Senior Information Security Engineer – Application
United States
Full Time
1 week ago
No Visa Sponsorship
Key skills
AWSCloudSDLCAIMLServerlessIAM
About this role
Role Overview
The Sr Information Security Engineer is responsible for designing, implementing, and continuously improving the technical security controls that protect internally developed applications, including cloud systems, containerized, and serverless workloads.
This role is a hands-on application security specialist who performs deep secure code reviews, leads threat modeling, and drives remediation of complex vulnerabilities across the SDLC.
Collaborating with other technical teams, this role ensures secure application development, deployment, and operation by assessing maturity, defining security requirements and guardrails, and delivering prioritized recommendations to improve pipeline controls, tooling, and integrations within the DevSecOps pipeline.
Conducting application security assessments, guiding secure software development practices, and advancing the maturity of application security capabilities.
The Information Security Engineer partners with development, operations, and security teams to embed security into development practices and responds as a subject matter expert during application-related security incidents.
Requirements
Bachelor’s degree in computer science, management information systems, or related field. Four years work experience in the areas of information security, systems or network administration, programming, or systems analysis may be substituted for a degree.
Seven (7) or more years of experience in information security, software engineering, DevSecOps, SRE/Platform Engineering, or a closely related field.
At least four (4) years of direct application security experience, including hands-on secure code review and vulnerability remediation guidance.
Knowledge of: Secure software development practices, secure software architecture principles, and common vulnerability classes with demonstrated ability to translate findings into practical engineering fixes.
Cloud-native, containerized, and serverless security concepts; particularly AWS IAM and event-driven architectures.
Demonstrated understanding of secure application development, DevSecOps practices, and application security technologies (e.g., SAST, DAST, SCA, container security).
AI/ML security concepts relevant to internal AI development (data governance, model/inference service security, and common AI threat scenarios). Equivalent demonstrated experience securing complex systems with the ability to quickly build AI security depth is acceptable.
Demonstrate experience with one or more of the following: Application Vulnerability Management, Identity and Access Management, and Data Loss Prevention process development, technical analysis and supporting technologies.
Demonstrate understanding in forensic investigations, data recovery and the handling of digital evidence.
Tech Stack
AWS
Cloud
SDLC
Benefits
NMDP offers regular, full-time employees medical, dental, vision, life and disability, accident/critical illness/hospital, well-being, legal, identity theft and pet benefits.
Retirement, paid time off/holidays, leave and incentive plans are also offered to eligible employees.