





Tier-1 brand, metro location, mid-level generalist role, and broad skill requirements increase applicant competition.
Role requires specialized application security and secure SDLC experience, making cross-industry transferability limited.
Explicit 4+ years requirement plus desired certifications, specific AppSec tool experience, and SDLC expertise indicate strict filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead or participate in security incident response activities, including investigation, digital forensics, and remediation recommendations.
Design, document, test, and maintain security solutions related to networking, cryptography, cloud, authentication, email, applications, and endpoint security.
Contribute to Secure Development Lifecycle Management by designing and managing non-functional security requirements, coding guidelines, WASAPI development, and integrating security tools within SDLC practices.
Minimum 4+ years of Information Security Engineering experience or equivalent through work, training, military, or education.
Experience with Secure Development Lifecycle Management and designing/developing non-functional security requirements (NFRs) — 3+ years desired but not explicitly mandatory.
Ability to work in a hybrid model with expected office presence three days a week.
Knowledge or certification in industry security standards (CISSP, CSSLP, CEH) and experience with application security tools and frameworks (SD Elements, OWASP ESAPI, NIST SSDF).
Experienced in managing complex security incidents with strong investigative and digital forensic skills.
Technical proficiency in application security including secure SDLC programs, security coding standards, WASAPI development, and automation tools integration.
Familiarity with banking/financial services application security, cloud platforms (Azure, Google Cloud), and compliance metrics/reporting.