Search jobs > Milwaukee, WI > Application security

Application Security Engineer

Veolia North America
Milwaukee, WI, United States
Full-time

Company Description

About Veolia North America

A subsidiary of Veolia Group, Veolia North America (VNA) offers a full spectrum of water, waste and energy management services, including water, and wastewater treatment, commercial and hazardous waste collection and disposal, energy consulting and resource recovery.

VNA helps commercial, industrial, healthcare, higher education, and municipality customers throughout North America. Headquartered in Boston, Mass.

Veolia North America has approximately 10,000 employees working at more than 350 locations across the continent. Please visit our websitewww.veolianorthamerica.com.

Job Description

BENEFITS

Veolia's comprehensive benefits package includes paid time off policies, as well as health, dental and vision insurance. In addition, employees are also entitled to participate in an employer sponsored 401(k) plan, to save for retirement.

Pay and benefits for employees represented by a union are outlined in their collective bargaining agreement.

Position Purpose :

The Application Security Engineer identifies and remediates security vulnerabilities in software applications, ensuring robust protection against potential threats.

The Application Security Engineer develops and implements security measures, conducts security assessments, and provides guidance on secure coding practices and stays updated on the latest security trends and technologies to continuously enhance application security

Primary Duties / Responsibilities :

  • Assist in onboarding applications and applications to Secure SDLC controls including remediation guidance, issue tracking and metrics.
  • Assist in integration of security tools (e.g., DAST, SAST, SCA, etc.) in the delivery pipeline and the S-SDLC process.
  • Collaborate with engineers, consultants and leadership to address security risks and provide mitigation recommendations within the Secure Software Development Life Cycle (SSDLC).
  • Provide remediation coaching to development teams on how to build a more secure application, including explanations of risk assessment, e.g. likelihood, impact.
  • Review and improve static and dynamic analysis findings to ensure their accuracy and relevance.
  • Perform impact assessments, develop prioritized remediation plans, and drive remediation campaigns for the newest and most critical application vulnerabilities.
  • Perform security architecture and design reviews.
  • Take a leadership role in driving strategic solutions to recurring vulnerabilities.
  • Provide actionable security guidance to our engineering teams.
  • Integrate security technologies and processes directly into our pipelines.
  • Proactively research and monitor security-related information sources to aid in vulnerability discovery.
  • Understand, communicate and balance business risk with security risk.
  • Ability to understand business requirements and apply security controls without adversely affecting the desired functionality.

Work Environment :

This will be a hybrid role located in Milwaukee, WI.

Qualifications

Education / Experience / Background :

  • Bachelor's or Master's Degree in Computer Science, Engineering, Information Security or extensive professional experience considered in place of a Bachelor's degree.
  • Min of 5 years of professional experience as an Application Security Engineer.
  • Experience with infrastructure as code (IaC) using Terraform, Ansible, AWS CDK, or similar.
  • Experience with DAST, SAST, SCA.

Knowledge / Skills / Abilities :

  • Subject matter expertise in application security and vulnerability assessments.
  • Provent technical understanding of OWASP Top 10, CVSS and other vulnerability ratings.
  • One or more programming languages (Rust, Python, C++, Go, PHP, etc.).
  • Application Security, AWS, GCP, Azure Security, Container Security.
  • Tools you may be familiar with :
  • APT Hunter, AWS, Alien Vault, Azure, Bash, Confluence, Cuckoo Sandbox, EKS, Google Workspace, Github, GitLab, Golang, HTML, Hashcat, JIRA, JWT, Java, Java script, Jenkins, Kubernetes, Metasploit, New Relic, Nmap, NodeJS, OWASP, Python, Rails, Ruby, SAML, SNORT, SNow, SQL, SQLMap, TypeScript, Wireshark, tcpdump, Yara, Zeek.
  • Familiarity with IDEs, e.g. Visual Studio, eclipse or IntelliJ IDEA.
  • Familiarity with build systems such as Bamboo, Jenkins, AWS native build tool.
  • Familiarity with IDEs, e.g. Visual Studio, eclipse or IntelliJ IDEA.
  • High level of personal integrity with the ability to professionally handle confidential matters and reflect appropriate level of judgment.
  • High degree of accuracy and attention to detail.
  • Excellent organization skills and ability to multitask.
  • Knowledge of Threat Modeling and risk assessment techniques.
  • Strong understanding of encryption, authentication, and access control mechanisms.
  • Firm understanding of enterprise class application architectures that are highly scalable, reliable and the ability to secure them.
  • Deep technical understanding of the Mitre Attack Framework.
  • Ability to work independently with minimal direction, self-starter, self-motivated with an passion for security & automation.

