onsite
Senior Application Security Analyst - Cencora
Security Engineer
Lead application security for enterprise middleware and Java/Spring stacks, ensuring robust threat modeling, secure coding, and compliance across Linux and Windows environments.
About the role
Key Responsibilities
- Design, implement, and maintain security architecture for IBM MQ, WebSphere, and Java/Spring applications.
- Conduct threat modeling, risk assessments, and secure code reviews to identify and remediate vulnerabilities.
- Collaborate with development and operations teams to embed security controls into CI/CD pipelines.
- Perform penetration testing and vulnerability scanning on Linux (SUSE, RHEL, CentOS, Ubuntu) and Windows platforms.
- Develop and deliver security training and best‑practice guidelines to cross‑functional teams.
Requirements
- 5+ years of experience in application security, with deep knowledge of middleware and Java/Spring ecosystems.
- Proficiency in Linux and Windows operating systems, including security hardening and patch management.
- Hands‑on experience with IBM MQ, WebSphere, and secure coding practices (OWASP Top 10).
- Strong analytical skills, ability to translate complex security concepts into actionable plans.
- Excellent communication skills and a collaborative mindset.
Skills
linuxjavaspringowasp