CybersecurityJobs.io
← Back to all jobs

Job Description

American Specialty Health Incorporated is seeking an Application Security Engineer II to help protect and defend the organization’s information security posture and assets. The role emphasizes maintaining regulatory compliance, reducing cyber risk, and supporting day-to-day application security and security testing activities as part of a DevSecOps-aligned environment.

Role focus

  • Perform day-to-day information security functions.
  • Support security testing, penetration testing, red teaming, and incident response activities.
  • Help coordinate security issue and remediation efforts between ASH scrum teams.
  • Serve as a point of contact for vulnerability questions and remediation options.
  • Research and communicate current trends in information security and threat environments.

Responsibilities

  • Assist with documenting improvements, including automation, for information security solutions in concert with DevSecOps activities.
  • Deploy and/or act as product owner for at least one product within the application security stack.
  • Support administration of security-related systems such as security and compliance testing software, web application firewalls, open source software, attack simulation, and vulnerability management.
  • Maintain updated documentation of technical controls, processes, and procedures.
  • Availability for after-hours work and occasional travel is required.
  • Perform other duties as assigned and comply with all policies and standards.

Requirements

  • Bachelor’s Degree in an IT-related field or relevant work experience; if equivalent experience applies, a high school diploma is required.
  • 5 years of software development with a security focus, including systems/software security testing and/or security administration.
  • High proficiency in scripting and automation across languages and platforms, including consuming and processing common API results.
  • Medium proficiency providing security guidance and implementation steps to software development teams with limited oversight.
  • Medium proficiency implementing security technologies and solutions within application security suite products.
  • High proficiency in web application vulnerabilities, OWASP recommendations, and mitigation strategies.
  • Medium proficiency understanding network and software architectures and design.
  • High proficiency with proxies such as BurpSuite or ZAP for manual validation of application security findings.
  • High proficiency in end-to-end application testing across API, logic flows, database, GraphQL, Windows networks and resources, Linux applications, and Azure cloud.
  • High proficiency with Static Code analysis tools, including their limitations and pipeline integrations/actions.
  • Medium proficiency with WAF technology setups, common limitations, and Runtime Protection concepts and implementation.

Technologies and tools

  • DevSecOps
  • Web application firewalls
  • Open source software
  • Attack simulation
  • Vulnerability management
  • OWASP
  • BurpSuite, ZAP
  • API, GraphQL
  • Static Code analysis tools
  • WAF
  • Runtime Protection
  • Azure cloud

Remote work and equipment

  • Trained remotely and required to work from home (WFH) in a designated work area using company-provided technology equipment.
  • Must have a stable internet connection to participate by video in online meetings over a reliable, consistent network.
  • Minimum internet speed requirement: 50 down / 10 up Mbps.
  • 100 down / 20 up Mbps is recommended to support higher quality video meetings.

Core competencies

  • Demonstrated ability to interact in a positive, respectful manner and build cooperative working relationships.
  • Excellent customer service to meet internal and external customer expectations.
  • Strong listening and interpersonal communication skills.
  • Ability to organize, prioritize, multi-task, and manage time effectively.
  • Ability to maintain accuracy and productivity in a changing environment with constant interruptions.
  • Ability to analyze information, problems, and procedures to develop effective solutions.
  • Strict confidentiality in all matters.

Mobility and physical requirements

  • Primarily sedentary; able to sit for long periods of time.
  • Ability to see, speak, and hear other personnel and/or objects.
  • Ability to communicate verbally and in writing.
  • Ability to travel within and around the facility or within the WFH environment.
  • Capable of using a telephone, computer keyboard, and mouse.
  • Ability to lift up to 10 lbs.

Location: Remote (remote). Compensation: USD 89,300 - 120,000 per year. Experience: 5 years minimum.

Similar Jobs