Senior Application Security Engineer
JumioIndia3d ago
SecurityEngineeringremotecurated-jd
Job description
Senior Application Security Engineer at Jumio.
About the role
This position involves building secure cloud infrastructure and delivering security engineering services to internal development teams. You will help protect the organization against cyber threats by integrating security practices throughout the software development lifecycle.
Key facts
What you'll do
- Partner with infrastructure and engineering groups to address security gaps in cloud environments and development processes.
- Embed security protocols from initial threat modeling through to system decommissioning.
- Conduct manual penetration testing for APIs and web applications.
- Perform source code audits and reviews for significant application updates.
- Advise engineering teams on vulnerability remediation and risk prioritization.
- Manage security risk mitigation efforts across internal and external teams.
- Implement security services using infrastructure as code and promote security as code practices.
- Execute periodic configuration reviews and security assessments of cloud environments.
- Develop custom security automation tools and lead various security initiatives.
- Scale DevSecOps practices and integrate security tooling into existing workflows.
Requirements
- 10+ years of experience in security engineering with a focus on cloud and application security.
- Proficiency in Linux and cloud ecosystems like AWS and GCP, including networking and security patterns.
- Knowledge of AWS services such as EC2, ECS, Lambda, and RDS, and the Well-Architected Framework.
- Experience with containerized deployments using Docker and Kubernetes.
- Background in implementing secure infrastructure as code.
- Hands-on experience with web application and API penetration testing.
- Deep understanding of CWE 25 and OWASP Top 10.
- Experience using SAST, DAST, IAST, and SCA tools.
- Experience with threat modeling.
- Strong communication skills and the ability to present risks to technical teams.
Nice to have
- Experience with mobile application penetration testing.
- Proficiency in Python or other scripting languages.
- Experience applying AI and LLMs to automate security workflows.
- Knowledge of CI/CD tools like Jenkins, GitHub Actions, or AWS DevOps.
- Bachelor or Master degree in Computer Science.
- Relevant certifications such as OSCP, CREST, OSWE, CEPT, CMWAPT, GPEN, PentTest+, or AWS Security/Associate level certifications.
Skills & tools
- Linux, AWS, GCP, Docker, Kubernetes, Python, SAST, DAST, IAST, SCA, CI/CD tools.
Practical notes
- Jumio operates under the values of Integrity, Diversity, Empowerment, Accountability, and Leading Innovation.
- The company is an equal opportunity employer.
- Personal information provided during the application process is handled according to the Jumio Applicant Privacy Notice. Questions regarding data privacy can be directed to privacy@jumio.com.