Senior Application Security Engineer
Signify Technology
Remoto
What You'll Do
- Help build and mature the Secure Design and Threat Modeling program, defining methodology, review standards, and sign off criteria across the organization
- Drive early stage security initiatives, embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating within CI/CD
- Own API security as a core discipline
- Support offensive security initiatives across the organization
- Build and maintain security automation using Python, creating tooling that scales the Application Security team's capacity
- Partner directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
- Contribute to AI assisted security pipelines, defining escalation paths, SLAs, and accountability structures for vulnerability management
- Hands on experience across secure design, threat modeling, API security, and offensive security
- Offensive security capability including penetration testing experience and a solid understanding of real world attack and API exploitation patterns
- Deep familiarity with the OWASP Top 10 in practice
- API security depth, with experience assessing REST and GraphQL APIs
- Strong Python proficiency, comfortable building automation tools that others will depend on
- Experience running programs that embed security earlier in delivery, including CI/CD security, developer enablement, and design review processes
- Solid understanding of web application and API security
- Comfortable reading code across multiple languages and engaging with engineering teams at a technical depth
- Familiarity with cloud native environments and attack surface management
- Demonstrated ability to influence across engineering and product, operating at an architecture level
- Relevant certifications are a plus, including OSCP, OSWE, GWEB, CSSLP, CISSP, or CEH
- Exposure to AI assisted security tooling or LLM security is a strong differentiator