Application Security Engineer (Hybrid - US)
Energy SolutionsAbout the role
Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus on the big impacts. And we believe that market-based programs can be a powerful force to deliver large-scale energy, carbon, and water-use savings. Since 1995, we’ve harnessed that power to offer proven, performance-based solutions for our utility, government, and institutional customers.
Description:
The Application Security Engineer will be hands on performing day to day application security and compliance activities. In performing this task, the Application Security Engineer will be expected to collaborate and build partnerships with multiple business units within our company. Professionalism and high ethical standards are expected.
Responsibilities:
- Manage security related tasks in the SDLC to ensure that software development activities remain in compliance.
- Responsible for interpreting, justifying, explaining, reviewing, etc. compliance related changes and requirements to our code base leads
- Collaborate with software developers and code base leads
- Be the bridge between the technical requirements from the business (ie. Security, Privacy, Compliance)
- Participate as a SME in security architecture including new designs and design review
- Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks
- Actively review architecture and compliance-related code changes
- Manage and maintain API Security including vulnerability scans and best practices
- Manage security components of the Mendix web development platform
- Manage security components in Django
- Manage scans and findings from Static Code Analysis tools such as GitHub Advanced Security
- Train and educate IS staff on security best practices including OWASP Top 10
- Ensure compliance with policies and standards such as secure separation of environment
- Manage and maintain all security related tickets, including recommendations, testing and validation
Security Compliance (SOC 2 and NIST 800-53 control implementation and maintenance)
- Scan and Remediate vulnerabilities
- Monitor and maintain compliance with SOC 2, NIST 800-53 and other required frameworks
- Security representative for Configuration Change Control
- Verification of implemented security controls
- Standards, Processes and Tools for Security compliance
- Criticality Analysis and Impact Analysis of security related changes
- SIEM - Ongoing security monitoring including Datadog, application logs, CloudWatch and other systems
AWS
- Manage and maintain security in AWS Security including IAM policies, permissions, security groups and security monitoring
- Maintain Web Application Firewall and associated rules to protect applications and systems
- Manage and monitor Database Security (RDS, Postgres, Redshift) including reviewing logs and validating permissions and making security recommendation.
Minimum Qualifications:
- Minimum 3 years of hands-on
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Field Applications Engineering (FAE) Technician
Advanced Energy
ITSM Application Administration/Configuration Analyst - Remote (2695)
PSI Pax, Inc.
Information Systems Application Analyst III/SR- Ambulatory
Lake Charles Memorial Health System