Why this role now
The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector. The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Vulnerability Remediation
Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs
Work with development squads to explain findings, validate fixes, and confirm remediation
Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs
Secure Development Lifecycle
Define and own the SDLC — security gates and review checkpoints in sprint and release processes
Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output
Embed security requirements into product planning and architecture decisions
Threat Modeling & Secure Design
Threat-model new features and architectural changes before code is written
Review designs for authentication, authorization, data-flow, and cryptographic risk
Produce written threat models that serve as developer guidance and audit evidence
API Security & Secure Code Review
Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention
Conduct or coordinate manual secure code review of security-sensitive components
Lead application penetration-testing cycles — scoping, managing testers, validating findings
Developer Enablement
Build and run a Security Champions program across development squads
Deliver developer security training on OWASP Top 10 and secure-coding patterns
Create runbooks, coding standards, and pattern libraries developers can apply independently
This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time.
Managerial Responsibilities
Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount)