Skip to content

Open nowPosted 9 days ago

Senior Application Security Engineer

Verisign24 open roles

Pay
$164,300 – $222,300 a year
Where
Reston,Virginia,United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Application Security EngineerVerisign · Reston,Virginia,United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Verisign's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Verisign postings stay open a median of 42 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 9 days ago

Verisign median: 42 days open

The posting

Verisign helps enable the security, stability, and resiliency of the internet. We are a trusted provider of internet infrastructure services for the networked world and deliver unmatched performance in domain name system (DNS) services.

We are a mission focused, values driven company where each individual can contribute to building a stronger, more secure internet. We offer a dynamic and flexible work environment with competitive benefits and the ability to grow your career.

The Senior Application Security Engineer will play a lead role in securing all software built and/or used by Verisign. The engineer will work with application development teams as well as 3rd party organizations to ensure that security, privacy, and compliance are built into applications from design through production. The engineer should be a technical leader helping determine the future of the application security program and actively participating in a broad spectrum of activities by leading assessments, following security research and best practices, and helping set the standards of the program. The individual should possess strong interpersonal skills, be highly motivated, results oriented, have excellent communication and presentation skills, and be a strong team player.

Responsibilities:

  • Serve as the application security subject matter expert for development teams during requirement, design, and architecture phases, including application threat modeling for new and significantly changed applications
  • Perform and lead deep dive manual and automated application vulnerability assessments, documenting findings, and provide clear remediation guidance to the responsible engineering teams
  • Own the application security vulnerability management lifecycle across the security toolchain, including software composition analysis, static and dynamic testing, interactive testing, secrets scanning
  • Review and provide remediation guidance for submissions from Verisign’s public Bug Bounty program
  • Track open issues against defined SLAs, follow up with development teams, and escalate overdue items to engineering and InfoSec leadership
  • Provide guidance to support integration of security testing into CI/CD pipelines
  • Review third party and vendor supplied applications against internal security requirements
  • Mentor junior engineers and analysts, review peer work, and provide constructive feedback
  • Contribute to Information Security standards, secure coding guidance, and be an active participant in the broader Verisign technical community

AI and Application Security:

  • Assess applications that embed large language models or other AI services for risks such as prompt injection, sensitive data exposure, insecure output handling, and over permissioned agents and integrations
  • Develop and maintain internal guidance for developers using AI coding assistants, including expectations for review, testing, and scanning of AI generated code
  • Evaluate and pilot AI assisted capabilities within the application security workflow such as finding triage, false positive reduction, and remediation guidance
  • Track developments in AI security guidance and standards and translate them into practical internal requirements and guidance

Key skills and experience:

  • 10+ years’ experience in Information Technology, including hands on application development experience
  • 6+ years’ experience conducting application security assessments using COTS and open-source tooling (Burp Suite, Fortify, or equivalent)
  • Hands-on experience with software composition analysis, dynamic application security testing, and secrets scanning platforms
  • Experience running a vulnerability management program through ticketing and workflow systems, including SLA definition and executive level reporting
  • Strong working knowledge of the OWASP Testing Framework and OWASP Top 10
  • Proficiency in currently accepted software development life cycles and associated standards and procedures
  • Knowledge of current application architectures (Single Page Application, 3 tier, microservices, containerized workloads)
  • Practical familiarity with AI and LLM application security risks and current industry guidance in that area
  • Methodical and organized, able to manage multiple opportunities, projects, and partners concurrently
  • Able to multitask and work independently with minimum supervision to meet firm deadlines
  • Excellent communication, presentation, and leadership skills, including the ability to present to senior technical and non-technical audiences

Preferred skills and experience:

  • 6+ years software development using Java, C++, Rust, Go and/or scripting languages such as Python or Perl
  • Experience implementing security assessments within a Continuous Integration pipeline
  • Advanced experience with Linux operating systems, high comfort level with working at the command line
  • Understanding of Agile methodologies (Kanban, Scrum, pair programming, etc.)
  • Understanding of DevOps and security integration
  • Experience with API security testing
  • Experience running or supporting a public or private bug bounty program

This position is based in our Reston, VA office and offers a hybrid work schedule.

The pay range is $164,300 - $222,300.

The anticipated annual base salary range for this position is noted above, however, base pay offered may vary depending on job-related knowledge, skills, experience. Verisign offers a discretionary bonus which is based on individual and company performance, and certain roles may be eligible for discretionary stock awards.

Verisign is an equal opportunity employer. That means we recruit, hire, compensate, train, promote, transfer, and administer all terms and conditions of employment without regard to their race, color, religion, national origin, sex, sexual orientation, gender identity, age, protected veteran status, disability, or other protected categories under applicable law.

Additional Information: Our Careers Page Our Benefits Summary Verisign in the Community Our EEO Statement Our Privacy Notice for Job Applicants/Candidates Reasonable Accommodations

Staffing agency policy: No fees will be paid for unsolicited resumes submitted to Verisign or our employees by third parties.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Verisign's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Verisign's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Verisign's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.