Application Security Engineer

Cornerstone OnDemand

4.6

United States

Why you should apply for a job to Cornerstone OnDemand:

  • Ranked as one of the Best Companies for Women in 2022

  • 4.6/5 in overall job satisfaction

  • 4.6/5 in supportive management

  • 90% say women are treated fairly and equally to men

  • 97% would recommend this company to other women

  • 100% say the CEO supports gender diversity

  • Ratings are based on anonymous reviews by Fairygodboss members.
  • Flexible work schedule.

  • Global Development Day: Every quarter Cornerstone hosts Development Day across the globe for professional and personal development.

  • Cornerstone Accelerator: a specialized program that provides a unique workspace and mentorship programs to startups.

  • #req8410

    Position summary

    The Application Security Engineer position is a hands-on role that involves evaluating and enforcing application security in all phases of the Software Development Life Cycle (SDLC). This position will work closely with our engineering teams to define the application security best practices, perform software architecture and design reviews, threat modeling, conduct white box security testing, and support the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms with a focus on supporting our GovCloud program.

    We are looking for someone with a strong background in information security and a proven ability to deliver under pressure. Position is remote and candidates must be willing to collaborate with team on PST timezone. Requires U.S. Citizenship.

    In this role you will…

    • Participate in architecture and design reviews with senior Engineering/DevOps staff to incorporate effective security standards into product design
    • Design, build & maintain security tools/processes to effectively secure our cloud-based environments (AWS, GovCloud,GCP) 
    • Implement a program to integrate security into the build/release pipelines to ensure our code is secure before it goes to production
    • Conduct white box security testing to assess and validate application security 
    • Define, maintain and enforce application security best practices and evaluate application security tools to improve our detection and prevention capabilities
    • Monitor and track progress of found vulnerabilities and maintain the history 
    • Explain and demonstrate vulnerabilities to application/system owners, and provide recommendations for mitigation 
    • Issue reports on assigned application and system scans 
    • Perform secure code development training to developers, quality assurance personnel and relevant staff

    You’ve got what it takes if you have…

    • Ability to obtain a security clearance which requires US citizenship
    • Bachelor’s degree in an Information Technology related field of study or equivalent post high school education and/or work-related experience 
    • 4+ years of experience in web or mobile application security
    • Experience with STIG and/or CIS
    • Knowledge of information security principles, web applications, and a level of familiarity with malicious code and common techniques used by hackers 
    • Experience with CI/CD practices and tools (Git, Jenkins) and integrating security solutions into CI/CD pipelines
    • Experience working on security responsibilities for a SaaS or PaaS solutions, preferably running in AWS. 
    • Understanding of SAST, DAST, Pen test and Open source vulnerability testing
    • Experience with common SDLC tools: static and dynamic code analysis, open source management, threat modeling, etc. 
    • Experience creating solutions in C#, Python, Node.JS, or Go, and Infrastructure as Code (AWS Cloud Formation)
    • Experience with HTML and JavaScript along with a solid understanding of HTTP protocol 
    • Excellent problem solving and analytical skills; outstanding oral and written communication skills
    • Experience coordinating penetration testing activities
    • Experience interacting with security vendors and customers
    • Self-motivation and the ability to work under minimal supervision are a must
    • Excellent at multitasking, and open to constant learning
    • Energetic and positive attitude
    • Demonstrated commitment to valuing diversity and contributing to an inclusive working and learning environment
    • Consideration for privacy and security obligations

    An extra dose of awesome if you have…

    • Experience working in AWS GovCloud or FedRAMP environment 
    • Knowledge of microservices architectures 
    • Basic knowledge of SQL and prior experience with programming in one or more server-side technologies such as ASP.Net. .NET Core or scripting (Python, Shell)
    • Thorough understanding of SDLC and software security maturity models such as Building Security In Maturity Model (BSIMM) or OWASP Software Assurance Maturity Model (SAMM)
    • Experience conducting secure code development training 
    • Knowledge of FIPS 140-2 and cryptographic tools

    #LI-ET1

    Get jobs straight to your inbox

    Anonymous company reviews, virtual recruiting events, and a supportive community for women when you sign up.

    What are Cornerstone OnDemand perks and benefits

    Lactation facilities

    Maternity leave coaching

    Care-taking PTO

    Sabbatical

    Unconscious bias training

    Networking

    Succession planning

    Diversity recruiting

    Remote work policy

    Part time policy

    About the company

    Industry: Technology: Software

    We are proud to be Cornerstars because we know that a few passionate people are capable of accomplishing big things and that small ideas can grow exponentially. Every individual has an innate desire to be their best and operate at their fullest potential. We believe that cultivating creativity and inspiring people to reach their full potential is the responsibility of both the ...

    Why you should apply for a job to Cornerstone OnDemand:

  • Ranked as one of the Best Companies for Women in 2022

  • 4.6/5 in overall job satisfaction

  • 4.6/5 in supportive management

  • 90% say women are treated fairly and equally to men

  • 97% would recommend this company to other women

  • 100% say the CEO supports gender diversity

  • Ratings are based on anonymous reviews by Fairygodboss members.
  • Flexible work schedule.

  • Global Development Day: Every quarter Cornerstone hosts Development Day across the globe for professional and personal development.

  • Cornerstone Accelerator: a specialized program that provides a unique workspace and mentorship programs to startups.