Talent.com
Senior Application Security Engineer
Senior Application Security EngineerAbbVie • Raleigh, North Carolina, United States
Senior Application Security Engineer

Senior Application Security Engineer

AbbVie • Raleigh, North Carolina, United States
[job_card.1_day_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Company Description

AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas immunology, oncology, neuroscience, and eye care and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com . Follow @abbvie on X , Facebook , Instagram , YouTube , LinkedIn and Tik Tok .

Job Description

Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software development to support and enhance our inline code testing and reporting processes. This role involves the implementation and administration of application security tooling, integration into CI / CD pipelines, and providing support for development teams using these products and consuming their findings.

Responsibilities :

  • Implementing and maintaining Application Security Testing (AST) tools (SAST, DAST, IAST, SCA, etc.) to identify code and dependency vulnerabilities during the software development lifecycle.
  • Implementing and maintaining Application Security Posture Management (ASPM) tools to centralize and deduplicate findings from multiple solutions and integrate into software development processes.
  • Acting as the first line of support for users by helping resolve false positives, providing guidance on finding remediation, and evaluating security exception requests.
  • Integrating security tooling with Continuous Integration / Continuous Deployment (CICD) pipelines.
  • Developing detailed reports on security findings and remediation efforts.
  • Demonstrate high proficiency across a wide range of technologies and platforms related to application security, software design and development, containerization, and cloud environments.
  • Communicate security risks and evangelize secure development practices to development teams and their management.
  • Lean / understand vulnerabilities, triage security risks at scale in disparate application development environments and business units.

Qualifications

  • Bachelors Degree and 7 years experience OR Masters Degree and 6 years experience OR PhD and 2 years experience
  • 5+ years of experience in application security and software development
  • 3+ years of experience implementing, administering, and supporting application security tooling such as SAST / DAST / IAST / SCA
  • Extensive knowledge of secure coding practices across multiple programming languages (esp. Java, Node.js)
  • Extensive experience integrating security testing into CICD pipelines
  • Strong knowledge of application security principles along with common vulnerabilities (e.g., OWASP Top 10, CWE, etc.) and associated mitigations
  • Experience implementing and scaling DevSecOps practices and tooling within large organizations
  • Experience implementing DevSecOps workflows in cloud environments such as AWS and Azure
  • Experience developing Infrastructure As Code (IAC) via solutions such as Terraform and / or CloudFormation
  • Experience supporting developers with assessing and mitigating application security test findings
  • Ability to effectively communicate technical findings to both technical and non-technical stakeholders
  • Demonstrated ability to function as a principal engineer, generating original technical ideas and strategies. Demonstrated creative 'out of the box' thinking to solve difficult technical problems and champion new technologies to achieve program goals.
  • Excellent written and oral English communication skills, as demonstrated by presenting at leading scientific or technical conferences.
  • Experience coaching and supporting the development of junior engineers
  • Preferred :

  • Experience implementing tooling to consolidate application security test findings from multiple sources to facilitate developer engagement and integrate with development workflows and tracking systems
  • Experience administering Snyk and Endor Labs
  • Experience integrating Cloud Security Posture Management (CSPM) tooling with application security pipelines
  • Experience automating workflows via programming and scripting languages such as Python
  • Experience building logging into DevSecOps pipelines to gain insights into pipeline performance
  • Experience collaborating with vulnerability and risk management partners to interface with risk management and acceptance processes
  • Additional Information

    Applicable only to applicants applying to a position in any location with pay disclosure requirements under state orlocal law :

    The compensation range described below is the range of possible base pay compensation that the Companybelieves ingood faith it will pay for this role at the timeof this posting based on the job grade for this position.Individualcompensation paid within this range will depend on many factors including geographic location, andwemay ultimatelypay more or less than the posted range. This range may be modified in thefuture.

    We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick),medical / dental / visioninsurance and 401(k) to eligibleemployees.

    This job is eligible to participate in our short-term incentiveprograms.

    This job is eligible to participate in our long-term incentiveprograms

    Note : No amount of payis considered to bewages or compensation until such amount is earned, vested, anddeterminable.The amount and availability of any bonus,commission, incentive, benefits, or any other form ofcompensation and benefitsthat are allocable to a particular employee remains in the Company's sole andabsolutediscretion unless and until paid andmay be modified at the Companys sole and absolute discretion, consistent withapplicable law.

    AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer / Veterans / Disabled.

    US & Puerto Rico only - to learn more, visit https : / / www.abbvie.com / join-us / equal-employment-opportunity-employer.html

    US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more :

    https : / / www.abbvie.com / join-us / reasonable-accommodations.html

    [job_alerts.create_a_job]

    Senior Application Security Engineer • Raleigh, North Carolina, United States

    [internal_linking.similar_jobs]
    M4-14Lead Security Analyst 141809

    M4-14Lead Security Analyst 141809

    FHR • Morrisville, NC, US
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Our direct client has a new opening for a Lead Security Analyst 141809.This job is 14 months to start, and the client is located in Augusta, ME. Please send your rate and resume.Regulatory compli...[show_more]
    [last_updated.last_updated_30]
    1-20-Infrastructure Security SME

    1-20-Infrastructure Security SME

    Focused HR Solutions • Raleigh, North Carolina, United States
    [job_card.full_time]
    [filters_job_card.quick_apply]
    A-8 / 9 - 716542 - Infrastructure Security SME - Remote & Raleigh, NC.Candidates will be allowed to work remotely.At times Candidate may be required to work onsite or attend meetings in Raleigh, ...[show_more]
    [last_updated.last_updated_30]
    Local Security Analyst (Security+)

    Local Security Analyst (Security+)

