[Hiring] Application Security Engineer @H.W. Kaufman Group
Application Security Engineer @H.W. Kaufman Group
Software Development
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Application Security Engineer @H.W. Kaufman Group

1mth ago - H.W. Kaufman Group is hiring a remote Application Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the Software Development Lifecycle (SDLC), ensuring compliance with regulatory requirements, proactively mitigating threats, and collaborating closely with developers to enhance the overall security posture of our applications.

As a subject matter expert in application security, the Application Security Engineer will lead the charge in finding and implementing innovative security solutions while ensuring the organization remains resilient against evolving threats. This individual will work closely with development and IT teams to embed security into application architecture, offer technical guidance to junior team members, and drive the implementation of security initiatives essential for meeting business and compliance needs.

  • Partner with development teams to embed security best practices across the SDLC, including design, development, and deployment, and provide secure coding guidance.
  • Conduct threat modeling and security architecture reviews to identify design-level risks and implement appropriate security controls.
  • Identify, assess, and mitigate application vulnerabilities through a combination of automated (SAST/DAST) and manual code reviews, as well as penetration testing, and drive risk-based remediation.
  • Implement and manage application security tools, including SAST, DAST, Software Composition Analysis (SCA), and other security scanning solutions.
  • Ensure application security practices align with regulatory standards such as NYDFS, NIST, and OWASP guidelines.
  • Partner with DevOps, IT, and security teams to integrate security into CI/CD pipelines and engineering workflows.
  • Design and oversee the implementation of authentication, authorization, and access control mechanisms for APIs and platforms.
  • Develop and enforce secure usage standards and governance for AI tools and AI-generated code, addressing risks such as prompt injection, data leakage, insecure code generation, and model misuse, while aligning with regulatory and industry standards.

Qualifications

  • 5+ years of experience in application security, secure software development, and vulnerability management.
  • Strong knowledge of secure coding practices, OWASP Top 10, OWASP Top 10 for LLMs, MITRE ATLAS, and common security vulnerabilities.
  • Experience with containerization technologies such as Docker and Kubernetes, the principles of container operation, and their secure interaction.
  • Experience with security testing tools (e.g., Burp Suite, Fortify, Veracode, or similar).
  • Experience with Black Duck/Polaris with Apex code (Salesforce) is a plus.
  • Familiarity with DevSecOps principles and integrating security into CI/CD pipelines.
  • Direct experience with security tools such as vulnerability scanners, intrusion detection systems, and log analysis tools.
  • Understanding of regulatory frameworks and compliance requirements (e.g., NYDFS, GDPR, SOC 2).
  • Ability in scripting and automation using languages such as Python, PowerShell, or Bash and leverage AI driven tools to streamline and enhance security process and workflows.
  • Relevant certifications such as Certified DevSecOps Engineer, CISSP, OWASP certifications, GIAC GWAPT.

Company Description

H.W. Kaufman Group is a powerful global network of companies dedicated to shaping the future of insurance. With thousands of dedicated professionals across an extensive network of over 60 offices around the world, we lead by offering innovative solutions that are at the forefront of the industry. We are privately owned and thus free from the influence of Wall Street. This allows us the ability to adapt to constantly fluctuating market conditions. From brokerage, underwriting, and real estate to claims, loss control and risk management services, our depth of services is unrivaled.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Application Security Engineer @H.W. Kaufman Group
Software Development
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 165,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 165,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 165,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later