Senior Application Security Engineer
Listed on 2025-12-27
-
IT/Tech
Cybersecurity, IT Consultant, Systems Engineer
This role offers a hybrid work schedule at our Wilmington, DE Tech Hub.
OverviewResponsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration. Provides advanced working guidance to technology teams and leadership in the areas of secure coding, application authentication, encryption, and quickly research and become competent in other areas as needed.
Primary ResponsibilitiesDevelop and implement engineering’s technical security policies and procedures, and performance of security measures,
Scan and test applications for potential vulnerabilities and non-compliance with security standards,
Partner with engineering teams during code reviews to identify potential security vulnerabilities and advise strategies to develop more secure code,
Integrate security tools and processes into the software development and operations (Dev Ops) pipeline, including automation of security checks and scans to identify and fix vulnerabilities early in the development process.
Lead training sessions for technology teams in one-on-one coaching and large team training sessions on secure coding practices and information system security best practices.
Configure and manage automated tools and solutions to address security weaknesses in applications, systems, and infrastructure.
Partner closely with incident response teams to mitigate the impact of incidents from application security vulnerabilities and identify necessary steps to remediate findings.
Proactively recommend process enhancements and implement prioritized improvements within Cybersecurity team to enhance application security capabilities.
Track current events, technological advancements, and changes in the secure application development landscape to anticipate how attackers may change their tactics, and implement adjustments to internal technologies, policies, and procedures.
Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
Promote an environment that supports belonging and reflects the M&T Bank brand.
Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
Complete other related duties as assigned.
Partners primarily with individual contributors and leaders within Cybersecurity and Technology, and occasionally senior leaders within Cybersecurity.
Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met.
Proficient ability to use multiple Cybersecurity tools, specific to function.
This role is used within Cybersecurity, typically in one of the following ways:
Application Security – partners with engineers and developers to secure first-party and third-party code by reviewing the application, data, and systems it interacts with.
Product Security – secures products by ensuring they are designed, developed, and delivered in a secure manner".
No supervisory responsibilities
Education and Experience RequiredBachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience, including a minimum of 5 years software development or application security
Prior experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
Intermediate understanding of the Software Development Life Cycle (SDLC)
Ability to train…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).