SonicJobs Logo
Left arrow iconBack to search

Application Security Engineer

SAS
Posted 3 days ago, valid for 16 days
Location

Cary, NC 27513, US

Salary

Competitive

Contract type

Full Time

Tuition Reimbursement

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The position for Application Security Engineer is located in Cary, North Carolina, and offers a hybrid work environment.
  • Candidates must have a minimum of 5 years of experience in Information Technology and a Bachelor's degree in computer science or a related field.
  • The role involves ensuring the security of internally-used applications, collaborating with various teams, and providing guidance on application security best practices.
  • The salary for this position is competitive, reflecting the candidate's experience and expertise in application security.
  • SAS offers world-class benefits including comprehensive medical plans, a robust 401k plan, and generous time off policies.

Application Security Engineer – Hybrid | Cary, North Carolina

 

We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.

 

If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more.

 

About the job  

As an Application Security Engineer within the Information Security Office (ISO), you will be responsible for verifying that our internally-used applications are secure by design. You will collaborate with a diverse set of development and management teams across R&D, IT, and SAS Managed Cloud Services organizations to help drive the maturity of the application security program at SAS.

Candidates should possess a diverse set of skills in application security and should have significant exposure to enterprise activities including software development, software testing, CI/CD, technical support, and program management. Your success will depend on your cooperative skills working with internal SAS customers and other teams across the enterprise to provide guidance about best practices in application security.

As an Application Security Engineer, you will:  

  • Provide Subject Matter Communication:
    • Coordinate with the Secure Design team to ensure new environments/applications align with expected compliance levels.
    • Provide guidance to development teams on security design, threat modeling, and resolution of security vulnerabilities
    • Advise on potential compensating and mitigating controls to reduce risk
    • Triage security findings received through a public bug bounty program, communicating with both the developers and independent security researchers
  • Perform Security Assessments & Assist in Remediation:
    • Perform application security assessments and web application security assessments on both internal and external web applications and web services
    • Interpret and triage results from web application assessments
    • Assess Azure and AWS cloud offerings to ensure usage aligns with security best practices
    • Assess applications for potential migration from on-prem to cloud
  • Build Security Standards & Integrations for Engineers:
    • Help research and define security benchmarks, guidelines, and processes

 

Required Qualifications

  • US Citizen.
  • 5+ years of experience in Information Technology
  • Bachelor's degree in computer science or related quantitative field
  • Experience with web-based architectures and applications
  • Familiarity with industry standards for application security
  • Familiarity with common application security testing techniques (DAST, SCA, SAST, IAST) and vulnerability management tooling
  • Equivalent combination of related education, training and experience may be considered in place of the above qualifications.
  • You’re curious, passionate, authentic and accountable. These are our values and influence everything we do.

 

Additional competencies, knowledge and skills

  • Continuous Improvement: Originating action to improve existing conditions and processes; identifying improvement opportunities, generating ideas, and implementing solutions.
  • Decision Making: Identifying and understanding problems and opportunities by gathering, analyzing, and interpreting quantitative and qualitative information; choosing the best course of action by establishing clear decision criteria, generating and evaluating alternatives, and making timely decisions; taking action that is consistent with available facts and constraints and optimizes probable consequences.
  • Influencing: Using effective involvement and persuasion strategies to gain acceptance of ideas and commitment to actions that support specific work outcomes.
  • Familiarity with DevSecOps
  • Familiarity with API Security best practices
  • Experience with container and Kubernetes security
  • Experience with Azure or other commercial clouds
  • Familiarity with various programming languages to assist with peer review (Java, Python, Golang)
  • Relevant security certifications such as CISSP, CSSLP, GPEN, GWAPT, OSCP
  • Familiarity with industry standard authentication and authorization (OAuth, Okta, Microsoft Entra) 

World-class benefits  

Highlights include...

  • Comprehensive medical, prescription, dental and vision plans.
  • Medical plan options include:
    • PPO with low annual deductible and copays.
    • HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
  • Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
  • An industry-leading 401k plan.
  • Tuition Assistance Program and programs and resources to support your development
  • Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
  • Volunteer Time Off, parental leave and unlimited paid sick days.
  • Generous childcare benefits for all full-time employees.

 

You are welcome here.

At SAS, it’s not about fitting into our culture – it’s about adding to it. We believe our people make the difference. Our inclusive workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers.

 

Additional Information:

To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer. All qualified applicants are considered for employment without regard to any characteristic protected by law. Read more: Know Your Rights. 

 

Resumes may be considered in the order they are received. SAS employees performing certain job functions may require access to technology or software subject to export or import regulations. To comply with these regulations, SAS may obtain nationality or citizenship information from applicants for employment. SAS collects this information solely for trade law compliance purposes and does not use it to discriminate unfairly in the hiring process.

 

SAS only sends emails from verified “sas.com” email addresses and never asks for sensitive, personal information or money. If you have any doubts about the authenticity of any type of communication from, or on behalf of SAS, please contact Recruitingsupport@sas.com.

 

Let's stay in touch! Join our Talent Community to stay up to date on company news, job updates and more.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.