CybersecurityJobs.io
← Back to all jobs

Job Description

Within PACCAR’s IT Division and Global Security group, this Application Security Engineer role focuses on improving application and API security across the portfolio. The position provides security guidance through code review, automated application testing, vulnerability assessment, secure development practices, and secure SDLC risk analysis.

Key Responsibilities

  • Conduct secure source code reviews using manual analysis and SAST tools to identify vulnerabilities.
  • Perform web security assessments for websites, web applications, web services, and APIs using DAST tools.
  • Review outcomes from automated security tools, confirm automated tests complete successfully, and identify or remove false positives from tool reports.
  • Develop and review threat models to proactively surface security risks.
  • Partner with development teams to support vulnerability remediation through consulting or hands-on assistance.
  • Help developers understand security defects, their associated risk, and define acceptable remediation approaches.
  • Collaborate to integrate secure coding practices and security tooling into CI/CD pipelines.
  • Provide security input during code reviews and design discussions.
  • Support adherence to application security controls and contribute to application risk analysis throughout the SDLC.
  • Contribute to the creation, maintenance, and communication of PACCAR secure coding standards, guidelines, and examples.
  • Support implementation of secure design principles aligned to organizational policies, standards, and application security patterns.
  • Create technical security documentation, including assessment reports and remediation guidance.
  • Share application security knowledge with engineering teams through brown bags, secure coding tournaments, and developer outreach.
  • Participate in strengthening security culture and awareness across the organization.
  • Support security incident response when needed.
  • Maintain and tune Secure SDLC tools including SAST, DAST, and Software Composition Analysis (SCA) platforms.
  • Support integration of security tooling and automated security checks within CI/CD pipelines.
  • Stay current with relevant security technologies, products, and emerging application security trends.

Required Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or a related field.
  • 5+ years of professional experience in application or software security, including hands-on secure code review, vulnerability assessment, threat analysis, or secure development practices.
  • Hands-on experience with application security testing tools, including DAST platforms (e.g., Burp Suite, WebInspect, OWASP ZAP) and SAST/SCA tools (e.g., Fortify, Checkmarx, SonarQube).
  • Programming language proficiency in one or more of C#, JavaScript, and/or Python.
  • Strong working knowledge of web application technologies, including HTTP, HTML, CSS, and JavaScript.
  • Expert-level understanding of the OWASP Top 10 and common web application vulnerabilities and website security concepts (headers, cookies, CORS, XSS, CSRF).
  • Familiarity with web authentication technologies including OAuth and/or SAML.
  • Experience with SDLC and development methodologies such as Waterfall and Agile.
  • Experience with source control systems: Git, GitHub, Azure DevOps.
  • Experience working in a large enterprise environment.
  • Experience with penetration testing or security tools (e.g., Kali Linux, Nmap).
  • Familiarity with cloud environments such as Azure, AWS, or GCP.
  • Certifications: CSSLP, CISSP, and/or CompTIA Security+.

Technologies and Tools

SAST, DAST, Software Composition Analysis (SCA), Burp Suite, WebInspect, OWASP ZAP, Fortify, Checkmarx, SonarQube, C#, JavaScript, Python, HTTP, HTML, CSS, OWASP Top 10, headers, cookies, CORS, XSS, CSRF, OAuth, SAML, SDLC, Waterfall, Agile, Git, GitHub, Azure DevOps, Kali Linux, Nmap, Azure, AWS, GCP, CI/CD, Secure SDLC tools, COTS, and open-source software.

Location and Salary

  • Location: Renton, WA, US (onsite)
  • Salary: USD 90,000 to 141,000 per year

Benefits

  • 401k with up to a 5% company match
  • Employee Stock Purchase Program (ESPP)
  • Fully funded pension plan providing monthly benefits after retirement
  • Comprehensive paid time off: minimum of 10 paid vacation days (additional days with additional seniority/years of service), 12 paid holidays, and sick time
  • Tuition reimbursement for continued education
  • Medical, dental, and vision plans for you and your family
  • Flexible spending accounts (FSA) and health savings account (HSA)
  • Paid short- and long-term disability programs
  • Life and accidental death and dismemberment insurance
  • EAP services that include wellness plans, estate planning, and financial counseling

Additional Information

  • PACCAR is an Equal Opportunity Employer and Protected Veteran/Disability employer.
  • No sponsorship for work authorization is provided for this position, including but not limited to H-1B visas, now or in the future.
  • Salary range: $90,000 - $141,000 annually.
  • This role is eligible for the full range of benefit options listed above.

Similar Jobs