Jobs and Careers
UN
Senior Application Security Engineer
UnumIrelandfull_timeVerifiedPosted 12 Aug 2025
About the role
Our Story
Unum Technology Centre in Carlow serves as a strategic software development and IT services centre supporting Unum, a leading provider of income protection in the US. Our team of IT professionals build solutions and critical business applications to digitally transform the way we do business.
Key Responsibilities
Secure Software Development & DevSecOps Integration
- Architect and integrate security into CI/CD pipelines using modern automation and guardrails.
- Develop secure frameworks, SDKs, and CI integrations to enable frictionless adoption of security controls.
- Maintain secure coding standards and guidance tailored to our technology stack.
- Collaborate with DevOps and platform teams to enhance container and infrastructure security (Docker, Kubernetes, IaC).
Threat Modeling, Reviews & Remediation
- Lead threat modeling workshops across product and platform teams.
- Identify and assess vulnerabilities using SAST, DAST, SCA, manual code reviews, and penetration testing.
- Promote reusable remediation patterns for code and infrastructure vulnerabilities.
- Leverage threat intelligence to prioritize mitigations based on business risk.
Engineering & Automation
- Build and maintain automation tools for vulnerability triage, mitigation, and reporting.
- Strengthen API security through robust authentication protocols (OAuth 2.0, OpenID Connect, SAML).
- Integrate with API gateways (e.g., Layer7, MuleSoft) to enforce secure communication and tokenization.
- Support secure deployment of microservices and distributed systems using best-in-class tooling.
Security Culture & Enablement
- Mentor engineers and analysts, fostering secure development capabilities across teams.
- Lead internal workshops, onboarding sessions, and lunch-and-learns to promote security awareness.
- Collaborate with Security Champions to build advocacy and threat modeling expertise.
- Create internal documentation, playbooks, and training materials aligned with real-world threats.
Cross-Functional Leadership & Collaboration
- Act as a bridge between Security, Engineering, and Product teams to align on secure architecture and SDLC practices.
- Participate in incident response, forensic analysis, and post-incident remediation.
- Support compliance initiatives (SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR) through technical guidance and documentation.
- Define and track KPIs to measure and improve security maturity across the organization.
Required Qualifications
- 5+ years in application security, software engineering, or a related technical security role.
- Proficient in at least one modern programming language (e.g., Java, C#, Python, JavaScript).
- Experience with security tools: SAST, DAST, SCA, IaC scanners, RASP.
- Strong knowledge of cloud infrastructure (AWS preferred), conta
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s