remote
Application Security Engineer - Veilant
Security Engineer
Join a fast‑moving team as an Application Security Engineer, designing and implementing security controls, threat models, and automated testing pipelines for cloud‑native applications using Python and modern DevSecOps tools.
About the role
Key Responsibilities
- Design and implement security architectures for web and API services, ensuring compliance with industry standards.
- Develop and maintain threat models, security requirements, and mitigation strategies throughout the software development lifecycle.
- Integrate and manage SAST and DAST tools in CI/CD pipelines to provide continuous security feedback.
- Collaborate with development, operations, and product teams to embed security best practices and remediate findings.
- Perform security code reviews, vulnerability assessments, and penetration testing of cloud‑based applications.
Requirements
- 3+ years of hands‑on experience in application security, preferably in cloud environments (AWS or Azure).
- Proficiency with security testing tools (e.g., SonarQube, Burp Suite, OWASP ZAP) and scripting languages such as Python.
- Strong understanding of secure software development practices, threat modeling frameworks, and DevSecOps integration.
- Experience conducting security code reviews and managing vulnerability remediation workflows.
- Excellent analytical and communication skills, with the ability to translate complex security concepts for cross‑functional teams.