Full-Time Senior Application Security Engineer
Experian is hiring a remote Full-Time Senior Application Security Engineer. The career level for this job opening is Senior Manager and is accepting Costa Mesa, CA based applicants remotely. Read complete job description before applying.
Experian
Job Title
Posted
Career Level
Career Level
Locations Accepted
Share
Job Details
In this remote role, reporting to the Director of Application Security, you will work with software engineers and leadership to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC).
You will do this by:
- Collaborating with development teams to understand their needs, assess risks, and customize solutions.
- Implementing and managing security tools (SAST, SCA, DAST) and integrating solutions into CI/CD pipelines.
- Reviewing applications against common flaws (e.g., OWASP Top 10) and providing visibility to senior management.
- Working with Risk & Compliance teams on audits (e.g., SOC 2, PCI-DSS, HIPAA) and recommending relevant policies.
- Defining security guardrails through automated tool policies, SLAs, and custom rules.
Required Experience:
5+ years of direct experience in enterprise-level application security, with a strong understanding of MITRE, OWASP, SafeCode, and risk management methodologies related to integration/software testing.
Experience in AppSec or DevSecOps, collaborating with developers to adopt and mature secure development practices.
Proficiency with SAST, SCA, DAST, IAST, RASP, and other DevSecOps tools, including deploying, maintaining, operating, and improving these tools.
Solid background in software development, familiar with development lifecycle processes and technologies.
Experience with CI/CD pipelines and related technologies (e.g., Git, Jenkins, Maven, Chef, Puppet, Ansible, Nexus, Artifactory, NPM) and cloud-based architectures.
Experience overseeing the integration of cross-functional applications between disparate business units and systems.
Expertise in business and technical requirements analysis, business process modeling/mapping, methodology development, and data mapping.
Project management skills and substantial exposure to project-based work structures and lifecycle models.
Experience understanding and addressing end-user needs and requirements.