Meredith

Application Security Engineer

Remote New York, NY
USD 105k - 150k
Java JavaScript Python API Git
Search for More Jobs Talk to a recruiter now 💪
Description

Job Title

Application Security Engineer

Job Description

About Your Role: 
Dotdash Meredith is looking for an Application Security Engineer with a track record of innovative thinking, technical expertise, and collaboration. This role will be tasked with supporting software development teams, vulnerability management and remediation, and improving security coverage throughout the SDLC. 
As a valued member of the Security team, you will be responsible for helping to set technical direction, delivering technical projects, and collaborating with other groups within the organization. 

This position offers remote work flexibility; however, if you reside within a commutable distance to one of our main offices in New York, Des Moines, Birmingham, Los Angeles, Chicago, or Seattle, the expectation is to work from the office three times per month.

About Your Contributions: 
Solutions 
● Function as a subject matter expert for security solutions within the organization’s platform.

● Integrate security solutions into the SDLC process. 
● Work with development teams to improve the security of CI/CD processes by ensuring version control for source code, scanning code for vulnerabilities in the build pipeline, and ensuring public/private repositories are trusted and secure. 
● Design and develop coding standards across infrastructure, application, and data security, building out guidelines and standards to drive a standardized set of security requirements that align with internal policies and meet external compliance/regulatory requirements.

● Help evolve application security functions and services. 


Vulnerability Assessment 
● Prioritize, triage and remediate vulnerabilities and findings from security scans and bug bounty programs. 
● Review security test results from vulnerability scans and penetration tests and propose appropriate remediation measures or mitigation controls, conduct a remediation plan and supervise its progress. 
● Improve and support application security tool deployments including static analysis, dynamic testing and software composition analysis tools. 
● Conduct security code reviews for various languages and frameworks of web and mobile applications. 
● Identify security exposures and develop mitigation plans. 
● Investigate and report vulnerabilities in systems and platforms. 
● Assess the application threat landscape through threat modeling and architecture reviews.

● Develop metrics and reporting on the posture of the application security program. 

About You: 
Technical Skills 
● 2+ years experience in a security technical role or software development. 
● Development experience in Java, JavaScript and Python. 
● Scripting and automation experience using RESTful API’s. 

Application Development and Security 
● Knowledge of SANS/CWE Top 25, OWASP Top 10 Application Security principals.
● Experience with application security tooling and processes, including code review, static code analysis, penetration testing, risk management, etc. 
● Strong knowledge and experience in implementing SDLC best practices. 
● Knowledge with Git and version control best practices. 
● Ability to innovate and find creative solutions that balance business needs with security needs.

● Familiarity with application layer assessment tools, such as local proxies and fuzzers.

● Familiarity with threat modeling and security design review methodologies. 

Infrastructure 
● Solid understanding of OSI model, TCP/IP, HTTP and TLS. 
● Knowledge of C.I.A. (confidentiality, integrity, availability) security principles and D.I.E. (distributed, immutable and ephemeral) security model. 
● Experience with data encryption, cryptography and encryption key management.

● Experience with configuration management and DevOps practices to ensure security is built into the SDLC process. 

Preferred Skills:
● Passion for application security and continuous learning. 
● Able to concisely communicate security risks to both technical and business audiences.

● Attention to detail. 
● Ability to work independently, and as part of a team. 
● Ability to multitask and prioritize work effectively.
 

It is the policy of Dotdash Meredith to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, the Company will provide reasonable accommodations for qualified individuals with disabilities. Accommodation requests can be made by emailing ddm.hr@dotdashmdp.com.

The Company participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here: https://www.e-verify.gov/employees

Pay Range

Salary: New York: $125,500.00 - $150,500.00 Remote US: $105,000.00 - $126,000.00 Washington: $120,000.00 - $145,000.00

The pay range above represents the anticipated low and high end of the pay range for this position and may change in the future. Actual pay may vary and may be above or below the range based on various factors including but not limited to work location, experience, and performance. The range listed is just one component of Dotdash Meredith’s total compensation package for employees. Other compensation may include annual bonuses, and short- and long-term incentives. In addition, Dotdash Meredith provides to employees (and their eligible family members) a variety of benefits, including medical, dental, vision, prescription drug coverage, unlimited paid time off (PTO), adoption or surrogate assistance, donation matching, tuition reimbursement, basic life insurance, basic accidental death & dismemberment, supplemental life insurance, supplemental accident insurance, commuter benefits, short term and long term disability, health savings and flexible spending accounts, family care benefits, a generous 401K savings plan with a company match program, 10-12 paid holidays annually, and generous paid parental leave (birthing and non-birthing parents), all of which may vary depending on the specific nature of your employment with Dotdash Meredith and your work location. We also offer voluntary benefits such as pet insurance, accident, critical and hospital indemnity health insurance coverage, life and disability insurance.

#NMG#
Meredith
Meredith
Advertising Broadcasting Marketing

0 applies

3 views

Other Jobs from Meredith

Senior Software Engineer, I

Remote Edmonton, Canada

Senior Software Engineer, II

New York, NY Seattle, WA

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 401 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • Salaries for the engineering jobs on our site range from $100K-$200K. On average, senior engineer positions on our EchoJobs are about $160K.
  • The EchoJobs positions have been sourced and vetted from the top companies to work for in the US as a software engineer, including LinkedIn and other reputable job sites. We also have syndicated jobs from companies that have just raised funding, as well as those that have great unique products and culture. From all of these sources, our founder, Morgan, has also resourced the company's authenticity in terms of their website, public appearance, and more.
  • Yes, our users asked us for just this, so now our search filters allow you to search for your top jobs via location, as well as by onsite, remote, or both. Approximately 30% of our jobs are remote, so you’ve got the best options for you!
  • We have not yet implemented this option, but are considering doing so in the future. For the moment, you would need to cancel your subscription, and resubscribe when you wanted to come back.
  • We add new jobs to EchoJobs every day! We scan our sources for the newest jobs, verify them, and post them to EchoJobs within minutes. We add about 2,000-3,000 new jobs for you each day!
  • From starting your job search to getting hired, the entire job search process can take us software engineers anywhere between 3-6 months. However, at EchoJobs, we’re striving to shorten this duration by finding the best, newest jobs for you, so you can do less job searching, and more applying.
  • We’d recommend checking EchoJobs daily, as we add new jobs to the site each day. Additionally, if you got a chance to read our previous email on “what makes EchoJobs different from any other job search tools,” we also recommended that you set a job alert based on your job filters, so if you get emails on those new jobs, you could be checking more than once per day.
  • If you decide to continue with us after the 1-month trial, we definitely recommend this, as we all know it usually takes 3-6 months to find a quality job as a software engineer these days. So to best support you, we just adjusted our membership options at EchoJobs to monthly, 3 months, or 12 months (this option is more for passive job seekers looking a little bit for the future if they want to come back to work or make a job switch potentially. This lets you see what’s out there in case an even better fit job becomes available.)
  • EchoJobs is truly the only job site of its kind. We want to be THE spot for you to find the best job for you, and haven’t encountered any other company doing this. Other job sites are in niches besides software engineering or focus on a small portion of engineering jobs (like a specific coding language). In the words of Morgan, our founder, “I think what makes EchoJobs different is the amount of jobs, frequency that we add new jobs (we add 2,000-3,000 new jobs daily!), and the powerful search engines to find exactly the job you want more easily and efficiently. We can provide you with the most jobs that are vetted by us, we’ll continually find more new jobs for you, and we make it easier for you to apply and get hired.

What Fellow Engineers Say