Senior Security Engineer (Product Application Security)
Veeam · United States
About The Role
Join our team as a Senior Security Engineer, where you'll play a crucial role in advancing the integration and operational maturity of enterprise application security tooling and vulnerability management. You'll work closely with various teams to improve visibility, automation, governance, and remediation workflows at scale. Your responsibilities will include evaluating and optimizing security tooling, building automated workflows for vulnerability management, and embedding security-by-design principles into the software development lifecycle. You'll also serve as a senior technical advisor on application security and mentor engineers and security practitioners on secure development and DevSecOps best practices.
- Évaluer, déployer, intégrer et optimiser les outils de sécurité, y compris SAST, DAST, SCA, IAST, et les tests de sécurité des API, dans les pipelines CI/CD et les flux de travail des développeurs.
- Construire des flux de travail automatisés pour l'ingestion des vulnérabilités, la priorisation, le suivi de la remédiation et le reporting, en intégrant des plateformes telles que GitHub Actions, Azure DevOps, Jenkins, Jira, et les outils SIEM.
- Conduire des initiatives de gestion des vulnérabilités au niveau de l'entreprise, y compris les cadres de priorisation, le suivi des SLA, les améliorations de la vitesse de remédiation et les tableaux de bord de posture de sécurité.
- Experience building API integrations and workflow automation across security platforms
- Bachelor's degree in Computer Science, Engineering, or equivalent experience
- Strong experience with Secure SDLC, threat modeling, and software supply chain security
- 8+ years of experience in Application Security, Product Security, DevSecOps, or Security Engineering
- 3+ years of hands-on experience with SAST, DAST, SCA, and IAST tooling integrated into CI/CD pipelines
- 3+ years in vulnerability management, including triage, risk scoring, and remediation coordination across engineering teams
- Experience in regulated or compliance-driven environments, including policy-as-code and OPA/Gatekeeper
- Familiarity with AI/ML security risks and emerging AI application security practices
- Demonstrated experience leading cross-functional security initiatives and influencing without direct authority
- Relevant certifications such as CISSP, CISM, CSSLP, or cloud security certifications
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring