Application Security Engineer
This is an Application Security Focused Engineer. Need's to have been involved in security for application front ends.
Location :
Acadia WI, Advance, NC, Seattle, WA, and Tampa. Onsite 5 days / week
Role :
Front End Developer / Cyber Security Engineer
- Need support to build safer applications due to recent attacks (web app / mobile cx)
- This individual will work closely with engineering & security teams to ensure a strategy moving forwards
- App side & less infrastructure focused
- OWASP Top 10
- Svelte
- API (shared responsibility)
Key Responsibilities :
Frontend Development & Security Integration
Architect and develop secure frontend applications using modern frameworks (Svelte, React, Flutter, etc.)Implement security-first design principles in web and mobile application developmentBuild and maintain security libraries, components, and frameworks for development teamsDesign secure authentication and authorization flows (OAuth 2.0, SAML, JWT)Implement Content Security Policy (CSP), CORS, and other browser security mechanismsApplication Security Leadership
Conduct security code reviews and vulnerability assessments for frontend applicationsImplement OWASP Top 10 mitigation strategies across all web propertiesDesign and implement secure API consumption patterns and data handlingLead security testing initiatives including SAST, DAST, and penetration testing coordinationDevelop secure coding standards and security guidelines for development teamsInfrastructure Security & Performance
Configure and optimize CDN security settings (Fastly)Implement and manage Web Application Firewall (WAF) rules and policiesDesign DDoS protection strategies and rate limiting mechanismsOptimize application performance while maintaining security standardsMonitor and respond to security incidents affecting frontend applicationsSecurity Tools & Monitoring
Implement security monitoring and alerting for frontend applicationsIntegrate security scanning tools into CI / CD pipelinesConfigure and manage security headers and SSL / TLS implementationsDevelop automated security testing and compliance validationCreate security dashboards and reporting mechanismsTeam Leadership & Education
Mentor development teams on secure coding practicesConduct security training and awareness sessionsCollaborate with DevSecOps, Security, and SRE teams on security initiativesLead incident response for application security eventsStay current with emerging security threats and mitigation techniquesRequired Qualifications :
Experience : 7+ years in frontend development with 4+ years focused on application securitySecurity Expertise : Deep understanding of OWASP Top 10, security vulnerabilities, and mitigation strategiesFrontend Technologies : Expert-level proficiency in JavaScript, TypeScript, HTML5, CSS3Frameworks : Strong experience with Svelte, or React with security considerationsSecurity Tools : Hands-on experience with SAST / DAST tools, vulnerability scanners, penetration testingWeb Security : Extensive knowledge of CSP, CORS, XSS prevention, CSRF protection, input validationInfrastructure : Experience with CDN configuration, WAF management, and DNS securityAuthentication : Implementation experience with OAuth, SAML, JWT, and multi-factor authenticationCompliance : Understanding of PCI DSS, GDPR, CCPA, and other relevant security standardsDevSecOps : Experience integrating security into CI / CD pipelinesPreferred Qualifications :
Certifications : CISSP, CEH, OSCP, AWS Security Specialty, or equivalent security certificationsCloud Security : Experience with AWS / Azure / GCP security services and configurationsMobile Security : Understanding of mobile application security (iOS / Android)API Security : Experience with GraphQL security, REST API protection, and microservices securityThreat Modeling : Experience with application threat modeling and risk assessmentIncident Response : Background in security incident response and forensicsE-commerce Security : Experience securing e-commerce platforms and payment processingZero Trust : Understanding of Zero Trust architecture principlesTechnical Skills :
Languages : JavaScript, TypeScript, Python (for security scripting)Security Frameworks : OWASP ASVS, NIST Cybersecurity FrameworkSecurity Tools : Burp Suite, OWASP ZAP, Nessus, Qualys, Checkmarx, VeracodeMonitoring : SIEM integration, security logging, threat detectionInfrastructure : Terraform, Docker, Kubernetes security configurationsVersion Control : Git with security branch protection and code signing