Senior Application Security Engineer at Hewlett Packard Enterprise
Overview
Lead security initiatives for applications APIs and CI/CD pipelines at HPE. Partner with engineering and DevOps to embed security into the SDLC. Design and implement WAF policies automate scanning and enforce secure API design. Drive secure development practices and mentor teams. Shape security strategy and collaborate with SOC during incidents.
What You'll Do42
- 1Integrate security practices throughout the SDLC in partnership with engineering and DevOps teams
- 2Promote secure coding standards tooling and automation
- 3Design and maintain security controls within CI/CD platforms GitHub Actions Jenkins GitLab Azure DevOps
- 4Ensure software integrity through code signing artifact validation and provenance
- 5Automate SAST DAST SCA and container image scanning in build and release pipelines
- 6Automate AI specific vulnerability scanning for LLM orchestration patterns
- 7Identify and remediate misconfigurations and access control gaps in pipeline environments
- 8Design deploy WAF rules and API security protections
- 9Conduct API risk assessments and promote secure API design patterns
- 10Perform secure code reviews and support automated security testing coverage
- 11Triage prioritize and track vulnerabilities across source code CI/CD pipelines and deployed services
- 12Facilitate threat modeling for applications APIs and delivery pipelines
- 13Expand security automation around API discovery dependency scanning SBOM generation and secrets detection
- 14Mentor engineering teams on secure coding and secure pipeline practices
- 15Support Security Champions program
- 16Act as trusted advisor to product platform engineering and DevOps teams
- 17Translate technical risks into business impact
- 18Partner with SOC/IR teams during software supply chain or pipeline-related security incidents
- 19Assess and guide secure adoption of AI capabilities focusing on data security access controls model input/output handling and preventing misuse
- 20Leverage AI-powered security tools to identify anomalies code risks and pipeline misconfigurations
- 21Secure CI/CD pipelines and source repositories GitHub GitLab Jenkins
- 22Apply supply chain security frameworks SLSA NIST SSDF
- 23Manage secrets signing artifact verification Sigstore Cosign and build integrity
- 24Implement WAF tuning API security and vulnerability remediation
- 25Maintain strong background in application security product security secure software development
- 26Secure secrets management artifact signing and build integrity practices
- 27Proficient in Python Java Go JavaScript/Node.js
- 28Experience with SAST DAST SCA and container scanning tools
- 29Cloud security experience AWS Azure or GCP
- 30Understanding OWASP Top 10 Web API CWE and secure coding practices
- 31Familiarity with OWASP Top 10 for LLM Applications and MITRE ATLAS
- 32Knowledge of runtime protection tools API security platforms RASP container EDR
- 33Experience with GitOps IaC scanning Terraform CloudFormation and policy-as-code
- 34Handle software supply chain or dependency poisoning incidents
- 35Influence developers DevOps engineers and leadership
- 36Solve problems with automation-first mindset
- 37Balance security with delivery velocity
- 38Provide comprehensive benefits supporting physical financial and emotional wellbeing
- 39Invest in career development and knowledge expertise growth
- 40Celebrate varied backgrounds and foster inclusion
- 41Offer flexible work personal needs management
- 42Make bold moves together as a force for good
Requirements17
- 15–8+ years in Application Security Product Security or Secure Software Development
- 2Hands-on experience securing CI/CD pipelines and source repositories GitHub GitLab Jenkins
- 3Knowledge of supply chain security frameworks SLSA NIST SSDF
- 4Experience with secrets management artifact signing Sigstore Cosign and build integrity
- 5Strong background in WAF tuning API security and vulnerability remediation
- 6Proficiency in at least one programming language Python Java Go JavaScriptNode.js
- 7Experience with SAST DAST SCA and container scanning tools
- 8Cloud security experience AWS Azure or GCP
- 9Understanding OWASP Top 10 Web API CWE and secure coding practices
- 10Familiarity with OWASP Top 10 for LLM Applications and MITRE ATLAS
- 11Knowledge of runtime protection tools API security platforms RASP container EDR
- 12Experience with GitOps IaC scanning Terraform CloudFormation and policy-as-code
- 13Handling software supply chain or dependency poisoning incidents
- 14Relevant certifications OSWE CSSLP GPCS GWEB GCSA
- 15Soft skills excellent communication influencing developers DevOps engineers and leadership
- 16Strong problem-solving abilities with automation-first mindset
- 17Collaborative outcome-oriented balancing security with delivery velocity
Salary Insight
$106 - $243k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
ACJobSite
VerifiedSenior Network Security & Cloud Developer at Hewlett Packard Enterprise
Design and develop end-to-end cloud and networking solutions at an HPE office. Lead technical design and implementation while collaborating with cross-functional teams. Drive innovation to deliver secure, scalable applications that transform data into actionable outcomes. This role offers unique exposure to enterprise-grade security and cloud infrastructure.
US00 Agilent Technologies Inc
VerifiedLead SDLC Security Engineering Manager at Agilent Technologies
We seek a Lead SDLC Security Engineering Manager to lead security tooling automation and secure SDLC practices across the Productivity Solutions Division. This role embeds low-friction security controls into developer workflows enabling faster releases with improved confidence and vulnerability management. Impact includes reducing vulnerabilities strengthening secure practices and accelerating developer velocity.
HP
VerifiedSecurity Software Engineer, Windows & C++
Own the security posture of HP's software products, driving integrity and resilience from design to deployment. You'll design, code, and test C++ and C# features for Windows desktop applications, collaborating with a cross-functional R&D team. This role focuses on identifying and mitigating vulnerabilities using secure coding practices and Agile methodologies. You'll impact multiple teams and may lead technical direction, with a clear path to influence product security at scale.
Wells Fargo
VerifiedSenior Information Security Engineer, AppSec & CI/CD
You will own application security engineering for Wells Fargo's enterprise portfolio, designing and automating AppSec processes across SAST, DAST, SCA, and IaC. You will drive technical leadership in tooling integration and rule tuning to boost defect detection precision. Collaborate with cross-functional teams to embed security controls into GitHub, Jenkins, and Harness pipelines. This role stands out for its focus on AI-assisted development security and governance.
Wells Fargo
VerifiedLead Information Security Engineer Wells Fargo
We seek a Lead Information Security Engineer to strengthen integration of AppSec controls across enterprise tools and CI/CD pipelines. You will improve workflow alignment between Security Architecture and Application Security functions. This role drives design and implementation of repeatable scalable automated AppSec processes. You will prioritize frameworks aligned with enterprise risk and business objectives. Transparency and reporting of AppSec processes will be enhanced. Technical leadership in tooling integration automation and process execution is required. Shift-left security strategies will be led while maintaining strong developer experience. Mitigation strategies for application security risks will be provided. Cross-functional governance participation is expected. Collaboration with control management and cybersecurity leadership is essential. Internal and external audit support is needed. Product enhancements and rule fine-tuning for defect identification are managed. Upgrades resilience continuity and compliance with enterprise standards are overseen. A team will be led to achieve objectives.
Bright Vision Technologies
VerifiedApplication Security Engineer Bright Vision Technologies
Lead security integration across software development lifecycles for a remote full-time role at Bright Vision Technologies. Own security practices while collaborating with engineering teams to build resilient applications. Drive measurable risk reduction through proactive threat mitigation and secure coding standards.