Application Security Engineer
Iselin, New Jersey, United States; New York, New York, United States
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Full Time Mid-level / Intermediate USD 140K - 170K
CLS Group
CLS's innovative settlement, processing and data solutions reduce risk and deliver efficiency.About CLS:
CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.
Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.
CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.
Our ambition to make a positive difference starts with our people. Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking.
Job information:
- Functional title – Application Security Specialist
- Department – IT Security
- Corporate level – Vice President
- Report to – Director, Application Security
- Location – New Jersey / New York.
- Expected full-time salary range between $ 140,000- $170,000 + variable compensation + 401(k) match + benefits.
What you will be doing:
- Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknesses,
- Triage security findings and collaborate with development teams to prioritize and remediate identified vulnerabilities.
- Drive threat modelling as a standard part of the SDLC, and develop and maintain threat models for critical applications, identifying potential security risks and proposing mitigations.
- Drive the Security Champions program, and define and promote secure coding practices, patterns, and standards across development teams.
- Conduct security reviews and provide guidance on security requirements for new features and projects.
- Assist in the analysis, selection and rollout of new application security tools, processes, and standards.
- Stay up to date with the latest security threats, vulnerabilities, and industry best practices.
What we’re looking for:
- Proven experience in application security with a focus on application security testing and vulnerability management.
- Hands-on experience with Application Security tools.
- Strong understanding of common application vulnerabilities (e.g., OWASP Top 10) and mitigation techniques.
- Experience with threat modelling methodologies and tools.
- Proficiency in at least one programming language (e.g., Java, Python, JavaScript).
- Excellent communication and collaboration skills, with the ability to work effectively in cross functional teams.
- Strong understanding of risk management.
Professional qualifications / certifications
- Degree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
- Relevant security certifications (e.g. CISSP, CEH, CSSLP) or equivalent is preferred.
Our commitment to employees:
At CLS, we celebrate diversity and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:
- Holiday - UK/Asia: 25 holiday days and 3 ‘life days’ (in addition to bank holidays). US: 23 holiday days.
- 2 paid volunteer days so that you can actively support causes within your community that are important to you.
- Generous parental leave policies to ensure you can enjoy valuable time with your family.
- Parental transition coaching programmes and support services.
- Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
- Affinity Groups (including our Women’s Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about DE&I.
- Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don’t.
- Active support of flexible working for all employees where possible.
- Monthly ‘Heads Down Days’ with no meetings across the whole company.
- Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
- Private medical insurance and dental coverage.
- Social events that give you opportunities to meet new people and broaden your network across the organisation.
- Annual flu vaccinations.
- Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
- Discounted Gym membership – Complete Body Gym Discount/Sweat equity program for US employees.
- All employees have access to Discover – our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
- Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.
Tags: APIs Application security CEH CISSP Computer Science CSSLP DAST Java JavaScript OWASP Python Risk management SDLC Vulnerabilities Vulnerability management
Perks/benefits: 401(k) matching Career development Equity / stock options Fitness / gym Flex hours Health care Medical leave Parental leave Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.