Application Security Engineer

Esri Logo

Esri

πŸ’΅ $73k-$128k
πŸ“Remote - United States

Summary

Join Esri as an Application Security Engineer and contribute to a technology-driven environment focused on securing intellectual property, networks, and sensitive data. You will collaborate with various teams to design security into applications, perform security testing, and assist developers in vulnerability remediation. This role involves creating and maintaining Web Application Firewall (WAF) policies, monitoring activity logs, analyzing findings, and communicating risks to stakeholders. You will also contribute to team organization, documentation, and reporting on findings and remediation activities.

Requirements

  • 2+ years of relevant, full-time experience
  • Thorough understanding of HTTP, TLS, DNS
  • Knowledge of common web vulnerabilities, including those outlined in the OWASP Top 10, and how to mitigate them
  • Familiarity with cloud infrastructure, network routing and basic infrastructure components
  • Moderate understanding of JavaScript and its role in modern web applications
  • Demonstrated ability to independently learn and adapt to new technologies
  • Strong organizational skills and a detail-oriented approach
  • Strong verbal and written communication and collaboration skills
  • Bachelor’s in Computer Science or related STEM field

Responsibilities

  • Create, deploy, maintain and troubleshoot Web Application Firewall (WAF) policies for existing and new web applications
  • Monitor and analyze activity logs to detect malicious internet traffic and indicators of compromise as well as to reduce false positive blocks
  • Review WAF usage and define means to improve and mature protection policies
  • Collaborate closely with application developers to analyze findings and implement required remediations or countermeasures
  • Help assess and calculate application risks, communicate your findings to stakeholders of varying technical skill levels
  • Assist leadership with organization of ongoing work across the team, policy and documentation creation, and preparation of relevant metrics on findings and remediation activity for leadership
  • Interpret web protocol information to determine source, intent, and risk of threats
  • Provide operational support, troubleshoot and quickly resolve problems
  • Create and maintain technical documentation regarding the WAF including network diagrams, policies and operational procedures for managing the infrastructure

Preferred Qualifications

  • Hands-on experience using web application firewall solutions such as offerings from Akamai, AWS, F5, or Fortinet
  • Experience using Splunk to analyze logs and detect malicious activity
  • Proficiency in scripting languages such as JavaScript, Python, Bash, or PowerShell for automation
  • Experience using APIs for automation, integration, or data analysis
  • Familiarity with Git
  • Understanding of common encoding and encryption schemes, and algorithms

Benefits

  • Industry-leading health and welfare benefits: medical, dental, vision, basic and supplemental life insurance for employees (and their families), 401(k) and profit-sharing programs, minimum accrual of 80 hours of vacation leave, twelve paid holidays throughout the calendar year, and opportunities for personal and professional growth
  • Base salary is one component of our total rewards strategy
  • Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.