About the job
Job Summary:
The Application Security Engineer will play a pivotal role in enhancing our Secure Development Lifecycle assurance processes and security automation technologies. This individual will spearhead the security hardening strategy across our product offerings while responding to both current and emerging security threats. This position is integral to our Product Security team, collaborating with development teams worldwide to define innovative security capabilities and partnering with organizational leaders to implement comprehensive security initiatives.
Job Expectations:
Lead cross-functional projects to establish advanced security development lifecycle practices.
Conduct security design reviews and threat modeling for both new and existing services at iHerb.
Assess, prototype, implement, and manage security-focused tools and services.
Create new secure architecture standards, frameworks, and patterns that span multiple layers.
Analyze emerging security threats relevant to iHerb and proactively develop centralized mitigations.
Evaluate, prototype, implement, and operate security tools and services (DAST, SAST, SCA, etc.).
Maintain an up-to-date understanding of current security threats and operational best practices.
Participate in our security assessment, penetration testing, and bug bounty programs.
Engage in security incident response activities.
The responsibilities listed above are intended to provide a general overview of the role and are not exhaustive. Additional duties may be assigned as necessary.

