Ascensus is hiring an Application Security Engineer to strengthen its application security program and support secure delivery across the software development lifecycle. In this onsite role in Dresher, PA, you will act as a trusted advisor to scrum teams, helping build security into development practices through DevSecOps and ongoing security analysis.
What you’ll do
- Protect and ensure proper handling of all confidential data to prevent unauthorized access, improper transmission, and unapproved disclosure.
- Bring Ascensus service philosophy and Core Values (People Matter, Quality First, and Integrity Always®) into day-to-day execution.
- Partner with security and development leadership to develop a comprehensive, agile, and innovative DevSecOps approach across all phases of the SDLC, identifying and managing risk.
- Provide security consultation to scrum teams, application owners, and technology teams on relevant security controls and secure SDLC process.
- Participate in sprint planning and decision-making sessions to ensure security requirements and considerations are incorporated into development practices.
- Perform application security analysis, including architecture review, data flow analysis, support for penetration testing, and threat modeling.
- Build and monitor compliance with application security policies, coding standards, and security controls to mitigate threats.
- Own deployment and integration of services that support SAST, DAST, and SCA. Support development teams with static and dynamic testing, triage findings, and provide remediation guidance when needed.
- Assist with other tasks and projects as assigned.
What you bring
- Minimum 7 years of experience in Secure Software Development and/or DevSecOps (preferred).
- Ability to define software security and privacy requirements.
- Solid understanding of threat modeling, risk, and mitigation from internal and external threats.
- Experience developing system security architecture diagrams and security architecture specifications aligned to security architecture standards.
- Experience conducting software security design reviews.
- Experience running software security testing tools in a CI/CD pipeline, including Static and Dynamic Application Security Testing and SCA.
- Hands-on experience with application testing tools such as Burp Suite, Fiddler, ZAP, Wireshark, and Metasploit.
- Experience configuring WAF, API Gateway, and API security tools.
- Knowledge of common application and API security risks, including OWASP Top 10 and SANS/CWE Top 25.
- Solid understanding of application, database, and network vulnerability testing principles.
- Working knowledge of Microsoft SDL, OWASP SAMM, or BSIMM.
- Experience assessing secure adoption of third-party components, including open source and commercial software.
- .NET/Java experience is a plus.
- Understanding of information security frameworks such as ISO27001, NIST, and CSA, and working in regulated environments against FFIEC, SEC, and/or HIPAA requirements.
- Strong understanding of authentication and authorization systems and cryptographic standards (encryption, hashing, key management, digital signatures, etc.).
- Ability to provide vulnerability remediation guidance and mentor product development software engineers.
- Ability to translate security risks into business impact.
- Experience running or managing vulnerability assessments using automated tools (for example Nessus, Qualys) and managing penetration testing engagements.
- Understanding of privacy regulations related to handling and protecting information.
- Experience with fraud detection and analysis as it relates to custom developed applications.
- Experience integrating automated testing tools into CI/CD pipelines.
- Experience implementing cloud security controls using CSA or cloud provider best practices (such as Azure and AWS).
- Experience implementing and supporting security automation tools, including K8 and cloud platform configuration, hardening, and monitoring.
Relevant tools and technologies
SAST, DAST, SCA, Burp Suite, Fiddler, ZAP, Wireshark, Metasploit, WAF, API Gateway, Nessus, Qualys, .NET, Java, ISO27001, NIST, CSA, FFIEC, SEC, HIPAA, OWASP Top 10, SANS/CWE Top 25, Microsoft SDL, OWASP SAMM, BSIMM, CI/CD, DevSecOps, SDLC, K8, Azure, AWS.