Summary
Join Experian as a remote Application Security Engineer and collaborate with software engineers and leadership to mitigate security risks within the Secure Development Lifecycle (SDLC). You will work with development teams, implement security tools, review applications for flaws, and collaborate with Risk & Compliance teams on audits. The role requires defining security guardrails and integrating security solutions into CI/CD pipelines. Experian offers a competitive compensation package, comprehensive benefits, and a flexible work environment. The company is committed to diversity, equity, and inclusion, and provides various employee wellness programs and development opportunities. This position is remote.
Requirements
- 5+ years of direct experience in enterprise-level application security, with an understanding of MITRE, OWASP, SafeCode, and risk management methodologies related to integration/software testing
- Experience in AppSec or DevSecOps, collaborating with developers to adopt and mature secure development practices. Proficiency with SAST, SCA, DAST, IAST, RASP, and other DevSecOps tools, including deploying, maintaining, operating, and improving these tools
- Solid background in software development, familiar with development lifecycle processes and technologies. Experience with CI/CD pipelines and related technologies (e.g., Git, Jenkins, Maven, Chef, Puppet, Ansible, Nexus, Artifactory, NPM) and cloud-based architectures
- Experience overseeing the integration of applications between different teams and systems
- Experience in business and technical requirements analysis, business process modeling/mapping, methodology development, and data mapping
Responsibilities
- Collaborate with development teams to understand their needs, assess risks, and customize solutions
- Implement and manage security tools (SAST, SCA, DAST) and integrate solutions into CI/CD pipelines
- Review applications against common flaws (e.g., OWASP Top 10) and report to senior management
- Work with Risk & Compliance teams on audits (e.g., SOC 2, PCI-DSS, HIPAA) and recommend relevant policies
- Define security guardrails through automated tool policies, SLAs, and custom rules
Benefits
- Great compensation package and bonus plan
- Core benefits including full medical, dental, vision, and matching 401K
- Flexible work environment, ability to work remote, hybrid or in-office
- Flexible time off including volunteer time off, vacation, sick and 12-paid holidays
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.