Amerisure Mutual Insurance Company Verified 4m ago
Senior Application Security Engineer (REMOTE)
Farmington Hills, MI Hybrid
Salary not listedPaySalary not listed
TypeFull-time
Work settingHybrid
Verified listing
JobFig found this opening at its original source and checks that it remains available.
About the role
We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to safeguard our applications from the ground up. The ideal candidate will possess the following skill set.
What you'll bring
- Bachelor’s degree or equivalent combination of education and experience.
- 7+ years of experience in Application and API Security within a DevSecOps environment.
- Required certifications include at least one CISSP, CSSLP, CCSP, GSEC, CEH, CISM, or CRISC, in addition to platform-specific certifications (AWS, Microsoft, Cisco, etc.) or domain specific certifications (OSWE, OSCP, GWAPT, or GWEB).
- Proven experience securing SaaS and custom applications in complex multi-cloud environments, applying security best practices and compliance frameworks.
- Expert knowledge of secure SDLC principles, application and API security, container security, and secure coding practices.
- Deep familiarity with OWASP Top 10, OWASP API Security Top 10, and CWE in DevOps environments using TeamCity, Azure Pipelines, GitHub Actions, and Bitbucket Pipelines.
- Extensive experience automating security scans and integrating SAST, SCA, IAST, DAST, and secrets detection tools into CI/CD pipelines.
- Proficiency in managing application security tools, including SonarQube, Black Duck, Synopsys Seeker, Snyk, and Wiz Code.
- Strong understanding of modern authentication and authorization protocols, including OAuth2, OIDC, JWT, and mTLS.
- Knowledge of cryptographic protocols and standards such as SSL/TLS, SSH, PKI, and emerging quantum-resistant encryption techniques.
- Solid understanding of security standards and frameworks, including NIST CSF, NY DFS, MI DIFS, HIPAA/HITECH, MITRE ATT&CK, and domain-specific regulatory requirements.
- In-depth knowledge of common attack vectors and tactics, with a focus on proactive defense and risk mitigation.