application security engineer in application security
Описание от работодателя
Описание: PepsiCo’s Global Application Security Program integrates security into software development at enterprise scale, making application security risks visible, actionable, and measurable for efficient remediation.
Задачи: Configure, tune, administer, and maintain SAST/SCA/Secret/DAST and API scanning security tools; Manually triage security findings, reproduce representative issues, determine exploitability, identify false positives, assess business impact, and provide actionable remediation guidance; Perform targeted manual security reviews of web applications and APIs, including authentication, authorization, session management, input validation, data exposure, business logic, and access-control testing; Develop, test, tune, and maintain SAST rules, policies, rule packs, severity mappings, exclusions, and quality gates aligned with organizational standards; Configure and optimize DAST scanning profiles, authentication workflows, crawl settings, scan scopes, schedules, policies, and integrations; Integrate security scanning into source-control, pull-request, build, CI/CD, release, ticketing, and developer workflows using reusable pipeline components, APIs, webhooks, and automation; Develop and support backend automated scanning systems that onboard applications, initiate scans, track scan state, manage queues and retries, ingest results, normalize findings, and route data to downstream systems; Integrate findings into centralized application-security, vulnerability-management, or ASPM platforms; Establish risk-based prioritization and remediation workflows; Partner with developers, product teams, DevOps engineers, platform owners, and security stakeholders to resolve findings and implement security guardrails; Monitor scanner and integration health, including scan success rates, job queues, runners, connectivity, authentication, timeouts, capacity, licensing, logs, and service reliability; Evaluate emerging application-security tools and capabilities through proofs of concept, comparative testing, technical scorecards, detection-quality analysis, integration assessment, and operational-fit reviews; Develop and maintain security-testing standards, integration patterns, technical documentation, onboarding guides, operational runbooks, troubleshooting procedures, and developer-facing remediation guidance; Develop metrics and KPIs for application onboarding, scan coverage, workflow adoption, scan success, execution time, finding quality, false-positive rates, remediation performance, and platform reliability; Support mobile application-security tooling and integrations as needed; Participate in Agile development activities and an appropriate platform-support or on-call rotation, including weekends and holidays where required.
Требования: Bachelor’s degree in Computer Science, Engineering, or a related technical field; 3-5 Years of relevant professional experience in application security, security engineering, secure software development, or vulnerability management; Hands-on experience configuring, tuning, administering, or integrating application-security tools across enterprise development environments; Experience with SAST/SCA/Secrets and DAST platforms, including policies, rules, authenticated scanning, crawl configuration, scheduling, scope management, and CI/CD integrations; Experience manually triaging application-security and API-security findings, reproducing issues, identifying false positives, assessing exploitability, and providing remediation guidance; Experience performing web application and API security reviews using Burp Suite, Postman, curl, browser developer tools, or comparable technologies; Strong understanding of the OWASP Top 10, OWASP API Security Top 10, common web vulnerabilities, and API authentication and authorization technologies; Experience reviewing application code written in Java, JavaScript, TypeScript, Python, Go, C#, or comparable languages; Proficiency with Python and/or Go for security automation, API integrations, data processing, scan orchestration, custom validation, and backend service development; Experience building or supporting backend automation using REST APIs, webhooks, workers, queues, databases, schedulers, retries, timeouts, rate limits, and asynchronous job-processing patterns; Experience integrating security tools into CI/CD platforms such as GitHub Actions, GitLab CI/CD, Azure DevOps, Jenkins, CircleCI, or equivalent technologies; Experience with centralized findings-management, ASPM, or vulnerability-management platforms; Experience managing finding state across multiple tools and systems; Experience with SAST, DAST, SCA, secrets detection, API security, SBOM, container security, and software supply-chain controls; Experience operating and troubleshooting security tooling, including platform upgrades, authentication, connectivity, runner capacity, job queues, scan failures, timeouts, logs, access controls, licensing, and data retention; Experience with AWS, Azure, GCP, Docker, or Kubernetes used to host, scale, or integrate security tooling; Understanding of secure credential handling, service-to-service authentication, role-based access control, encryption, certificate management, audit logging, and data protection; Familiarity with SQL, JSON, SARIF, REST APIs, event streams, or message queues; Experience creating technical documentation, integration patterns, onboarding guides, operational runbooks, troubleshooting procedures, and developer-facing remediation guidance; Strong written and verbal communication skills; High integrity with sound judgment and accountability; Excellent analytical, problem-solving, and critical thinking abilities; Self-motivated, curious, and committed to continuous learning; Strong collaboration, relationship-building, and influencing skills; Comfortable working in a fast-paced, global environment with changing priorities and ambiguity; Ability to perform effectively under pressure; Nice to have: Mobile application security reviews and relevant tooling.
Условия: On-call rotation may include weekends and holidays where required.