    InnoSoul, Inc. • Raleigh, NC, United States
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Job ID : NC-788683 (914090203) Hybrid / Local security Analyst / Program Director(15+) with NIST / CIS Controls / ISO, security servers / desktops / networks / firewalls / IAM / MFA / VPNs / patching ...[show_more]
    [last_updated.last_updated_variable_days]
    Cybersecurity Risk Assessment Lead

    Cybersecurity Risk Assessment Lead

    VGroup Inc • Raleigh, NC, United States
    [job_card.full_time]
    [filters_job_card.quick_apply]
    For more details, please connect with Kajal Verma at Kajalv@vgroupinc.Job Title : Cybersecurity Risk Assessment Lead Duration : 12+ Months < / div&...[show_more]
    [last_updated.last_updated_variable_days]
    M - 3 / 18 - 759936 - Sr. Cloud Network / Security Engineer

    M - 3 / 18 - 759936 - Sr. Cloud Network / Security Engineer

    Focused HR Solutions • Raleigh, North Carolina, United States
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Candidate will be allowed to work remote.Candidate must work EST business hours.All work must be completed in the United States. Our direct client has an opening for a Sr Cloud Network / Security Engi...[show_more]
    [last_updated.last_updated_30]
    Senior Cybersecurity Software Engineer

    Senior Cybersecurity Software Engineer

    Secmation • Cary, NC, USA
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Senior Cybersecurity Software Engineer.Location : Raleigh, NC |Huntsville, AL.Position Type : Full-Time | Hybrid.Signing Bonus and relocation assistance. Secmation is a proven, mission-focused enginee...[show_more]
    [last_updated.last_updated_30]
    Security Architect - Consultant 9309

    Security Architect - Consultant 9309

    FHR • Raleigh, NC, US
    [job_card.temporary]
    [filters_job_card.quick_apply]
    Security Architect - Consultant 9309.Employment Type : W2 Only (No Subcontractors).Contract Duration : 12-Month Contract. Our direct client is seeking an experienced.Linux, Windows, network security p...[show_more]
    [last_updated.last_updated_variable_days]
    IT Security Specialist

    IT Security Specialist

    Sunrise Systems • Raleigh, North Carolina, United States
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Duration : 11 Months On Contract.Security Management & Compliance : .Ensure the Epic EHR system is secure and compliant with federal, state, and organizational security policies, including HIPAA, ...[show_more]
    [last_updated.last_updated_30]
    Manager, Enterprise Apps

    Manager, Enterprise Apps

    Sumitomo Pharma • Morrisville, NC, United States
    [job_card.full_time]
    Japan with operations in the U.With several marketed products and a diverse pipeline of early- to late-stage investigational assets, we aim to accelerate discovery, research, and development to bri...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Senior Cyber Security Research Scientist

    Senior Cyber Security Research Scientist

    Hitachi Energy • Raleigh, NC, United States
    [job_card.full_time]
    Senior Cyber Security Research Scientist.Senior Cyber Security Research Scientist.At Hitachi Energy, we’re shaping the future of power systems through cutting‑edge research and innovation.As a Seni...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Software Engineer

    Senior Software Engineer

    LogistiVIEW • Cary, NC, US
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Senior Software Engineer Do you have a passion for technology and op timization ?.Do you want to join a growing company with the same passion?. At Logis ti VIEW we deliver intelligent Warehouse Exec...[show_more]
    [last_updated.last_updated_30]
    Senior Software Engineer - SDET - Data Mobility

    Senior Software Engineer - SDET - Data Mobility

    Dell • Butner, NC, Granville County, NC; North Carolina, United States
    [job_card.full_time]
    Senior Software Engineer - SDET – Data Mobility.The Software Engineering team delivers next-generation application enhancements and new products for a changing world. Working at the cutting edge, we...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Cybersecurity Program Director

    Cybersecurity Program Director

    Excelraise • Raleigh, North Carolina, United States
    [job_card.full_time]
    Core Job Details Job ID : 788683 Job Title : Cybersecurity Program Director Client : State of North Carolina-DHHS Job Description : The DHHS Privacy & Security Office is launching a large-scale cybersec...[show_more]
    [last_updated.last_updated_1_day] • [promoted]
    Senior Principal Software Engineer (Relocation Assistance)

    Senior Principal Software Engineer (Relocation Assistance)

    Baxter • Raleigh, NC, US
    [job_card.full_time]
    Senior Principal Embedded Software Engineer.At Baxter, we believe every personregardless of who they are or where they are fromdeserves a chance to live a healthy life. It was our founding belief in...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Professional Service Engineer

    Senior Professional Service Engineer

    Allied Telesis • Cary, North Carolina, United States
    [job_card.full_time]
    Salary : $88,000 - 152,000 per year.Bachelor’s degree in a technical or related field.Proficient in managing technical resources to achieve business and revenue goals. Continuous education in technol...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Cyber Security Research Scientist

    Senior Cyber Security Research Scientist

    Hitachi ABB Power Grids • Raleigh, NC, United States
    [job_card.full_time]
    Senior Cyber Security Research Scientist.Senior Cyber Security Research Scientist.At Hitachi Energy, we’re shaping the future of power systems through cutting‑edge research and innovation.As a Seni...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Cyber Security Research Scientist

    Senior Cyber Security Research Scientist

    Hitachi Automotive Systems Americas, Inc. • Raleigh, NC, United States
    [job_card.full_time]
    Senior Cyber Security Research Scientist page is loaded## Senior Cyber Security Research Scientistlocations : Raleigh, North Carolina, United Statestime type : Full timeposted on : Posted Todayj...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Application Development Manager

    Application Development Manager

    Rogers Corporation • Raleigh, NC, United States
    [job_card.full_time]
    This role is responsible for expanding product market presence, winning new business and increasing sales by providing expert support, training and assistance and directly managing specific custome...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]