Senior Application Security Engineer
Job description
Senior Application Security Engineer at Matillion.
About the role
Matillion is seeking a Senior Application Security Engineer to embed security practices directly into their product development lifecycle. This role focuses on integrating security from the initial design phase, fostering a SecDevOps culture within small, cloud-focused development teams. You will contribute to Maia, Matillion's AI Data Automation platform, which helps companies like Cisco and Slack manage exploding data demands.
Key facts
What you'll do
- Design and lead a security champions program across development squads.
- Define functional and non-functional security requirements for applications.
- Incorporate abuse case stories into the product backlog and ensure security stories are prioritized.
- Identify and address security gaps in the Software Development Life Cycle (SDLC).
- Guide developers on threat modeling during application design.
- Serve as the primary security contact for development teams, offering solutions for technical software issues.
- Manage penetration testing cycles for core applications through hacking exercises.
- Review application code against frameworks like OWASP ASVS.
- Contribute to the design of security controls, including customer authentication workflows.
- Implement security tools like SAST, IAST, and DAST into the CI/CD pipeline.
- Develop and automate security tools for testing Matillion applications.
- Integrate security test failures and outputs back to development teams to ensure secure production releases.
- Create security tests for code and assist developers with building security unit tests.
- Provide responsive support to development teams and analyze logs for issue resolution.
- Conduct research and prototyping for future security opportunities.
- Investigate new security technologies and optimize infrastructure deployment through automation.
- Engage in self-development, identify training goals, and participate in technical discussions.
Requirements
- A strong drive for success in application security.
- Comprehensive understanding of the Software Development Life Cycle (SDLC).
Nice to have
- Background as a security professional with prior software engineering experience.
- Familiarity with the OWASP ASVS framework.
- Experience in Agile delivery environments.
- Experience setting up security technologies from scratch (greenfield projects).
- Ability to build relationships with key stakeholders.
- Proactive attitude towards various security issues.
- Stays current with security developments.
- Engages with the security community.
- Quick learner.
Skills & tools
- OWASP ASVS
- SAST
- IAST
- DAST
Practical notes
Matillion offers flexible working, company equity, 30 days holiday plus bank holidays, 5 days paid volunteering leave, private health insurance, life insurance, pension, and mental health support. Recruiters will only contact candidates from @matillion.com email addresses or via trusted partners who will identify themselves. Matillion will never ask for money or bank details during the hiring process.