Degreed is hiring a
Remote Application Security Engineer US
\nThe Application Security Specialist will be a key member of the Information Security team, reporting directly to the Information Security Officer (ISO). The primary responsibility of this role is to oversee the development and implementation of a secure Software Development Life Cycle (SDLC). Additionally, the Application Security Specialist will collaborate closely with the DevOps team to provide guidance and ensure the security of Degreed's cloud infrastructure.\n\nAs an Application Security Specialist, your primary responsibilities will involve collaborating with the product and engineering teams to proactively identify security issues during solution design and prevent vulnerabilities during development. You will support the development of design patterns and development standards to help developers and architects build secure solutions. You will support the development of assessment frameworks to evaluate designs then be responsible for their execution.\n\nOur ideal candidate will be comfortable working cross-functionally and enjoy building customer trust both internally and externally while finding innovative ways to mitigate risk, and protecting the data of our clients and users using Degreedโs products.โฏ\nDay in the Life\n\n\n* Support the design of proactive application security frameworks to ensure the secure architecture and development of business solutions. This includes frameworks for performing consistent application security assessments, threat models, as well as the development of secure design patterns and development standards.\n\n* Strong technical understanding of all security domains to help secure the Cloud environment, focusing on maturing the ability to protect assets and applications with applying controls around the four pillars of prevent, detect, respond and remediate.\n\n* Join forces with our brilliant Security Engineering team to define and integrate Security Architecture standards and Secure SDLC across the organization, ensuring our security practices stay top-notch and our products remain unbeatable.\n\n* Act as a key player in Degreedโs large-scale assisting the DevSecOps team\n\n* CI/CD pipelines and help design high-tech security practices for our cloud and container release platforms.\n\n* Conduct application security assessments, threat modeling and be involved with application design.\n\n* Proactively communicate design and development principles to appropriate stakeholders.\n\n* Empower and inspire our team of developers, architects, and others through training in secure coding and design principles to build the most robust and secure applications possible.\n\n* Build an application security program to allow internal teams to improve security designs and reduce vulnerabilities found after development of code.\n\n* Automation and standardization of all applicable processes.\n\n\n\nSkills Needed\n\n\n* Adaptability: Comfortable working in a dynamic environment with constant change and ambiguity.\n\n* Interpersonal Skills: Ability to build strong relationships with development, software architecture, and product management stakeholders.\n\n* Cloud Knowledge: Familiarity with popular cloud provider solutions (such as Azure, AWS, GCP) and cloud orchestration tools (like Kubernetes).\n\n* OWASP Understanding: In-depth comprehension of the OWASP Top 10 and the ability to effectively communicate security concepts with developers and application architects. Previous experience in development or software architecture is preferred.\n\n* Security Assessments: Expertise in conducting cloud architecture reviews, application risk assessments, and threat modeling to identify potential security risks.\n\n* SDLC Integration: Experience in integrating security controls into all stages of the Software Development Life Cycle (SDLC), including automating security measures into CI/CD pipelines.\n\n* Risk Analysis: Ability to analyze business impact and exposure based on emerging security threats, vulnerabilities, and risks. Capable of recommending suitable technologies and solutions to mitigate those risks.\n\n* Effective Communication: Skill in translating technical concepts into plain language to effectively communicate business risks and requirements to both technical and non-technical stakeholders.\n\n* Collaboration: Collaboration with developers and software architects to adjust designs and ensure they meet business and technical requirements securely.\n\n\n\nWho You Are\n\n\n* 5+ years of overall experience in information security, including 3+ years in application security field and 1+ year in Cloud Security\n\n* Background in the application security basics and a working knowledge of the OWASP Top Ten exploitation paths and control mitigations to protect against them. Cloud security experience preferred.\n\n* Knowledge and experience with the configuration of security controls and secure migration of enterprise applications to one of the major cloud providers such as Azure (preferred), Amazon Web Services, or Google Cloud.\n\n* Experience with defining and integrating Security Architecture standards and Secure SDLC across the organization. A general understanding of old and new development patterns: Release cycles, CI/CD, Code check-in and review. Demonstrated knowledge of build concepts like pipelines, runners, and security checks in early lifecycle build. A background in container build environments.\n\n* Demonstrated experience conceptualizing and thinking about threat assessments and threat modeling both in the release cycle and containerized environments. Experience with vulnerability management.\n\n* Exposure to delivering results in an agile environment driven by priorities.\n\n* Some development background such as building applications in at least one language in recent history and understand the complexities of building in modern languages.\n\n* Ability to work effectively in virtual environment where key team members and partners are in various time zones and locations.\n\n* A cybersecurity certification would be highly advantageous (Security+, SSCP, CISSP, CISM, CCSP, CSSLP, CEH, etc.)\n\n\n\nCompensation and Benefits at Degreed\nDegreed is passionate about pay transparency and we are committed to fair and equitable compensation practices. The pay range for this role is $140,000 - $170,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to: skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor.\nWe believe your best work happens when you have a complete life balance, and Degreed gives you the support and flexibility to make that happen. Degreed is committed to delivering a comprehensive benefits program that provides the support you need. At the time of this posting, this role is eligible to participate in the following benefits and wellness programs:\n\n\n* Comprehensive health insurance for you and your family (both PPO and HDHP plans available)\n\n* Dental and vision plans for you and your family\n\n* Employer-paid life insurance, AD&D, short-term disability, and long-term disability\n\n* Company equity\n\n* 401(k) Retirement Savings Plan with up to 4% match\n\n* Company funded HSA and dependent care FSA (pending eligibility)\n\n* Generous Parental Leave\n\n* Unlimited Paid Time Off and 5 sick days per year\n\n* Education benefit: Up to $1,200 per year for anything you want to learn (and we mean anything!)\n\n* 100% remote with a One-time Home Office Stipend to make your workspace more comfortable\n\n* Monthly internet and phone stipend\n\n* Monthly wellness stipend through Forma\n\n* Wellness programs focused on your financial, physical, and mental wellbeing\n\n\n\n*Degreed reserves the right to modify these benefits at any time, for any reason in accordance with applicable law. Please note the offerings vary based on location.\n \n#LI-Remote\n100% Remote \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Design, DevOps, Cloud and Engineer jobs that are similar:\n\n
$60,000 — $110,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐
We hire old (and young)\n\n
\n\n#Location\nWisconsin Dells, Wisconsin, United States
Apply for this job
๐ Please reference you found the job on Remote OK, this helps us get more companies to post here, thanks!
When applying for jobs, you should NEVER have to pay to apply. You should also NEVER have to pay to buy equipment which they then pay you back for later. Also never pay for trainings you have to do. Those are scams! NEVER PAY FOR ANYTHING! Posts that link to pages with "how to work online" are also scams. Don't use them or pay for them. Also always verify you're actually talking to the company in the job post and not an imposter. A good idea is to check the domain name for the site/email and see if it's the actual company's main domain name. Scams in remote work are rampant, be careful! Read more to avoid scams. When clicking on the button to apply above, you will leave Remote OK and go to the job application page for that company outside this site. Remote OK accepts no liability or responsibility as a consequence of any reliance upon information on there (external sites) or here.