Application Security Engineer
Job description
About the role
The Security team at AppsFlyer is on the lookout for a skilled Application Security Engineer to lead initiatives focused on product and application security. In this role, you will be instrumental in promoting secure design principles, mentoring engineering teams, and ensuring that all services adhere to stringent security standards. Your expertise will help shape the security landscape of our products and enhance the overall security posture of the organization.
Key facts
What you'll do
- Work closely with product and development teams to integrate security measures throughout the software development lifecycle, ensuring that security is a fundamental aspect of product design and implementation.
- Conduct thorough architecture security assessments and threat modeling exercises to identify potential vulnerabilities and mitigate risks before they manifest.
- Execute vulnerability assessments, code reviews, penetration tests, and evaluations of secure design practices to ensure robust application security.
- Stay informed about industry trends and emerging threats to proactively adapt and enhance our security strategies.
- Participate in incident response efforts, including conducting root cause analyses and implementing corrective actions to prevent future occurrences.
- Develop automation solutions for security-related tasks and seamlessly integrate security tools into continuous integration and continuous deployment (CI/CD) pipelines.
- Deliver training sessions on secure coding practices to engineering teams, fostering a culture of security awareness and best practices across the organization.
- Collaborate with cross-functional teams to ensure compliance with security policies and standards, and to promote a security-first mindset throughout the company.
- Provide insights and recommendations to enhance security protocols and practices based on your findings and industry best practices.
- Assist in the development of security documentation and guidelines to support ongoing security efforts and compliance requirements.
Requirements
- A minimum of 3 years of hands-on experience in Product Security, Penetration Testing, or Application Security, particularly within a Software as a Service (SaaS) environment.
- A Bachelor's degree in Information Security, Computer Science, or a related field is essential.
- In-depth understanding of web application security principles, with a focus on the OWASP Top 10, encryption methodologies, authentication mechanisms, and secure coding practices.
- Proficiency in scripting or programming languages such as Python, JavaScript, or Go, particularly for automation tasks.
- Familiarity with cloud security frameworks and standards, specifically for platforms like AWS, GCP, or Azure.
- Practical experience in implementing DevSecOps practices and integrating security into CI/CD pipelines.
- Strong communication skills to effectively convey complex security risks and concepts to both technical teams and executive leadership.
- Experience working in large-scale, complex research and development environments, demonstrating the ability to navigate and address security challenges in such settings.
Nice to have
- A referral from a current employee at AppsFlyer, which can enhance your application.
- Previous experience in a startup environment, showcasing adaptability and a proactive approach to security challenges.
- Knowledge of regulatory compliance standards such as GDPR, HIPAA, or PCI-DSS, which can be beneficial for our security initiatives.
Skills & tools
- Proficient in Python, JavaScript, and Go for scripting and automation.
- Familiar with cloud platforms including AWS, GCP, and Azure for security implementations.
- Experienced in CI/CD processes and tools to ensure security is integrated into development workflows.
- Knowledgeable about OWASP Top 10 and other security frameworks to guide secure application development.
Practical notes
AppsFlyer operates a diverse workforce across 25 offices in 19 countries, emphasizing a commitment to equal opportunity employment. The company values diversity and inclusion, welcoming candidates from various backgrounds, cultures, genders, races, and sexual orientations. This role offers an opportunity to contribute to a dynamic team while advancing your career in application security within a globally recognized organization.
If you are passionate about application security and eager to make a significant impact in a fast-paced environment, we encourage you to apply for the Application Security Engineer position at AppsFlyer.