JobHabor

Application Security Engineer

Teradata

Location
California
Workplace
Remote
Employment
Full Time
Salary
USD 101,600–152,500
Apply on the employer’s site

Posted 1mo ago

The employer’s full description could not be read from their board. This is a summary of the posting — follow the apply link for the original.

Responsibilities

  • Analyze and triage findings from SAST, SCA, DAST, IaC, and container scanning tools
  • Deliver actionable remediation guidance to development teams for AppSec findings
  • Perform code reviews across Java, C/C++, Go, Python, and JavaScript/TypeScript codebases
  • Integrate and tune AppSec scanning tools within CI/CD pipelines
  • Assess web applications and APIs for OWASP Top Ten vulnerability classes
  • Apply OWASP ASVS, AISVS, and SVPS standards to security assessments
  • Review AI-assisted development workflows and evaluate agentic systems for security risks
  • Investigate software supply chain risks in open-source dependencies
  • Write and maintain automation scripts in Go for security processes
  • Review Infrastructure as Code configs in Terraform, CloudFormation, Helm, and Ansible
  • Evaluate cloud environments across AWS, Azure, and/or Google Cloud for AppSec risks
  • Communicate security findings and risk to technical and non-technical stakeholders
  • Support compliance activities related to PCI-DSS and FedRAMP
  • Deliver developer training on secure coding and AppSec tooling
  • Guide and mentor software engineers on vulnerability remediation
  • Serve as go-to SME for AppSec topics, processes, and tooling

Requirements

  • Proficiency reading and reasoning about code in Java, C/C++, Go, Python, or JavaScript/TypeScript
  • Experience integrating SAST, SCA, DAST, IaC, and container scanning into CI/CD pipelines
  • Experience writing and maintaining security automation scripts in Go
  • Experience identifying and remediating software supply chain risks
  • Experience evaluating internal software and third-party products against security requirements
  • Familiarity with OWASP AISVS and OWASP Top 10 for LLMs, Agentic Apps, or NHIs
  • Ability to translate security findings into plain-language summaries for non-security audiences
  • Knowledge of core application security principles and common vulnerability classes
  • MS/BS degree in Electrical Engineering, Computer Science, Information Technology, or related field

Preferred

  • Advanced degree highly preferred

Skills

  • Java
  • C++
  • C
  • Go
  • Python
  • JavaScript
  • TypeScript
  • SAST
  • SCA
  • DAST
  • Terraform
  • CloudFormation
  • Helm
  • Ansible
  • AWS
  • Azure
  • Google Cloud
  • OWASP ASVS
  • OWASP AISVS
  • OWASP Top Ten

Similar roles