Role Purpose: The Sr. Application Security Engineer will be a hands-on role responsible for delivering security engineering services to Jumio’s engineering teams and building secure systems and cloud infrastructure with our engineering teams and for executing initiatives on improving our security program.
Role Value: This role plays a vital part in our global Infosec function. It enables our business and customers to have more confidence in our systems, our processes and our ability to manage the cyber threats we face by ensuring that we work in a secure cloud infrastructure.
Example Responsibilities
Collaborate with Engineering and Infrastructure teams to identify and fill any security gaps in our SDLC, cloud infrastructure and associated processes
Integrate security into the Software/Infrastructure processes from initial threat modelling to decommissioning
Perform manual penetration testing of Web/mobile applications and APIs
Audit source code and perform code review for critical application changes
Help teams in understanding security vulnerabilities and associated risk,
providing guidance in prioritizing and remediation efforts
Identify critical security risks and drive mitigation with engineering teams
Manage cross-functional internal and external team collaboration and communications
Deploy security services and tools through IaC, and actively promote the culture of security as code
Periodic security assessments and configuration review of cloud environments
Build custom security solutions tooling and automation and lead security initiatives
Build, promote and scale DevSecOps across the company and enable integration of tools and practices as the teams transition to DevSecOps.
Experience And Qualifications
10+ years of experience in a security engineering role, specialized in application security and cloud security
Robust familiarity with Linux operating systems and cloud ecosystems like Amazon AWS, GCP, including networking concepts and security services