Mô tả Công việc
We are seeking an Application Security Engineer to build and develop our application security capability. The core mandate is security: defining how the organization designs, builds, and ships software securely - spanning secure SDLC, DevSecOps, security architecture and design, application security testing, and
developer enablement. The engineer drives security into the development lifecycle and CI/CD pipelines and fundamentally reduces security risk in software.
Key Responsibilities
Security by Design: Threat modeling, secure design review, security requirements; collaborate with architects to embed security into application design.
Security Architecture & Solutions: Recommend and implement security controls appropriate to each application's risk profile - e.g., WAF, API security, mobile app hardening (RASP / anti-tampering).
Application Security Testing: Operate SAST/DAST/SCA/SBOM tooling; triage findings, eliminate false positives, validate exploitability, and prioritize remediation by real risk.
Secure SDLC & DevSecOps Integration: Embed security gates and automated checks into CI/CD pipelines.
AppSec Maturity (OWASP SAMM): Run SAMM assessments, define the maturity roadmap, and measure improvement over time.
Developer Enablement: Secure coding training và Security Champions program.