SonicJobs Logo
Left arrow iconBack to search

Senior Engineer – Cybersecurity Application Security

OneMain Financial
Posted 3 days ago, valid for 20 days
Location

Irving, TX, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • OneMain Holdings, Inc. is seeking an application security engineer with a Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • The position requires a minimum of 5 years of application security engineering experience, including expertise in implementing and administering various application security platforms.
  • Key responsibilities include improving application security tooling, integrating security testing into software delivery pipelines, and developing security standards and policies.
  • Candidates should have strong communication skills and the ability to manage complex security initiatives while collaborating with various stakeholders to enhance application security maturity.
  • Salary details are not specified, but the role offers opportunities to contribute to security automation initiatives and support secure software development practices.

Key Responsibilities

  • Implement, administer, and continuously improve application security tooling supporting secure software development.
  • Integrate security testing and security controls into software delivery pipelines and engineering workflows.
  • Develop, maintain, and enhance application security standards, policies, procedures, documentation, and operational guidance.
  • Analyze security findings, operational metrics, and compliance trends to identify improvement opportunities and areas of elevated risk.
  • Partner with engineering teams to improve security adoption and enable secure-by-design and secure-by-default development practices.
  • Support secure SDLC governance, vulnerability management, and remediation tracking activities.
  • Collaborate with cybersecurity, architecture, platform, and engineering stakeholders to improve overall application security maturity.
  • Contribute to security automation initiatives that increase operational efficiency and reduce manual effort.
  • Support the secure implementation of emerging software development practices, including AI-assisted development workflows.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 5+ years of application security engineering experience.
  • Experience implementing and administering application security platforms, including SAST, DAST, SCA, IAST, container security, API security testing, and software supply chain security capabilities.
  • Experience securing APIs across the development lifecycle, including API discovery, authentication and authorization validation, schema and contract testing, abuse-case analysis, OWASP API Security Top 10 risks, and remediation guidance.
  • Experience integrating security tooling and automated security controls into CI/CD pipelines using infrastructure-as-code (IAC).
  • Experience supporting secure SDLC governance, policy enforcement, compliance reporting, and remediation management.
  • Working knowledge of application security principles, secure coding practices, OWASP Top 10 risks, and common vulnerability remediation techniques.
  • Experience developing and maintaining technical standards, procedures, policies, and security documentation.
  • Strong written and verbal communication skills with the ability to influence technical stakeholders.
  • Ability to independently manage moderately complex security initiatives and contribute to broader cybersecurity objectives.

Preferred Qualifications

  • Industry certifications such as CSSLP, GSEC, CISSP, GWAPT, or similar.
  • Experience supporting financial services, banking, or other highly regulated environments.
  • Experience assessing, implementing, and governing security controls for AI-assisted software development workflows, including secure use of code-generation tools, prompt and output handling, developer guardrails, and risk monitoring.
  • Experience with security automation, scripting, and workflow orchestration.
  • Experience creating executive, engineering, or operational security metrics and dashboards.

OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.