Lead Application Security Engineer
Api Security
Application Security
Application Security Engineering
Application Security Testing
Automated Security Testing
Cybersecurity Tools
DevSecOps
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
Secrets Scanning
Security
Security Automation
Security Engineer
Security Testing
Software Security
Job Description
Hands-on Lead Application Security Engineer role focused on strengthening DevSecOps and software assurance for a financial services organization in Pasadena.
Responsibilities
- Harden development pipelines and evaluate the trustworthiness of internally developed and third-party applications
- Coordinate penetration testing engagements and translate findings into actionable software risk decisions
- Assess API security and incorporate threat intelligence to inform application security posture
Requirements
- Proven application security or DevSecOps experience, including secure SDLC, threat modeling, and vulnerability remediation expertise
- Hands-on experience with GitHub Advanced Security, including:
- Secret scanning
- Push protection
- Security automation within CI/CD pipelines
- Practical experience with SAST, DAST, and code review using tools such as:
- CodeQL
- Dependabot
- OWASP ZAP
- Experience evaluating third-party software, dependencies, or compiled binaries, including knowledge of software supply chain security
Key Technologies
- GitHub Advanced Security
- Secret scanning
- Push protection
- CI/CD pipelines
- SAST and DAST
- CodeQL
- Dependabot
- OWASP ZAP
- Threat intelligence
- API security
Location
- Pasadena, CA (onsite)
Compensation
- $120,000–$180,000 base per year
Work Authorization
- US work authorization is required
- Visa sponsorship is unavailable
Job Reference: 6145
Focus Areas
- Influence how software is developed, assessed, and approved for enterprise use in partnership with engineering teams
- Combine pipeline security, deeper application analysis, and continuous validation of application trust