More jobs:
Senior Security Engineer AppSec
Job in
Dallas, Dallas County, Texas, 75215, USA
Listed on 2026-06-18
Listing for:
East West Bank
Full Time
position Listed on 2026-06-18
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Data Security
Job Description & How to Apply Below
Overview
The Senior Cyber Security Engineer will lead and execute security initiatives across the application lifecycle, integrating security into Dev Ops pipelines, managing vulnerability assessments, and coordinating penetration testing efforts. This role ensures that applications are secure by design and resilient against evolving threats.
Application Security & Dev Sec Ops Integration- Embed security controls into CI/CD pipelines using Git Hub workflows and automation tools.
- Collaborate with development teams to implement secure coding practices and threat modeling during design and development phases.
- Manage Git Hub Advanced Security configurations, including secret scanning, push protection, and impact analysis.
- Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using approved tools (e.g., CodeQL, Dependabot, OWASP ZAP).
- Perform manual and automated code reviews to identify vulnerabilities and ensure remediation through code fixes or configuration changes.
- Maintain accurate mapping of applications to Git Hub repositories to support vulnerability tracking and reporting.
- Perform regular API security assessments and integrate monitoring tools like Data Theorem for endpoint protection.
- Implement and manage Web Application Firewall (WAF) policies and monitor logs for threat detection.
- Scope and schedule internal and third-party penetration tests for internet-facing and extranet applications.
- Validate findings, coordinate remediation with development teams, and track progress in Service Now and Jira.
- Generate and present vulnerability metrics to senior leadership, highlighting risk posture and remediation progress.
- Ensure compliance with internal standards and regulatory requirements (e.g., GLBA, SOX, SOC2).
- Deliver targeted training sessions based on impact analysis and vulnerability trends to improve developer awareness.
- Lead bi-weekly App Sec Management Update & Post-Finding Review Training meetings.
- May perform other duties as assigned.
- 3+ years of experience in application security, Dev Sec Ops , or related fields.
- Proficiency in Git Hub, SAST/DAST tools, WAF technologies, and API security frameworks.
- Strong understanding of secure SDLC, threat modeling (e.g., STRIDE), and vulnerability management.
- Experience coordinating penetration tests and managing third-party vendors.
- Excellent communication and stakeholder engagement skills.
Applicants must have legal authorization to work in the United States. We do not offer visa sponsorship at this time.
CompensationThe base pay range for this position is USD $/Yr.
- USD $/Yr. Exact offers will be determined based on job-related knowledge, skills, experience, and location.
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×