The posting
Job Summary
The Application Security Engineer will drive the development and operationalization of Malcode and CBOM capabilities, focusing on security assessment, risk validation, remediation guidance, and automation to strengthen application security posture.
Responsibilities
Security Engineering & Development
- Develop and enhance Malcode and CBOM capabilities to improve security detection and response
- Implement workflow automation and process improvements to increase efficiency and reduce manual effort
- Integrate security tools, repositories, and supporting platforms to streamline security operations
- Enhance analysis and reporting capabilities to provide actionable security insights
Security Assessment & Remediation
- Analyze security findings for exploitability, severity, and business impact to prioritize risks
- Review source code, logs, and technical artifacts to identify vulnerabilities
- Identify false positives and duplicate findings to ensure accurate vulnerability tracking
- Validate remediation activities and conduct retesting to confirm issue resolution
- Provide remediation guidance to application teams to support secure development practices
Governance & Operations
- Manage vulnerability and finding lifecycle processes to maintain security oversight
- Track remediation progress and risk disposition to ensure timely risk mitigation
- Produce operational and management reports to inform stakeholders
- Support governance reviews and stakeholder engagements to align security efforts with business objectives
Required competencies and certifications
- Application Security Testing (SAST, DAST, SCA) applied to identify and assess vulnerabilities
- Software Composition Analysis and dependency risk management to secure third-party components
- Secure SDLC practices to embed security throughout the development lifecycle
- Source code review and vulnerability assessment to detect security flaws
- Automation and scripting (Python, PowerShell, or similar) to enhance security workflows
- Security reporting and analytics to deliver meaningful security metrics and insights
Preferred competencies and qualifications
- CEH, GWAPT, CSSLP, OSCP, or equivalent certifications demonstrating professional security expertise
- Experience with SBOM/CBOM, malware analysis, and software supply-chain security to address emerging threats
- Prior experience in enterprise-scale application security programs to manage complex security environments



