- Experience
- 3+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 43 minutes ago
- Work mode
- Work from home
- Education
- Bachelor's degree or equivalent
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
As an Application Security Engineer at Prometric, you will join the expanding cybersecurity team focused specifically on securing applications. Your responsibilities will include validating security postures, performing application penetration testing, and managing vulnerabilities throughout Prometric's worldwide network. Collaboration with development teams is key to leading the static application security testing (SAST) initiatives and working alongside infrastructure teams to promote secure coding and deployment practices. You will also engage with the information security team in vulnerability management and dynamic application security testing (DAST) efforts. A strong understanding of SAST and DAST tools, MITRE ATT&CK framework knowledge, along with web development and network skills, is essential. Candidates should have at least five years of relevant application security experience.
Main Responsibilities
- Deliver hands-on assistance for triaging and maintaining the DAST/SAST platform, including onboarding new applications and repositories.
- Oversee scan coverages, review security findings, and collaborate with application owners and development teams to ensure remediation.
- Engage with architecture, development, and security colleagues to support secure application design and resolve security issues.
- Optimize vulnerability tracking and communication pipelines and automate issue detection and resolution through security tool integration.
- Contribute to endpoint security assessments to uphold compliance with standards and best practices.
- Develop and update application security policies, procedures, and standards.
- Create and refine threat models for critical applications.
- Support Prometric’s responsible disclosure program by properly triaging submissions.
- Coordinate with external penetration testers and security auditors, handling scope definition, preparation, evidence collection, validation, and remediation follow-ups.
- Assist in incident response operations relevant to application security.
- Stay informed on evolving threats and advancements in application security technologies.
Required Qualifications and Skills
- Bachelor’s degree or equivalent experience in Computer Science, Information Security, or related field.
- Minimum of three years’ experience in cybersecurity roles.
- Hands-on experience with SAST and DAST security tools.
- Strong background in application and product security assurance.
- Experienced in developing threat models for web applications.
- Familiarity with DevOps processes and CI/CD pipelines.
- Proven capability in designing, deploying, and maintaining security controls.
- Knowledge of infrastructure vulnerability evaluation.
- Excellent problem-solving and troubleshooting aptitudes.
- Strong organizational skills with meticulous attention to detail while managing multiple tasks.
Preferred Attributes
- Relevant security certifications are advantageous but not mandatory.
- Effective time management and communication skills.
- Ability to work both autonomously and collaboratively in a dynamic, fast-paced setting, managing several priorities and meeting deadlines.
- Exposure to secure practices in AI engineering, including reviewing AI-assisted development, model-driven apps, automation agents, and associated data security.
Employee Benefits
- Participation in pension plans.
- Healthcare coverage provided.
- Life insurance benefits.
- Health and wellbeing programs for employees.
- Additional annual leave beyond statutory requirements.
- 24/7 access to employee assistance programs.
- Enhanced maternity and paternity leave policies.
- Social club membership opportunities.
- Complimentary car parking facilities.
Minimum education
Bachelor's Degree