Engineer, Application Security- (Open to remote)

Remote Full-time
About the position Penguin Random House is seeking an Application Security Engineer to join the IT Security team. This position will be responsible for advancing Secure Software Development Life Cycle (SDLC) practices and incorporating Application Security services and technologies to achieve a security-first design in all of Penguin Random House's applications. In addition, the individual will be expected to contribute to and help deliver services and projects across various aspects of information security. The individual will collaborate with developers and business stakeholders from relevant technical teams to evaluate the security architecture of new products and features through application security assessments. They will prioritize and provide guidance on mitigating identified weaknesses and vulnerabilities while working with development teams to define and promote security best practices. Responsibilities • Develop and refine our core infrastructure architecture to minimize the vulnerability of essential services and reduce the impact of potential security exploits. • Strategize and implement application security architectures that are in line with the company's business objectives, ensuring adherence to privacy standards and compliance requirements. • Utilize scripting languages (Python, Ruby, Bash, etc.) to build automation tools as needed. • Create and deliver presentations and documentation to educate developers and operations teams on application security best practices and secure coding techniques. • Identify and assess threats, vulnerabilities and potential exploits through architecture design reviews, threat modeling, code reviews, SCA/SAST/DAST assessments and collaborate with developers/engineers to remediate issues. • Formulate and establish application security policies, standards and guidelines to support the secure development of products and services. • Collaborate with the DevOps team to enhance Application Security, integrating security tools into the CI/CD pipeline, including container security, SCA/SAST, DAST, IAST, and third-party vulnerability Scanning. • Partner with security stakeholders across the organization to assist delivery teams in conceptualizing and implementing security-focused projects and initiatives. Requirements • Bachelor's degree in computer science or a related field. • Minimum of five years of professional experience encompassing a robust technical understanding and practical involvement in secure software development, security engineering, DevOps, application penetration testing, and/or negative QA testing. • Proficient in effective communication, interpersonal relations, and organizational management. • Experience with application security tools such as SCA, SAST, DAST, Penetration testing, and Fuzzing. • Comprehensive knowledge of prevalent software and web application security vulnerabilities, including OWASP Top 10 and SANS/CWE Top 25. • Expertise in conducting security assessments for web and mobile applications based on OWASP ASVS/M-ASVS and other testing guidelines. • DevOps experience with building and deploying applications/infrastructure with technologies like GitLab/GitHub, Ansible, Jenkins. • Advanced understanding and experience with web architectures, web applications, APIs, mobile applications, desktop applications, Unified Communications (including VoIP and SMS), and the underlying technology of cloud infrastructure. • Experience securing DevOps, including continuous integration, configuration management, and continuous deployment. • Demonstrated ability in leading code reviews, executing threat modeling, and conducting penetration tests. • Industry-recognized certification in security is a plus (e.g., CISSP, CISA, CISM, CRISC, CEH, etc.) • Bilingual in Spanish preferred. Benefits • Medical/Prescription drug insurance • Dental • Vision • Health Care/Dependent Care Flexible Spending Account • Health Savings Account • Pre-Tax and Roth 401(k) • Short and Long-Term Disability Insurance • Life/AD&D Insurance • Commuter Benefits • Student Loan Repayment Program • Educational Assistance • Generous paid time off Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Salesforce Consultant - Phoenix, AZ (Remote)

Remote Full-time

Behavioral Health Care Advocate (Utilization Review, Outpatient)

Remote Full-time

**Experienced Data Entry Clerk – Flexible Part-Time Remote Work Opportunity with blithequark**

Remote Full-time

Experienced Entry-Level Remote Data Entry Specialist – Work from Home Opportunity with blithequark

Remote Full-time

Lead Generation Specialist / Sales Development - Healthcare - REMOTE! Base & Comm

Remote Full-time

Experienced Customer Experience Associate – Global Remote Customer Support and Relations Specialist

Remote Full-time

SAP GTS Functional Consultant ( IMPORT & EXPORT)

Remote Full-time

Remote Transcriptionist 1099 Job at Global Impact Group LLC in Raleigh

Remote Full-time

**Experienced Live Chat Specialist – Insurance Customer Service Representative**

Remote Full-time

Experienced Part-Time Remote Data Entry Specialist – Essential Data Management and Organizational Role at Blithequark

Remote Full-time
← Back to Home