onsite
Security Engineer - Momentive Software
Security Engineer
Security Engineer responsible for embedding Secure SDLC practices, conducting SAST/DAST and SCA testing, and performing secure code reviews to ensure robust application security throughout the development lifecycle.
About the role
Key Responsibilities
- Support the implementation of Secure SDLC processes across multiple development teams, ensuring security requirements are integrated from design through deployment.
- Conduct static and dynamic application security testing (SAST, DAST) and coordinate open‑source dependency scanning (SCA) to identify vulnerabilities.
- Participate in security architecture and design reviews, providing guidance on threat modeling and mitigation strategies.
- Perform basic secure code reviews under senior engineer mentorship, documenting findings and recommending remediation.
- Track, validate, and follow up on vulnerability remediation efforts to ensure timely resolution.
Requirements
- Experience with Secure SDLC frameworks and application security testing tools (e.g., SAST, DAST, SCA).
- Understanding of common vulnerability types (OWASP Top 10) and remediation techniques.
- Ability to conduct secure code reviews and communicate findings to development teams.
- Familiarity with vulnerability management processes and ticketing systems.
- Strong analytical and problem‑solving skills with a collaborative mindset.
Skills
pythonjavascriptjavaawsgcpazureowasp