Staff Application Security Engineer

1 month ago
Full-time
Lead
Cybersecurity
Ivanti

Ivanti

Ivanti provides automated solutions that discover, repair, and secure devices across various locations, enabling employees to work efficiently and securely from anywhere.

Internet Software & Services
1K-5K
Founded 1985
$26M raised

Description

  • Manage the integration of security best practices across all phases of the software development lifecycle.
  • Build scalable security tools, processes, and solutions to detect, remediate, and mitigate vulnerabilities in large codebases.
  • Design secure architectures and perform threat modeling for web and mobile applications.
  • Lead penetration testing and code reviews to identify and address security issues.
  • Partner with development, operations, and architecture teams to embed security into DevOps practices.
  • Lead security education efforts by creating training and documentation for cross-functional teams.
  • Drive vulnerability remediation efforts with stakeholders across technical and non-technical groups.
  • Collaborate with product, engineering, business, and third-party security vendors on vulnerability reports and disclosure programs.
  • Advise stakeholders on prioritizing vulnerabilities, secure coding standards, cryptographic techniques, and security/compliance practices.

Requirements

  • 8+ years of experience in web application security.
  • Deep technical knowledge of common and advanced security vulnerabilities, exploitation techniques, and remediation strategies.
  • Proven expertise in applied cryptography, threat modeling, vulnerability assessment, CVSS scoring, and penetration testing.
  • Experience with secure software development practices across SSDLC and CI/CD pipelines.
  • Experience implementing and maintaining security tools and processes such as SAST, SCA, DAST, and container scanning for large-scale codebases.
  • Experience providing secure coding education to developers.
  • Strong programming skills, preferably in Python.
  • Ability to explain complex security topics to both technical and non-technical stakeholders.
  • Demonstrated ability to work cross-functionally in collaborative environments.
  • Experience contributing to responsible disclosure, bug bounty, and vulnerability management programs, and securing cloud and SaaS environments at scale.

Benefits

  • Remote-friendly work with flexible schedules.
  • Competitive compensation and total rewards.
  • Health, wellness, and financial plans for employees and their families.
  • Access to best-in-class learning tools and development programs.
  • Opportunity to work with global, diverse teams across 23+ countries.
  • Inclusive culture with a strong focus on equity and belonging.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Application Security Engineer

CookUnity 251-1K Hotels, Restaurants & Leisure

CookUnity is hiring a founding Application Security team member to help secure its engineering organization’s applications and build security into the software lifecycle.

Agile AWS Azure Burp Suite CI/CD DevSecOps Docker GCP Java Kotlin Kubernetes OAuth OpenID Connect OWASP Penetration Testing SAML TypeScript
12 hours, 11 minutes ago

Senior Application Security Engineer

Onit 251-1K IT Services

Onit is hiring a Senior Application Security Engineer in Pune to secure its SaaS applications, APIs, and AI-driven platform through hands-on security architecture, risk assessment, and vulnerability management.

AWS Azure CI/CD DevSecOps GCP GraphQL OAuth OpenID Connect REST API SAML SonarQube System Design
21 hours, 40 minutes ago

Product Security Intern

Funding Societies 251-1K Capital Markets

Funding Societies | Modalku is seeking a Product Security Intern to help strengthen secure software development and security automation across its engineering environment using Generative AI and modern security tooling.

Bash CI/CD Cybersecurity Encryption Generative AI Git Go JavaScript LLM Penetration Testing Python
1 day, 13 hours ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into its open-source software supply chain, cloud-native products, and CI/CD systems for production environments.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
1 day, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers