Application Security Engineer - Assistant Vice President
State Street CorporationMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessTier-1 brand and metro location increase candidate density, but senior specialized AppSec reduces competition.
High — deep AppSec and DevSecOps expertise typically tied to regulated financial domain requirements.
High — explicit 12–15 years, mandatory AppSec tooling experience and certifications in regulated environment.
Job Description
Structured overview of role & requirementsAbout This Role
Lead integration of Application Security and DevSecOps strategies within agile software development environments.
Partner with engineering and application teams to implement security tools, manage security vulnerabilities such as those from GenAI model scans, and support audit processes.
Develop, maintain, and improve security-related documentation, dashboards, metrics, and processes aligned with project objectives and organizational security goals.
Minimum Requirements
12 to 15 years of relevant experience in application security, software development, and SDLC.
Bachelor’s degree in IT, computer science, or related field.
Extensive experience with SAST, DAST, SCA, container security scanning, and DevSecOps tooling in CI/CD pipelines.
Work Location: Hybrid with requirement to work from base office 4 days/week; flexible hours to support global stakeholders.
Ideal Candidate Profile
Hands-on experience in programming languages such as Java, .Net, Python, Node.js and working with cloud platforms like Azure and AWS.
Proven expertise in automating security processes using tools like Ansible, Terraform, Kubernetes, and knowledge of Infrastructure as Code (IaC).
Certified Information Systems Security Professional (CISSP) or equivalent cybersecurity certifications with experience in Agile, Scrum, and influencing engineering teams to adopt security best practices.
