Bessemer Trust

Application Security Engineer

Woodbridge Township, NJ, US

13 days ago
Save Job

Summary

Description

We are looking for an Application Security Engineer to join our growing Information Security team. In this role, you’ll collaborate with development, DevOps, and security teams to help build secure software at every stage of the SDLC. Your work will directly contribute to the protection of sensitive data, systems, and client trust across our digital landscape.

Job Duties

Partner with application delivery and DevOps teams to embed security into the SDLC and perform or facilitate the following functions:

  • Conduct secure code reviews and perform SAST, DAST, and manual security assessments.
  • Perform threat modeling and risk analysis for new and existing application architectures.
  • Define, implement, and automate application security testing in CI/CD pipelines.
  • Deploy and manage tools such as Snyk, Veracode, OWASP ZAP, Burp Suite, and Checkmarx.
  • Provide actionable remediation guidance to developers and promote secure coding best practices.
  • Deliver targeted security training sessions for development and engineering teams.
  • Assist with incident response for application-related security events, including root cause analysis and follow-up improvements.
  • Monitor and ensure adherence to industry frameworks and standards (e.g., OWASP, NIST, PCI-DSS).
  • Define and maintain secure development policies and reference architectures.
  • Stay ahead of emerging threats, zero-day vulnerabilities, and innovative security solutions.
  • Research and recommend new tools and practices to strengthen our application security posture.

Qualifications

Education:

  • Bachelor’s degree in computer science, Information Security, or a related field (or equivalent experience).

Experience

  • 3-5 years of experience in application security, software development, or DevSecOps roles.
  • Hands-on experience with application security tools (e.g., Snyk, Veracode, OWASP ZAP, Burp Suite, Checkmarx)

Technical Skills

  • Strong knowledge of web and mobile app vulnerabilities (e.g., OWASP Top Ten, CWE).
  • Experience with at least one programming/scripting language (Python, Java, JavaScript, etc.).
  • Proficiency in integrating security into CI/CD pipelines and DevOps workflows.

Certifications (Preferred, Not Mandatory)

  • GIAC GWAPT, GIAC GWEB, CSSLP, CEH, or similar.

Soft Skills

  • Strong analytical and problem-solving skills.
  • Excellent verbal and written communication skills.
  • Ability to explain technical risks to non-technical stakeholders.

What We Offer

  • A collaborative, security-first culture
  • Opportunities to lead security initiatives and influence engineering practices
  • Competitive compensation and benefits
  • Ongoing professional development and certification support

How strong is your resume?

Upload your resume and get feedback from our expert to help land this job

People also searched: