Application Security Engineer

Charlotte, North Carolina, United States

Allspring Global Investments

Now is the era of investing. At Allspring, we believe that return on investment expands beyond financial gains. We invite you to explore our capabilities.

View all jobs at Allspring Global Investments

Apply now Apply later

Elevate Your Career

Work where your ideas have impact

COMPANY

Allspring Global Investments™ is a leading independent asset management firm that offers a broad range of investment products and solutions designed to help meet clients' goals. At Allspring, our vision is to inspire a new era of investing that pursues both financial returns and positive outcomes. With decades of trusted experience propelling us forward, we strive to build portfolios aimed at generating successful outcomes for our clients. We do this through the independence of thought that powers our investment strategies and by bringing a renewed approach to look around the corner to unlock what's possible.  Allspring is a company committed to thoughtful investing, purposeful planning, and the desire to deliver outcomes that expand above and beyond financial gains. For more information, please visit  About Us - Allspring Global Investments.

At Allspring, unique views inspire us. We leverage the diversity of people, ideas, and skills to help our clients pursue their financial goals. We strive to attract and retain a diverse talent pool that enables us to better serve our global client base. Intentionally fostering a diverse and inclusive culture allows us to empower innovation, productivity, and engagement. It’s also essential for elevating the experience of our clients as well as the communities in which we operate. Thank you for considering Allspring as you explore the next step in your career journey.

POSITION

Allspring Global Investments is seeking an experienced Application Security Engineer to join our exceptional Engineering and Technology (AllspringET) Information Security team. In this role, you will have the unique opportunity to contribute to the security practices within Allspring's software development lifecycle.

RESPONSIBILITIES

  • Act as an expert and builder for cloud-based technologies, prioritizing security, performance, operability, and scalability.
  • Support the implementation of advanced front-end technologies within technology and business groups as an in-house specialist.
  • Foster strong relationships with developers, technology teams, solution teams, and business application owners.
  • Develop and implement effective security measures by following established industry standards.
  • Develop and implement innovative cloud technologies to differentiate our offerings.
  • Collaborate and consult with technical experts, technology teams, and external industry groups to address complex technical issues and achieve our goals.

REQUIRED QUALIFICATIONS

  • Bachelor's degree or higher in MIS, CS, or another technology-related field OR equivalent combination of education and work experience.
  • 5+ years of engineering and technology experience, preferably in Financial Services, Technology, or a related field.
  • 2+ years of experience in static code analysis using SonarQube and Jfrog Xray or other industry-standard scanning tools.
  • 2+ years of experience working within a DevSecOps framework, including expertise in version control, continuous integration, continuous testing, configuration management, and secure containerization.
  • 2+ years of experience with applications running in AWS, including knowledge of AWS Security in areas such as IAM and KMS.
  • 2+ years of experience conducting security assessments of Cloud-based applications and ensuring compliance with relevant standards and frameworks.
  • 2+ years of experience with AWS or other hyperscale cloud provider implementation.
  • Demonstrated expertise in strengthening applications by implementing effective strategies in areas such as Identity and Access Management, Data Security, Container Security, and Secrets Management.
  • Knowledge of secure containerization, with experience using industry-standard containerization platforms such as AWS ECS and Kubernetes.
  • Understanding of common application attack vectors within industry-standard frameworks like OWASP and MITRE ATT&CK.

PREFERRED QUALIFICATIONS

  • Familiarity with Jenkins or another industry-standard software build automation platform.
  • Proficiency in C-based programming languages (C#/C++) as well as web development languages such as JavaScript and Node.js.
  • Ability to multitask in a fast-paced environment and prioritize duties to meet deadlines with limited supervision.
  • Excellent verbal and written communication skills.
  • Strong influencing and consensus-building skills.
  • Proven track record of approaching challenges with a strategic problem-solving approach.
  • Effective teaching and mentoring abilities.
  • Impressive presentation and communication capabilities.
  • Willingness to occasionally travel outside of the primary work location.
  • Demonstrated success working effectively in a heavily distributed environment.
  • Consulting experience is a plus.
  • Track record of maintaining strong documentation.
  • Capability to share knowledge with essential team members and serve as a valuable resource.
  • Demonstrated ability to deliver on-call support and resolve challenges autonomously.
  • Confidence in interacting with counterparts at all levels within the organization.
  • Proficient in identifying and finding solutions to complex problems.
  • Demonstrated ability to collaborate with teams across multiple locations.

 

#LI-CD1

#LI-Hybrid

 

 

We are an Equal Opportunity/Affirmative Action Employer. We consider all qualified applicants for employment regardless of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other protected status.

 

Apply now Apply later
  • Share this job via
  • 𝕏
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  3  2  0

Tags: Application security Automation AWS C Cloud Code analysis Compliance DevSecOps IAM JavaScript Jenkins Kubernetes MITRE ATT&CK Node.js OWASP SDLC Security assessment SonarQube Teaching

Perks/benefits: Career development

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.