Additional Information

We are an Equal Opportunity Employer! All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Disclaimer : The salary, other compensation, and benefits information is accurate as of the date of this posting. The Company reserves the right to modify this information at any time, subject to applicable law.

13 hours ago
Related jobs
Promoted
Veolia North America
Milwaukee, Wisconsin

The Application Security Engineer develops and implements security measures, conducts security assessments, and provides guidance on secure coding practices and stays updated on the latest security trends and technologies to continuously enhance application security. The Application Security Enginee...

Promoted
Veolia
Milwaukee, Wisconsin

The Application Security Engineer develops and implements security measures, conducts security assessments, and provides guidance on secure coding practices and stays updated on the latest security trends and technologies to continuously enhance application security. The Application Security Enginee...

Blackbaud
Remote, Wisconsin, US
Remote

You are either a security-minded software engineer who has been building modern services using a microservice architecture in an agile development environment or a development-interested security practitioner who understands security best practices, but wants to get closer to development and enginee...

Promoted
Regal Rexnord Corp
Cudahy, Wisconsin

We are seeking an Application Engineer to support the following brand:. A portfolio of highly engineered power transmission components and subsystems efficiently transmits motion to power industrial applications. Provide customer with assistance for product selection for unique, special, or technica...

Promoted
Silgan Containers
Brookfield, Wisconsin

What we can offer you:A great culture where you are a member of our family.Achievements are recognized, acknowledged, and celebrated.Excellent salary and a robust benefits package including health, dental, vision, life, short and long-term disability, and more.Add-on benefits include pet insurance, ...

Promoted
Umanist Staffing LLC
Milwaukee, Wisconsin

As a Network Engineer, you will play a vital role in designing, implementing, and maintaining the organization's network infrastructure. Proven experience as a Network Engineer or similar role. You will be responsible for ensuring seamless connectivity, optimal network performance, and robust se...

Promoted
AE Business Solutions
Milwaukee, Wisconsin

AE Business Solutions is seeking a GRC Analyst to take on a fully remote contract position! The GRC Analyst position will last at minimum through the end of the year with the possibility of being converted to FTE status in 2025. GRC/Security Analyst experience. Manage and maintain IT and cybersecuri...

Promoted
Xometry
Milwaukee, Wisconsin

The Manufacturing Applications Engineer is responsible for providing manufacturing expertise and input covering areas of customer quoting, manufacturing engineering, manufacturing operations and project management for Xometry's Product Development, Partner Network, Applications Engineering and M...

Promoted
Advocate Health
Milwaukee, Wisconsin

Security Officer healthcare certification (CHSO) issued by the International Association for Healthcare Security and Safety (IAHSS) needs to be obtained within 2 years. Delivers security awareness education to team members to leverage their assistance in the overall security of the site. Serves as t...

Promoted
Harley-Davidson Motor Company
Wauwatosa, Wisconsin

These positions require a Bachelor of Science Degree in Software Engineering, Electrical Engineering, Computer Engineering, or a related technical Degree. We have openings at various levels within our Software group (Associate, Design Engineer, Systems Architect, Technical Lead). Ability to work bey...