Staff Application Security Engineer

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Staff Application Security Engineer securing Engine’s AI-native intelligent travel platform. Owning SIEM, vulnerability management, application security reviews, and incident response.

Responsibilities:

  • Own the configuration, tuning, and management of the SIEM solution
  • Diagnose unusual threats through sophisticated analysis and develop security alerts across multiple layers
  • Perform architecture, code, and infrastructure configuration reviews
  • Conduct light penetration testing on web and mobile applications
  • Identify root causes of vulnerabilities and resolve them
  • Maintain and optimize a vulnerability management CI/CD pipeline within container and application delivery infrastructure
  • Partner with development and infrastructure teams to enforce secure coding practices and remediation strategies
  • Build and maintain enterprise security frameworks and tooling
  • Contribute to incident response and forensic investigations
  • Stay current on emerging threats and provide guidance to development teams
  • Help develop security training and improve the organization’s security posture

Requirements:

  • Highly skilled in one or more programming languages, such as Ruby, Java, Python, C#, or Node.js
  • Expertise managing SIEM solutions and developing efficient alerting
  • Strong knowledge of Docker and Kubernetes
  • Hands-on experience in automated container vulnerability management
  • Mastery of SAST, DAST, and IAST tools
  • Ability to perform manual validation testing
  • Deep knowledge of the OWASP Top 10, Mitre Top 25, and secure coding practices
  • Ability to assess complex, ambiguous situations and identify root causes
  • Clear, direct communication skills and a track record of earning credibility with peers
  • Passion for mentoring others
  • Experience with cloud security concepts and compliance frameworks such as SOC 2 and PCI

Benefits:

  • Competitive base pay tied to role and experience
  • Equity for all employees
  • Some roles are eligible for bonuses or commissions
  • Hybrid-hub model with office-based or fully remote work environments
  • Benefits available through Engine’s full benefits program; perks and benefits may vary based on employment type and location