C

Senior IT Application Security Engineer

CBTS • United State
Remote
Apply
AI Summary

Lead application security initiatives as a subject matter expert, driving secure software design, threat modeling, and secure coding practices across the SDLC. Mentor teams, advise leadership, and foster a culture of security through training, risk analysis, and process improvement. Champion incident response and third-party security assessments while developing internal security tooling.

Key Highlights
Subject matter expert in secure application design, threat modeling, and secure coding practices
Proactive leadership in defining and enforcing application security standards across the organization
Mentorship and training for IT stakeholders, with a focus on continuous improvement and risk-based decision-making
Key Responsibilities
Develop and deliver presentations on application security topics to technical and non-technical stakeholders
Advise executive leadership on evolving threats and risk-informed decision-making
Mentor the information security team on application security best practices and methodologies
Facilitate third-party penetration tests, triage findings, and create remediation plans with development teams
Provide tailored remediation guidance to software developers addressing security findings
Review and assess the security of third-party and open-source software used by CBTS
Develop internal security tooling for identifying or remediating security risks
Assist or lead application security efforts during security incidents
Technical Skills Required
Secure Coding Practices (OWASP Top 10) Application Security (Threat Modeling, SDLC Integration) Software Development (Object-Oriented Programming, C#, Java, C++)
Benefits & Perks
Equal Employment Opportunity (EEO) compliance
Nice to Have
Agile/Scrum, SAFe, or Lean certification
SANS/GIAC, CompTIA, ISC2 (e.g., CISSP) certifications
Foundational knowledge of cloud infrastructure, containerization, and networking security practices
Experience with risk-based analysis and security governance

Job Description


100% Remote - Direct Hire/Fulltime - NO (Sponsorship, Corp-to-Corp, H1B, OPT, EAD)



CBTS is searching for a Sr. IT Application Security Engineer. The Senior IT Application Security Engineer is recognized as a subject matter expert in secure application design, threat modeling, and secure coding practices. You will assist software development teams in designing, creating, and implementing secure solutions by ensuring that security checks are followed throughout each phase of the software development life cycle (SDLC). You are expected to take a proactive leadership role in driving application security initiatives and define, communicate, and enforce application security standards across the organization. You will lead opportunities to enhance security processes and mentor team members by sharing your expertise. You will also identify security knowledge gaps and present training to IT stakeholders. Additionally, you will champion efforts to advance the maturity of the application security program to help foster a culture of continuous improvement.



Responsibilities:

  • Develop and provide presentations on application security topics to both technical and non-technical audiences.
  • Advise executive leadership on current and evolving threats to enable risk-informed decisions.
  • Mentor members of the information security team on matters of application security.
  • Facilitate third-party penetration tests, triage findings, and create remediation plans with development teams.
  • Provide tailored remediation guidance to software developers to address security findings.
  • Provide architectural and security guidance for third-party platforms and services as they integrate into our environments and/or code.
  • Review the security of third-party/open-source software used by CBTS.
  • Provide risk-based analysis of security posture to drive business decisions.
  • Foster relationships with key business partners to create a culture of security and achieve prioritization of security initiatives.
  • Develop internal security tooling for identifying or remediating security risks.
  • Assist/lead on matters of application security in the event of an incident.
  • This job profile is not meant to be all inclusive of the responsibilities of this position. May perform other duties as assigned or required.



Requirements:

  • Bachelor's degree or above in Computer Science, Information Security, or related field.
  • At least four years of professional experience, with at least two years in a security field and at least one year with direct experience writing code.
  • Familiar with object-oriented programming and have written code in one or more programming languages (e.g. C#, Java, C++).
  • Agile/Scrum, SAFe, or Lean certification preferred.
  • Familiarity with secure coding best practices such as the OWASP Top 10.
  • Knowledge of common application architectures and the relative risks associated with them (e.g. single page apps, client-server, native mobile, microservices).
  • Foundational knowledge of security practices in several applied contexts, e.g. networking, cloud infrastructure, containerization, operations, audit, or governance.
  • Knowledge of relevant technology, tools, databases, and development techniques.
  • Strong focus on team dynamics and interpersonal relationships.
  • Strong sense of task ownership with consistent follow-through.
  • Ability to anticipate risks and devise solutions with limited information or context.
  • Excellent project management, organization, and team collaboration skills.
  • Curiosity to learn.
  • Capable of defining and measuring key performance indicators.
  • Able to work cross-functionally with IT and business partners across all areas of CBTS and vendor partners.
  • Adaptive, flexible, and responsive to challenges.
  • Awareness of how security controls influence both internal stakeholders and CBTS customers.
  • SANS/GIAC, CompTIA, ISC2 (e.g. CISSP) or other applicable industry certifications preferred.



CBTS provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a protected veteran in accordance with applicable federal, state and local laws.



Similar Jobs

Explore other opportunities that match your interests

Cyber Security Architect

Cyber Security
•
10m ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Tradeweb

United State

Cybersecurity Program Analyst

Cyber Security
•
11h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

TEKsystems

United State

Security Analyst

Cyber Security
•
12h ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Entry level

hiredbuddy

United State

Subscribe our newsletter

New Things Will Always Update Regularly