Senior Application Security Engineer
Job Description
Verisign helps enable the security, stability, and resiliency of the internet. We are a trusted provider of internet infrastructure services for the networked world and deliver unmatched performance in domain name system (DNS) services.Β
We are a mission focused, values driven company where each individual can contribute to building a stronger, more secure internet.Β We offer a dynamic and flexible work environment with competitive benefits and the ability to grow your career.
As a Senior Application Security Engineer, you will be responsible for enhancing the security posture of our applications throughout their lifecycle. You will collaborate closely with development teams to integrate security best practices, conduct thorough threat modeling, and apply OWASP ASVS techniques to identify and mitigate security vulnerabilities.
Key Responsibilities:
- Lead and participate in the design and implementation of secure coding practices across development teams
- Conduct detailed threat modeling exercises for new and existing applications to identify potential security issues
- Perform security reviews and code analysis to proactively identify and mitigate security vulnerabilities
- Participate in code reviews (Java, Python, etc.)
- Perform manual and tool-assisted secure code reviews on code diffs for a variety of programming languages.
- Work closely with developers to provide guidance on remediation strategies and secure coding techniques
- Implement and maintain automated security testing tools and processes
- Evaluate third-party libraries and dependencies for security risks
- Stay abreast of emerging security threats, vulnerabilities, and technologies to continuously improve application security measures
- Collaborate with cross-functional teams including Engineering and Operations to integrate security into the software development lifecycle (SDLC)
Requirements:
- Bachelorβs degree in Computer Science, Information Technology, or related field (or equivalent experience)
- 10+ years of proven experience as an Application Security Engineer or a similar role
- In-depth knowledge of OWASP ASVS and application security best practices
- Strong understanding of threat modeling methodologies and tools
- 5+ years of extensive development experience in one or more of the following programming languages: Java, C, C++, or Python
- Hands-on experience with secure coding practices and techniques (e.g., encryption, authentication mechanisms, secure API design)
- Proficiency in conducting security assessments (e.g., penetration testing, code reviews)
- Experience with SAST, DAST, and SCA security tools like CodeQL, Burp Suite Enterprise, etc.
- Excellent communication skills with the ability to articulate complex technical issues to non-technical stakeholders
- Certifications such as CEH, or equivalent are a plus
This position is based in our Reston, VA office and offers a flexible, hybrid work schedule
The pay range is $160,300 - $216,900.Β
The anticipated annual base salary range for this position is noted above, however, base pay offered may vary depending on job-related knowledge, skills, experience. Verisign offers a discretionary bonus which is based on individual and company performance, and certain roles may be eligible for discretionary stock awards.
Verisign is an equal opportunity employer. That means we recruit, hire, compensate, train, promote, transfer, and administer all terms and conditions of employment without regard to their race, color, religion, national origin, sex, sexual orientation, gender identity, age, protected veteran status, disability, or other protected categories under applicable law.
Additional Information:
Our Careers Page
Our Benefits Summary
Verisign in the Community
Our EEO Statement
Our Privacy Notice for Job Applicants/Candidates
Reasonable Accommodations
Staffing agency policy: No fees will be paid for unsolicited resumes submitted to Verisign or our employees by third parties.
Date Posted
09/11/2024
Views
0
Similar Jobs
Information Security Consultant - Application Security Engineer - MassMutual
Views in the last 30 days - 0
MassMutual is seeking an experienced Application Security Engineer to join their dedicated team The role involves driving security best practices cond...
View Details2025 Sensor Modeling and Simulation Analysis Engineer - The Aerospace Corporation
Views in the last 30 days - 0
The Aerospace Corporation is a trusted partner to the nations space programs providing technical expertise and innovative solutions across satellite l...
View DetailsSenior Associate, Data Science - People Analytics - Capital One
Views in the last 30 days - 0
Capital One is seeking a Senior Associate Data Science specialist for their People Strategy Analytics team The role involves applying data science an...
View DetailsSenior Associate, Data Scientist - Customer Management - Capital One
Views in the last 30 days - 0
Capital One is seeking a Senior Associate Data Scientist for the Mainstreet Customer Management Data Science team The role involves partnering with cr...
View DetailsSenior Named Account Executive, SLED - Cloudflare
Views in the last 30 days - 0
Cloudflare is seeking a seasoned sales professional with a technical background to build a Public Sector Sales team in Pennsylvania The ideal candidat...
View DetailsRegional Director Public Sector Sales DOW - Chainguard
Views in the last 30 days - 0
The job seeks a Regional Director with sales expertise and security clearance to lead public sector initiatives and build partnerships Responsibilitie...
View Details