Hybrid Senior Security Engineer, Applications

Posted last month

Apply now

About the role

  • Mentor junior Security Engineers and Security Champions on security best practices and techniques
  • Improve security tooling and processes to reduce manual review efforts and false negatives
  • Conduct security talks and training sessions
  • Identify critical flaws and weaknesses in web applications, services and cloud infrastructure and design/implement remediation
  • Write and review technical proposals, architectural diagrams, application code and IaC
  • Use automated and manual testing techniques to understand environments and reduce false negatives
  • Improve scope of assessments by adding new techniques and vulnerability categories
  • Consolidate and track vulnerabilities across the organisation and supply chain to prioritise security uplift efforts
  • Review and define requirements for developing and deploying secure products; create guidelines and standards
  • Build systems that protect against and eradicate entire classes of vulnerabilities

Requirements

  • Experience working as a Senior Security Engineer with deep involvement in securing modern web applications and APIs
  • Experience conducting threat modelling, security reviews and risk assessments
  • Solid project management experience leading initiatives that have measurably improved the security of organisations
  • Proficient in one or more high-level programming languages
  • Proficient with common developer tools and processes such as Github, CI/CD, containers and orchestration, IaaS/PaaS, APIs, Websockets, Databases, Front-End and Back-End systems
  • Experience securing Data to meet various privacy framework and regulation requirements
  • Deep understanding and experience in securing AWS environments
  • Experience in deploying AppSec tools (e.g., SAST, SCA, WAF) throughout the stages of the SDLC
  • Understanding of web security mechanisms such as SOP, CORS, CSP, Subresource Integrity, and same-site cookies
  • Strong understanding of authentication/authorization protocols e.g. OAuth, SAML and JWT

Benefits

  • Postman pay-on-performance philosophy
  • Flexible schedule working with a fun, collaborative team
  • Full medical coverage
  • Flexible PTO
  • Wellness reimbursement
  • Monthly lunch stipend
  • Wellness programs to support physical and mental health
  • Frequent team-building events
  • Donation-matching program
  • Inclusive culture

Job title

Senior Security Engineer, Applications

Job type

Experience level

Senior

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job