Information Security Engineer
This role offers a hybrid work schedule at our Wilmington, DE Tech Hub. Responsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration. Provides advanced working guidance to technology teams and leadership in the areas of secure coding, application authentication, encryption, and quickly research and become competent in other areas as needed.
Primary Responsibilities :
Scope of Responsibilities :
Partners primarily with individual contributors and leaders within Cybersecurity and Technology, and occasionally senior leaders within Cybersecurity. Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met. Proficient ability to use multiple Cybersecurity tools, specific to function. This role is used within Cybersecurity, typically in one of the following ways : Application Security partners with engineers and developers to secure first-party and third-party code by reviewing the application, data, and systems it interacts with. Product Security secures products by ensuring they are designed, developed, and delivered in a secure manner.
Manager Responsibilities :
No supervisory responsibilities.
Education and Experience Required :
Bachelor's degree and a minimum of 3 years' relevant work experience, or in lieu of a degree, a combined minimum of 7 years' higher education and / or work experience, including a minimum of 5 years software development or application security. Prior experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite. Intermediate understanding of the Software Development Life Cycle (SDLC). Ability to train technologist and people leaders at various levels on secure application development, both in person and virtually. Excellent communication and interpersonal skills.
Education and Experience Preferred :
Intermediate experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite. Understanding of common software weaknesses that impact cloud and web applications, beyond the Open Worldwide Application Security Project (OWASP) Top 10. Demonstrable experience developing and maintaining automation for application security tasks and defect identification. Experience developing enterprise applications. Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments. Certifications in the area of Application Security. Proficient persuasive communication skills to gain buy-in of others in cybersecurity and technology teams. Ability to create an effective learning environment that allows for maximum learner results. Must be comfortable with providing 1-1 coaching for all levels of individual contributors and up to SVP management. Ability to build and maintain effective relationships within and across multiple technical teams. Prior experience utilizing continuous integration and continuous deployment (CI / CD) pipeline instrumentation. Highly proficient at coding with one or two programming languages. Highly proficient with Agile development methodologies and version control systems. Experience defining and reviewing software security features and capabilities
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $102,939.06 - $171,565.10 (USD). The successful candidate's particular combination of knowledge, skills, and experience will inform their specific compensation.
Location Wilmington, Delaware, United States of America M&T Bank Corporation is an Equal Opportunity / Affirmative Action Employer, including disabilities and veterans.
Application Security Engineer • Wilmington, DE, United States