Jobs and Careers
PR

Senior Application Security Engineer

PRA Group
US - Remote, United States, United StatesRemotefull_timeVerifiedPosted 10 Mar 2025
💰 $188,000/yr($118,000/yr$188,000/yr)

About the role

We invite you to explore a future with us at PRA Group, a diverse and growing company that has a tangible impact on the global economy.

Position Summary: 

PRA Group is hiring a Senior Application Security Engineer to join the Information Security team. This new role joins the newly created Application Security department, providing an exciting opportunity for an experienced application security professional to make an impact and lead application security initiatives across the enterprise. Reporting to the Associate VP of Application Security, this role requires frequent collaboration with development and project management teams to ensure secure coding and architectural principles are integrated across the SDLC. The person in this role will also provide vulnerability remediation guidance, develop and nurture a partnership model between the Information Security team and Software Development teams, and participate in AppSec activities such as tuning existing toolsets, creating and maintaining a bug bounty program, and managing inventory of software assets.

Experience:

  • We are seeking individuals with at least 3 to 5 years of experience as an Application Security Practitioner as well as 3-5 years of previous experience in software engineering in large-scale production environments  
  • CISSP certification or one that is in progress is preferred
  • Experience with enterprise backend systems written in languages such as .NET/C#, Ruby on Rails, or Java; prefer C#.
  • Experience with git version control 
  • Understanding of the software development peer review, testing, deployment and maintenance phases 
  • Also experience with front end languages and frameworks such as Vue.JS, Blazor, and vanilla JS 
  • Experience working within frameworks and guidelines such as ISO 27001 and the OWASP Top 10  
  • Experience integrating 3rd- party and/or custom security testing solutions into CI/CD pipelines 
  • Experience with tuning and managing security testing tools such as DAST/SAST and SCA 
  • Bachelor’s Degree in Computer Science, Information security OR related professional experience 

Preferred Experience:

  • Proven track record of contributing to the security or software development field, including teaching, speaking, mentoring, volunteering or publishing works 
  • Any experience or interest in Cloud Security, IAC, container security, or AI security 
  • A passion for cross-departmental education and communication 
  • Interest in how security can inform business processes, whether by driving revenue or cutting costs 

Key Responsibilities:

  • Collaborate with software engineering to implement Application Security architecture as designed by the senior leadership of InfoSec and software engineering 
  • Act as security advisor to SWE, which includes triaging security vulnerabilities, illustrating common exploits, assessing reachability from an attacker’s perspective, and assisting with remediation of agreed upon priorities 
  • Provide software quality assurance by completing secure code reviews 
  • Build relationships with software engineers to illustrate the ‘how’ and ‘why’ behind vulnerability remediation strategies
  • Work with security architects and software engineers to review and design security requirements for new software features and the maintenance of current software
  • Participate in security and technology strategic planning to ensure identified risk governance is incorporated into enterprise strategy
  • Oversee the management and operations of Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST) 
  • Work with Risk & Compliance teams on ISO 27000, SOC2, PCI-DSS, SOX, and other audits as needed.
  • Integrates 3rd-party testing solutions into CI/CD pipelines and development cycles
  • Define security guardrails through automated tool policies, SLAs, custom rules, and support of the developer community
  • Support education strategies for software developers through regular lunch and learns, e-learning platforms, and written educational resources 
  • Integrate security tooling into developer toolsets such as IDE plugins 
  • Expertise in API security governance & knowledge of how to build secure APIs
  • Manage potential tools to cover API security such as gateways and automated API security testing to enforce secure development
  • Experience with threat modeling, which includes creating DFDs to analyze security weak points throughout the application’s environment
  • Create and maintain a bug bounty program
  • Excellent communication skills: verbal, written, and presentational
  • Ability to present to various levels of stakeholders on metrics c

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

PRA Group

View company profile →