Senior Application Security Engineer

Blackbaud
Remote, Virginia, US
Remote
Full-time

We’re hiring on the Blackbaud Application Security team!

As a member of the Cyber Security organization at Blackbaud, the Application Security Engineer is a specialized position that plays a key role in securing software built and / or used by Blackbaud.

You can expect to work closely with software development teams as well as third-party organizations to ensure that security, privacy, and compliance requirements are planned for, designed, and built into software applications at Blackbaud.

In addition to securing software, you will be expected to stay up-to-date on what’s happening in the Cyber Security industry in order to optimize and align our application security processes and systems throughout the Software Development Life Cycle (SDLC) at Blackbaud.

The Application Security Engineering team focuses on building automation for security self-service and vulnerability management to reduce unnecessary toil.

What you will be doing :

Identifying solutions for difficult security problems while participating in a broader agile Application Security team.

Building comprehensive solutions to conduct consolidation, aggregation, and notification of security findings to respective stakeholders.

Conducting threat modeling, secure design reviews, and providing direct guidance to development teams.

Promoting, designing, and evaluating application security in all phases of the SDLC and constantly looking for innovative ways to improve processes.

Influencing, building, and assisting with information security challenges within applications.

What we'll want you to have :

You are either a security-minded software engineer who has been building modern services using a microservice architecture in an agile development environment or a development-interested security practitioner who understands security best practices, but wants to get closer to development and engineering.

3+ plus years experience with open source and commercial application security testing and analysis tools for DAST, SAST, SCA, and Attack Surface Management, e.

g. Burp Suite, OWASP Zap, Rapid 7 InsightAppSec, AppScan, Fortify, Checkmarx, Coverity, Semgrep, OWASP Dependency Check, Mend, Blackduck, OWASP Amass, Spiderfoot, and various programming language linters.

3+ years experience with Python, Bash, and / or PowerShell.

3+ years experience in integrating security solutions into CI-CD pipelines and automating tooling orchestration.

Experience partnering with development and systems engineers on impactful security initiatives.

Understanding of software development; how it is designed, built, and can be broken is critical.

Understand DevSecOps cultural mindsets, and an engineering focused approach to solving complex security problems.

Strong verbal and written communication skills to translate security objectives and requirements to specific engineering outcomes.

The Application Security team at Blackbaud is committed to ensuring security issues are prevented, discovered, and remediated in collaboration with our engineering partners across the business.

If that description fits your approach to security, we’d love to chat with you about what you can do to help our mission!

LI-REMOTE

Blackbaud is a remote-first company which embraces a flexible remote work culture. Blackbaud supports hiring and career development for all roles from the location you are in today!

30+ days ago
Related jobs
Promoted
Peraton
Alexandria, Virginia

The work is hands-on and requires engineers that can work with limited guidance, and you will provide technical guidance to junior engineers. A current/valid IAT LVL III Certification (Security+ CE, CCNP, CCNP Security, CISA, CISSP, GCED, GCIH, and CCSP). Experience with application of DoD IAVAs, DI...

Promoted
The MIL Corporation
Dahlgren, Virginia

Systems Security Engineer, Journeyman (Security Engineering, Senior Analyst). Perform programmatic or technical roles identifying, formulating, designing and/or testing practical solutions to engineering problems and guide the engineering development of modern complex systems; and to employ systems ...

Promoted
Compass, Inc
Chantilly, Virginia

Senior-level Systems Engineers guide engineering teams in taking a multi-discipline approach to requirements engineering, solutions engineering, scheduling, reliability, resiliency, services development, integration, test and evaluation, maintainability, and analysis across the National System of Ge...

Promoted
Booz Allen Hamilton
Springfield, Virginia

Systems Threat Engineer, Senior. As a leader in systems engineering, we’re looking for you to solve complex challenges and shape our customer's mission by leading an engineering team. Systems Engineering of Information Te. Master’s degree in Mathematics, Science, Engineering, or Te. ...

Promoted
ASRC Federal
Fort Belvoir, Virginia

ASRC Federal Business Innovation, a subsidiary of ASRC Federal, is seeking a .ACC IBS Exec Support Program on site at Fort Belvoir, VA.Plan, direct, or coordinate activities in such fields as electronic data processing, information systems, systems analysis, and computer programming.Support formulat...

Promoted
LMI
Chantilly, Virginia

LMI is seeking a skilled Senior Space Systems Engineer in Colorado Springs, CO or Chantilly, VA. The Senior Space Systems Engineer advises National Reconnaissance Office (NRO) customers on technical discussions, studies, analyses, algorithms, models, simulations, and other technical products and eff...

Promoted
InfoReliance
Fairfax, Virginia

Senior RSA Archer Cyber Security Engineer. InfoReliance is hiring for an experienced RSA Archer Consultant & Engineer to provide ongoing engineering and integration support for multiple eGRC Platform solutions to include the implementation of Assessment and Authorization and Security Operations ...

Peraton
Herndon, Virginia

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. ...

Booz Allen Hamilton
Quantico, Virginia

Embedded Hardware Security Engineer, Senior. That’s why we need you, an electrical engineer, with an understanding of embedded system design, mobile platforms and architecture, and hardware security concepts to help us design and develop techniques for testing memory subsystems, security subsystems,...

ALTA IT Services
Reston, Virginia

Senior FIPS 140 Security Engineer. The Accredited Testing and Evaluation (AT&E, Common Criteria/FIPS) team, provides the opportunity to work in the growing IT Security field in support of National defense. Ability to comprehend security standard requirements and apply them to products. Knowledge of ...