Application Security Engineer
Job Description
Wawa, Inc. is seeking an Application Security Engineer to help strengthen security across the software lifecycle for internally developed applications. This onsite role in Media, PA focuses on day-to-day application security operations, improving the application security program, and serving as a technical resource to support secure software development throughout the SDLC.
The successful engineer will collaborate closely with developers and product owners, support secure coding practices, and help identify and remediate application and platform security risks. In addition to threat research and vulnerability management, the role supports reviews, testing activities, incident response participation, audit readiness, and internal enablement through security presentations.
Responsibilities
- Support security best practices in the software development lifecycle by partnering with developers and product owners to secure applications at all stages.
- Research, identify, and communicate current and emerging application security threats, along with applicable solutions.
- Maintain and iterate on secure coding practices, policies, standards, and procedures.
- Test applications for security threats and vulnerabilities.
- Support application security vulnerability management.
- Create and deliver security presentations for internal audiences, both technical and non-technical.
- Identify security design gaps in existing and proposed applications and recommend changes or enhancements.
- Continually assess the Application Security Program for gaps and inefficiencies, then propose solutions.
- Participate in and support application security reviews, penetration tests, and threat modeling.
- Contribute to internal security-focused program direction.
- Assist with developing metrics and a reporting framework to measure program effectiveness.
- Support development and maintenance of technology security policies and standards, ensuring their application to technology architectures.
- Assist with ongoing compliance with regulatory obligations and internally developed policies and standards.
- Provide support to the Technology Security Incident Response team during cyber incidents.
- Maintain internal relationships across information security, information technology, and development teams to support alignment on initiatives.
- Maintain external relationships with industry peers, ecosystem partners, vendors, and other parties to address shared trends, findings, and cybersecurity risks.
- Serve as a technical resource for internal business teams and the IT department to plan, implement, and support new and existing software.
- Support audit and assessment activities for IT, including the annual PCI audit, IT general controls review, and other audits or assessments related to security and general IT controls.
- Provide application security guidance on IT and business-related projects as required, and participate in IT and security related projects.
- Work with business units to facilitate application security engineering requirements and advocate for application security best practices.
Requirements
- Minimum 2 years of experience in a complex technology environment in the application security engineering field.
- Proven experience securing custom software.
- Ability to work individually and collaboratively in a team environment.
- Ability to learn on the job and effectively track task progress.
- Experience working with teams of developers and product owners.
- Strong written and verbal communication skills, including the ability to explain application security and risk concepts to diverse audiences.
- Poise and ability to act calmly in high-pressure, high-stress situations.
- Critical thinking and strong problem-solving skills.
- Ability to manage multiple projects with strict timelines in a demanding, dynamic environment.
- Ability to engage in internal security technology and security remediation projects.
- Ability to understand large technology implementations spanning hundreds of physical and virtual environments.
- High personal integrity and ability to handle confidential matters with appropriate judgment and maturity.
- High initiative and dependability, resilient to change, and able to work with limited supervision.
- Ability to participate in on-call 24x7x365 rotation for information security incidents.
- Advanced knowledge of containers and container security.
- Solid knowledge of cloud technology and security.
- Solid knowledge of Java programming.
- Basic knowledge of Golang programming.
- Basic knowledge of React and React Native programming.
- Experience reading and writing enterprise software.
- Experience preventing and remediating software security flaws in enterprise software.
- Up-to-date knowledge of common security weaknesses and flaws, including prevention and remediation.
- Advanced knowledge of OWASP guidance.
- Solid knowledge of web-related protocols such as TCP/IP, HTTP, HTTPS, and REST.
- Understanding of relevant legal and regulatory requirements such as Payment Card Industry Data Security Standard (PCI DSS).
- Degree in computer science preferred, or equivalent professional experience.
- Professional security management certification preferred, such as CISSP, CISM, GDSA, CSSLP, CEH, etc.
- Solid knowledge of information security management frameworks such as Critical Security Controls, and NIST 800-53 and the Cybersecurity Framework.
- Significant knowledge of application security concepts and technologies including SAST, DAST, SCA, IaC, cryptography, authn/authz, and API security.
- Strong understanding of cloud, application security, and software engineering principles.
- Experience with scripting and automation (including Python, PowerShell, Unix shell, JavaScript, and TypeScript).
- Proven experience and strong understanding of DevSecOps and SAFE Agile working methodologies.
Technologies
- container security
- Java
- Golang
- React
- React Native
- OWASP guidance
- TCP/IP, HTTP, HTTPS, REST
- Payment Card Industry Data Security Standard
- Critical Security Controls
- NIST 800-53
- Cybersecurity Framework
- SAST, DAST, SCA, IaC
- cryptography
- authn/authz
- API security
- Python, PowerShell, Unix shell
- JavaScript, TypeScript
- DevSecOps, SAFE Agile
- PCI audit, IT general controls review