Application Security Engineer, Secure Product Development
CA Canada (ResMed Halifax - Remote)
ResMed
Die vernetzten Lösungen von ResMed verbessern das Leben von Millionen von Menschen mit Schlafapnoe und anderen Atemwegserkrankungen - entdecken Sie, was unsere Lösungen für Sie tun können.The Information Technology (IT) team plays a key role in providing business enablement throughout ResMed. We are focused on application, infrastructure, and user productivity solutions, with innovation, efficiency and security. Our goal is providing customer oriented agile delivery, effective business partnership and state-of-the-art technology solutions.
In your role as an Application Security Engineer, you are responsible to enable developers to build secure applications. Under limited direction of your management, you will operate with an agile mentality – delivering solutions quickly and improving upon design and implementation of existing solutions. You will collaborate with cloud security, security operations and other teams to ensure secure application development across the enterprise.
This role will be a global role and is part of the Enterprise Security group, which is globally deployed.
Let’s talk about Responsibilities
A key role of the Application Security Engineer is to enable development teams to develop secure applications.
Specific tasks include (but are not limited to):
- Operation and support of code scanning tools, e.g., CheckMarx, Invicti, and Wiz.
- Supporting development teams to triage findings and enable self service.
- Ensuring code scanning tools integrate seamlessly into the current software development lifecycle with minimal friction e.g. Gitbhub actions as a part of existing shared CICD workflows.
- Oversee the design, implementation, and management of the infrastructure and tooling necessary to support all security aspects of continuous integration, continuous delivery, and continuous deployment (CI/CD) pipelines.
- Collaborate with key stakeholders to identify opportunities for automation, process improvement, and tool optimization.
- Research and implement new technologies to improve and grow secure development (e.g. applications, systems, outsources services).
- Maintain operational guidelines, diagrams, and documentation for secure development.
- Work closely with the developer experience team to integrate security automation into the development process.
Let’s talk about Qualifications and Experience
Required:
- Expertise in Securing Software Development Lifecycles.
- Expertise in one or more high-level programming languages, e.g., Java, C#, Python, etc.
- Expertise in application-level attacks and defences, e.g., OWASP Top 10, SANS Top 25, etc.
- Experience with AppSec tooling such as SAST, DAST, IAST, RASP, etc.
- Experience working with DevOps, Agile, Scrum, Kanban methodologies.
Preferred:
- Bachelor’s degree in computer science or a related field.
- Minimum of 2 years of experience in application security, software development, or related field.
- Security related certification(s) such as CSSLP.
- Experience with Infrastructure as Code and the use of Application Release Automation tools.
- Experience as an AWS Dev/Sec/Ops Engineer developing continuous Integration and Continuous Delivery pipelines (CI/CD).
- Experience working in a regulated secured environment and understanding the security requirements (NIST, ISO, etc.).
- Experience working with production incident management tools and processes to resolve Enterprise level issues.
- Experience with AWS cloud services such as WAF, EC2, S3, Lambda, VPC, CloudWatch, CloudTrail, EKS, ECS, KMS, IAM, RDS.
Joining us is more than saying “yes” to making the world a healthier place. It’s discovering a career that’s challenging, supportive and inspiring. Where a culture driven by excellence helps you not only meet your goals, but also create new ones. We focus on creating a diverse and inclusive culture, encouraging individual expression in the workplace and thrive on the innovative ideas this generates. If this sounds like the workplace for you, apply now! We commit to respond to every applicant.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Application security Automation AWS C Checkmarx CI/CD Cloud Computer Science CSSLP DAST DevOps EC2 IAM IAST Java Kanban Lambda NIST OWASP Python S3 SANS SAST Scrum SDLC
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.