Jobs and Careers
FI
Senior Application Security Engineer
First AmericanSanta Ana, United Statesfull_timeVerifiedPosted 23 Apr 2025
💰 $182,700/yr
About the role
Who We Are
Join a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for ten consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.What We Do
Job Profile SummaryThe Security Engineer is responsible for providing operational security solutions that would enable the success of IT and business initiatives. Security Engineer interfaces with IT Groups across the company, client managers, business customers, third-parties, vendors, and auditors. The Security Engineer co-designs (along with Security Architect) and operationalizes security solutions that can be effectively delegated to Security Analysts or other support/operations functions. The scope of Security Engineers extends across technical and administrative controls that enable the protection and availability of business and IT systems. The Security Architect is responsible for defining the organizations information security architecture and standards and creating prioritized risk based upon technical security control roadmap. The Security architect will coordinate technical design/review activities and develop secure architectural frameworks, operational guidelines and metrics to support a secure computing environment consistent with the organizations Information security policies, standard and overall strategy security risks for the company.
What You'll Do
- Application Security Strategy: Develop, implement, and maintain a comprehensive application security strategy that aligns with the company's business goals and regulatory requirements, utilizing industry-leading tools.
- Security Assessments: Conduct thorough security assessments, including static and dynamic application security testing (SAST/DAST), penetration testing, and code reviews using tools like Veracode and Burp Suite to identify vulnerabilities in our applications. Collaborate with development teams to remediate identified issues.
- Risk Management: Proactively identify and assess security risks associated with applications and systems. Develop and implement risk mitigation strategies to address identified vulnerabilities, ensuring compliance with frameworks such as OWASP, NIST, and ISO 27001.
- Secure Software Development Lifecycle (SDLC): Integrate security best practices into the software development lifecycle. Provide guidance and training to development teams on secure coding practices, security testing methodologies, and the use of development tools such as GitHub and Jenkins for continuous integration and deployment.
- Incident Response: Lead and coordinate incident response efforts related to application security breaches. Conduct root cause analysis and implement corrective actions to prevent future incidents.
- Security Tools and Technologies: Evaluate, implement, and manage security tools and technologies to enhance the security posture of our applications. Stay updated on the latest security trends, emerging threats, and advancements in security technologies.
- Compliance: Ensure compliance with industry standards, regulatory requirements, and internal security policies, including PCI-DSS and SOC 2. Prepare and maintain documentation to support audits and assessments.
- Collaboration: Work closely with cross-functional teams, including development, operations, and compliance, to ensure security requirements are integrated into all phases of the application lifecycle.
- Mentorship: Provide mentorship and guidance to junior members of the security team. Foster a culture of security awareness and continuous improvement within the organization.
What You'll Bring
Required Education, Experience, Certification/Licensure
- Education: Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
- Experience: Minimum of 8-10 years of experience in application security or a related field, with a proven track record of securing complex applications in a fintech environment.
- Certifications: Relevant certifications such as CISSP, CEH, OSCP, or CSSLP are highly desirable.
- Technical Expertise: In-depth knowledge of application security principle
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s