Application Security Engineer at ProSight Financial Association
Remote, Oregon, USA -
Full Time


Start Date

Immediate

Expiry Date

16 Nov, 25

Salary

140000.0

Posted On

16 Aug, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Good communication skills

Industry

Information Technology/IT

Description

REPORTS TO: DIRECTOR, PRODUCT DEVELOPMENT & OPERATIONS

BAI and RMA have come together as ProSight Financial Association, a leading industry organization whose purpose is to empower financial services leaders to strengthen and advance our industry. The strategic combination brings together RMA’s expertise in serving the commercial banking and risk management functions and BAI’s knowledge in serving the retail banking and regulatory compliance functions. It’s a complementary union of two non-profit organizations that have always had their members’ and customers’ best interests in mind. Our industry-leading offerings include peer sharing events, thought leadership, learning and development, and decision support solutions. Our work creates positive ripple effects throughout financial services organizations and ultimately helps consumers, businesses and communities thrive.
We are seeking an Application Security Engineer who will collaborate with software engineers to establish and enforce secure coding practices, contribute to defining security best practices, and foster a culture that promotes security as a core tenet, from initial design through production deployment.

Responsibilities
  • Collaborate with developers and operations teams to anticipate security vulnerabilities, proactively assess and identify potential risks, develop mitigation strategies, and ensure that security measures are incorporated throughout the entire application development process
  • Lead application security reviews and threat modeling efforts, including code reviews, dynamic testing, penetration testing, hacker simulations, and reviewing applications against OWASP Top 10
  • Integrate security tools and processes into the DevOps pipeline to automate security checks and scans to identify and fix vulnerabilities early in the development process
  • Establish and maintain secure coding standards and best practices and provide guidance and training to development teams
  • Collaborate with development, DevOps, and IT teams to ensure that security measures are implemented in production environments
  • Help manage security incident response and recovery processes, including impact assessment, remediation, root cause analysis, and preventative measures
  • Define, develop, and present key application security metrics, identify critical issues proactively, and communicate them effectively to stakeholders.
  • Ensure compliance with relevant security regulations and standards, especially those relevant to banking and finance
  • Stay current with the latest security threats, trends, and countermeasures to ensure that the organization’s applications are always protected
Loading...