CookUnity is a unique platform that connects people with great food from top chefs. The Senior Application Security Engineer will lead application security efforts, conduct security assessments, and collaborate with engineering teams to ensure secure coding practices and vulnerability remediation.
Responsibilities:
- Lead application security efforts by performing security assessments, code reviews, and penetration testing focused on applications developed in Kotlin, Java, and TypeScript
- Identify, classify, prioritize, and track remediation of vulnerabilities such as those listed in the OWASP Top 10 and other common weaknesses
- Use and maintain application security tools such as Burp Suite for dynamic testing, SAST/DAST/IAST tools, and other automated security scanners
- Collaborate closely with software development teams to enforce secure coding standards and hold Software Engineers accountable for patching vulnerabilities within defined SLAs
- Integrate security testing and automation into CI/CD pipelines to ensure continuous security validation
- Define and maintain security requirements and best practices aligned with industry standards such as OWASP, NIST, ISO, PCI DSS, and GDPR
- Conduct threat modeling, risk assessments, and security design reviews for new and existing applications
- Promote security awareness and provide training to development teams on secure coding and vulnerability mitigation
- Respond to security incidents and support remediation efforts
- Recommend and implement new security tools and technologies to improve application security posture
- Work in Agile and DevSecOps environments to embed security throughout the software development lifecycle
Requirements:
- Bachelor's degree in Computer Science, Cybersecurity, or related field
- 6-8+ years of experience in application security, secure coding, and vulnerability assessment
- Strong development background with hands-on experience in Kotlin, Java, and Typescript
- Deep understanding of OWASP Top 10, CWE, and common web and API vulnerabilities
- Proficient with security testing tools such as Burp Suite, Fortify, Veracode, or similar
- Experience with secure SDLC, DevSecOps practices, and integrating security into CI/CD pipelines
- Familiarity with authentication and authorization protocols like OAuth2, OIDC, and SAML
- Ability to work effectively with development teams, guiding and holding them accountable for timely vulnerability remediation
- Relevant certifications such as CISSP, CSSLP, OSCP, GWAPT
- Fluency in English
- Knowledge of cloud security (AWS, GCP, Azure) and container security (Docker, Kubernetes) is a plus