experience back up your opinionated views on security practices and tradeoffs, which you love to openly debate and willingly share - You’re sought after for your security engineering expertise, having built multiple security controls that are actively proven in large production estates - Your security expertise extends to at least one public cloud, including essential security features and long-term security hardening practices - You have a good grounding in Kubernetes security and have ideally developed complex, heavily customised multi-cluser environments - You appreciate building systems with good engineering practices and may have a background in software engineering at scale - You’re open to being a part of our on-call rota, ready to respond if we have a severe, platform-impacting security tooling failure or need second-line security incident response assistance Desirable - You have an interest in offensive security, potentially including participation in CTFs and past experience as a red team operator or pen tester - You’ve developed security configurations in multiple public and private clouds - You’re a confident presenter and have accelerated appreciation of security across engineering teams - You regularly support building and analysis of threat models using a well defined process - You have experience securing data centers and networking devices - You’re terrified by supply chain and CI/CD security, but have good patterns for reducing the risks - Your engineering experiences matches Form3’s tech stack – including Golang and Terraform TECH STACK ⚙️ - AWS, GCP, Azure and private Data Centers - Kubernetes, Helm, Flux - Distributed systems, mostly Golang based with CockroachDB and NATS - SIEM/SOAR, EDR, CNAPP, and a suite of open source tools with custom integrations THE TEAM You will join a team of defensive security engineers directly maintaining and expanding security controls as well as advising the wider platform and application engineers within our R&D team. We report into the CISO and work alongside the other functional pillars of InfoSec. HIRING LOCATIONS We are a remote-first organisation and are able to accept applications from the following countries; Germany, Netherlands, Spain, Portugal & UK

Germany + 4 moreAll locations: Germany | Netherlands | Spain | Portugal | United Kingdom
Form3 logo

Senior Cloud Security Engineer - Kubernetes

Form3

We design, build and run the technology that powers the future of payments.

Full TimeRemoteTeam 501-1,000H1B No Sponsor

Senior Cloud Security Engineer (Kubernetes) Location 100% Remote (UK/EU*) You will build and run defensive security controls for highly-available multi-cloud payment systems running the latest technology. You understand current threats, exploitation paths and risk tradeoffs in order to advise engineering teams on beneficial security features as well as prioritise management of defensive controls. WE’RE LOOKING FOR Essential - You live on the linux command line - Your current research and experience back up your opinionated views on security practices and tradeoffs, which you love to openly debate and willingly share - You’re sought after for your Kubernetes security expertise and have developed complex heavily customised multi-cluser environments - Your security expertise extends to at least one public cloud, including essential security features and long-term security hardening practices - You appreciate building systems with good engineering practices and may have a background in software engineering at scale - You’re open to being a part of our on-call rota, ready to respond if we have a severe, platform-impacting security tooling failure or need second-line security incident response assistance Desirable - You have an interest in offensive security, potentially including participation in CTFs and past experience as a red team operator or pen tester - You’ve developed security configurations in multiple public and private clouds - You’re a confident presenter and have accelerated appreciation of security across engineering teams - You regularly support building and analysis of threat models using a well defined process - You have experience securing data centers and networking devices - You’re terrified by supply chain and CI/CD security, but have good patterns for reducing the risks - Your engineering experiences matches Form3’s tech stack – including Golang and Terraform TECH STACK - AWS, GCP, Azure and private Data Centers - Kubernetes, Helm, Flux - Distributed systems, mostly Golang based with CockroachDB and NATS - SIEM/SOAR, EDR, CNAPP, and a suite of open source tools with custom integrations THE TEAM You will join a team of defensive security engineers directly maintaining and expanding security controls as well as advising the wider platform and application engineers within our R&D team. We report into the CISO and work alongside the other functional pillars of InfoSec. We are a remote-first organisation and are able to accept applications from the following countries; Germany, Netherlands, Spain, Portugal & UK

Germany + 4 moreAll locations: Germany | Netherlands | Spain | Portugal | United Kingdom
Ardent logo

IT Subject Matter Expert

Ardent

Your "ALL IN" Location Intelligence | Digital Transformation | Data Science & Analytics experts

Full TimeRemoteTeam 51-200Since 2008H1B Sponsor

Role Description Ardent is seeking an IT Subject Matter Expert to support enterprise IT initiatives within a federal environment. This role will provide technical expertise, operational support, and stakeholder coordination across enterprise systems, governance activities, and modernization efforts. The position will support technical initiatives requiring strong analytical, problem-solving, and enterprise IT experience. Responsibilities and Duties - Provide subject matter expertise supporting enterprise IT governance and modernization initiatives. - Support technical governance activities, operational planning, and strategic IT initiatives. - Provide recommendations regarding enterprise IT processes, systems, and operational improvements. - Collaborate with stakeholders, technical teams, and leadership to support program objectives. - Support development of technical documentation, reports, and briefings. - Assist with analysis of enterprise IT environments, systems, and operational requirements. - Participate in governance meetings, technical reviews, and planning discussions. - Provide guidance on IT standards, best practices, and operational processes. - Support coordination across technical and business teams to ensure alignment with program goals. - Contribute to continuous improvement and modernization efforts across enterprise IT operations. Qualifications - Bachelor’s degree in Computer Science, Engineering, or related field. - Minimum of 10 years of experience in Information Technology environments. - Minimum of 4 years of experience supporting enterprise IT initiatives or enterprise-scale environments. - Experience supporting technical governance, enterprise IT operations, or modernization efforts. - Strong communication and stakeholder coordination skills. - Ability to support complex technical and operational initiatives in a federal environment. - Strong analytical, organizational, and problem-solving abilities. Preferred Qualifications - Experience supporting federal government environments. - Experience supporting IT governance, enterprise architecture, or modernization programs. - Familiarity with enterprise IT infrastructure, cybersecurity, or cloud environments. - Experience developing technical reports, governance documentation, or executive briefings. - Experience collaborating across multidisciplinary technical teams. Requirements Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process. We highly encourage all Veterans and those with disabilities to apply. Benefits - Competitive pay. - Comprehensive health coverage. - Flexible PTO. - Federal holidays off. - Tuition reimbursement. - Professional development support. - Wellness stipends. - A culture that values and rewards hard work, dedication, and adaptability. Company Description Ardent hires people who want more than a job — they want to serve a mission that matters. Our teams support the federal government’s most critical national security and defense priorities, helping protect the nation, strengthen resilience, and advance the technologies and capabilities that keep America secure.

United States