Hi Vendors
My
Client is looking for a consultant for Application Security Engineer
position for a Long Term Contract
position in Boston, MA
Position - Application Security Engineer
Location - Boston, MA
Type – Contract
Job Summary
We are seeking an
experienced Application Security Engineer to join the Cyber Security
Architecture & Engineering team. The ideal candidate will be responsible
for strengthening application security capabilities across the software
development lifecycle (SDLC), driving secure development practices, and supporting
the rollout and adoption of application security tools and processes.
The successful
candidate will work closely with development, DevOps, cloud, and security teams
to identify, assess, and remediate application security risks while enabling
secure software delivery across enterprise platforms.
Key Responsibilities
- Implement and promote application security
best practices throughout the Secure Software Development Lifecycle
(SSDLC).
- Conduct threat modeling exercises and secure
design reviews for new and existing applications.
- Perform secure code reviews and identify
security weaknesses in application code.
- Analyze security vulnerabilities for
exploitability, reachability, and business impact.
- Support onboarding, configuration, and rollout
of Application Security (AppSec) tools across development teams.
- Integrate security controls and testing
capabilities into CI/CD pipelines.
- Partner with development teams to remediate
vulnerabilities and improve security posture.
- Provide guidance and training on secure coding
practices and security standards.
- Perform security assessments of applications
deployed in cloud environments.
- Develop security metrics, reports, dashboards,
and executive-level presentations.
- Collaborate with security architecture,
engineering, and compliance teams to ensure adherence to organizational
security policies.
- Assist in defining and improving application
security processes, standards, and governance.
Required Qualifications
- 8–12 years of experience in Application
Security, Cyber Security, Software Development, or a related field.
- Strong understanding of application security
principles, secure design methodologies, and security architecture.
- Hands-on experience performing:
- Threat
Modeling
- Secure
Design Reviews
- Secure
Code Reviews
- Vulnerability
Risk Assessment
- Experience implementing and managing Secure
SDLC programs.
- Strong knowledge of common application
vulnerabilities including:
- OWASP
Top 10
- CWE
- API
Security Risks
- Experience with modern programming languages
and frameworks such as:
- Java
- .NET/C#
- Python
- Node.js
- Hands-on experience with AppSec tools
including:
- SAST
(Static Application Security Testing)
- DAST
(Dynamic Application Security Testing)
- SCA
(Software Composition Analysis)
- Experience integrating security testing into
CI/CD pipelines.
- Strong communication and stakeholder
management skills.
- Ability to work effectively with development,
DevOps, and business teams.
Best Regards
Rohit Kumar (Sr.Technical Recruiter)
Intellisoft Technologies Inc.
11494 Luna Road, Ste 280 Farmers Branch, TX -75234
roh...@intellisofttech.com| www.intellisofttech.com
www.linkedin.com/in/rohit-pal-965a1a190