First American Financial - Santa Ana, CA

posted about 2 months ago

Full-time - Mid Level
Remote - Santa Ana, CA
11-50 employees
Insurance Carriers and Related Activities

About the position

The Application Security Engineer at First American Financial Corporation plays a crucial role in providing operational security solutions that support IT and business initiatives. This position requires collaboration with various stakeholders, including IT groups, client managers, business customers, third-party vendors, and auditors. The Security Engineer will work closely with the Security Architect to co-design and operationalize security solutions that can be delegated to Security Analysts or other support functions. The role encompasses both technical and administrative controls to ensure the protection and availability of business and IT systems. The Security Architect is responsible for defining the organization's information security architecture and standards, creating prioritized risk assessments based on a technical security control roadmap, and coordinating technical design and review activities. This position is essential for developing secure architectural frameworks, operational guidelines, and metrics that align with the organization's information security policies and overall strategy. In this role, the Application Security Engineer will be expected to have a strong ability to communicate with stakeholders, explaining code issues and fixes to the development community. Daily collaboration with developers is necessary to ensure that all projects adhere to the Software Development Life Cycle (SDLC) process, and that all code in the environment is scanned and remediated appropriately. The engineer will manage code scanning tools and oversee their day-to-day operational management. Additionally, the role involves interfacing with development and security architecture teams on application security topics, such as vulnerability remediation and threat modeling, as well as working with the vulnerability management team to ensure that identified vulnerabilities are reported and validated according to service level agreements (SLAs). The Application Security Engineer will also be responsible for developing Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for the Enterprise Application Security program, conducting manual testing activities to validate vulnerability or penetration testing findings, and may require weekend and night work based on project and business needs.

Responsibilities

  • Work closely with developers to ensure adherence to the SDLC process and code scanning and remediation.
  • Manage code scanning tools and oversee their operational management.
  • Interface with development and security architecture teams on application security topics.
  • Collaborate with the vulnerability management team to report and validate identified vulnerabilities according to SLAs.
  • Develop KPIs and KRIs for the Enterprise Application Security program.
  • Conduct manual testing activities to validate vulnerability or penetration testing findings.
  • Communicate code issues and fixes to the development community.

Requirements

  • Bachelor's degree in Information Security, Computer Science, or equivalent experience.
  • 5+ years of experience in Application Security.
  • Experience with AWS, Azure, or Google Cloud Platform.
  • Experience with APIs and DevSec practices.
  • Strong understanding of web application security principles.
  • Experience with security testing tools and methodologies.
  • Development background in programming languages such as C#, C++, Java, Python, or .Net.
  • Experience performing manual code reviews.
  • Experience in developing and maturing CI/CD pipelines regarding code quality and vulnerability detection.
  • Expert knowledge of OWASP Top 10 or CWE and understanding of common software threats and mitigations.
  • Bug Bounty and/or penetration testing experience is a bonus.
  • Process and detail-oriented with the ability to create detailed process documentation.
  • Excellent analytical and critical thinking skills.
  • Strong interpersonal and communication skills.

Nice-to-haves

  • Experience with Bug Bounty programs.
  • Penetration testing experience.

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401k plan
  • Paid time off (PTO)
  • Paid sick leave
  • Employee stock purchase plan
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service