About the job
Join our dynamic Information Security Team at Devexperts as an Application Security Engineer. In this pivotal role, you will collaborate with software development teams, product owners, and other stakeholders to establish, implement, and uphold rigorous security practices throughout the software development lifecycle (SDLC).
Your primary responsibilities will include identifying and mitigating security vulnerabilities across applications, systems, and APIs. You will ensure that secure coding practices are followed and assist in maintaining compliance with key security standards such as OWASP Top 10, NIST, and ISO/IEC 27001.
This position is critical in enhancing our organization's security posture, advocating for security best practices, and safeguarding the integrity of our software applications.
Key Responsibilities:
- Conduct regular security assessments of applications, including code reviews, static/dynamic analysis, and penetration testing.
- Collaborate with development teams to design and integrate security controls into the SDLC.
- Lead efforts to identify and remediate security vulnerabilities in applications, APIs, and third-party services.
- Provide technical guidance on secure coding practices, threat modeling, and vulnerability management.
- Enforce security best practices for secure coding, API security, and encryption across application architectures.
- Stay updated on the latest security threats, vulnerabilities, and trends to proactively mitigate risks.
- Develop and maintain automated security testing tools and processes for continuous security integration within CI/CD pipelines.
- Support risk assessments and threat modeling for new and existing applications, prioritizing remediation efforts.
- Participate in incident response activities related to application security, bringing expertise to investigate and resolve security breaches.
- Create and deliver security training to developers, fostering a culture of security awareness within teams.
- Assist in tracking and verifying the resolution of identified vulnerabilities.
- Ensure compliance with internal security standards and external regulatory requirements (e.g., GDPR, PCI-DSS, HIPAA).
- Work collaboratively with cross-functional teams, including DevOps and security operations, to ensure a unified approach to application security.

