Application Security Engineer
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• Knowledge in information security policies, continuous integration/continuous delivery pipeline scripting languages. • Experience with Security Tool deployment automation using various scripting languages and open-source solutions. • Understanding of Security-as-Code principles to build templates for identifying and mitigating vulnerabilities. • Ability to analyze system modifications, upgrades, downtime interfaces, and integrate new commercial off-the-shelf software into the existing environment while maintaining compliance with MeridianLink policies. • Skill in following monitoring, auditing, and reporting frameworks that support security needs. • Experience working on problems of moderate scope requiring analysis of varied situations or data involving multiple factors (implied experience). • Ability to determine appropriate action based on guidelines while modifying processes as required (implied ability/skill). • Capability to exercise judgment within defined procedures and practices for problem resolution.
Responsibilities
• Support application security initiatives while collaborating with senior application security engineers and other security team members as needed. • Participate in application security reviews and threat modeling activities, including code review and static and dynamic testing. • Interpret business and technical requirements to support the design and development of secure applications and infrastructure. • Design and implement application security solutions that enforce consistent security controls across applications and products. • Conduct assessments of cloud, network, and data services supporting MeridianLink’s products. • Design, build, test, document, deploy, monitor, and support application security and security operations tooling. • Automate security testing and vulnerability management processes where appropriate. • Proactively identify opportunities to improve security architecture and recommend enhancements to address evolving threats. • Partner with developers to promote secure coding practices and integrate security controls into the SDLC. • Collaborate cross-functionally to implement and support automated static and dynamic testing within CI/CD pipelines. • Serve as the primary security point of contact for development and engineering teams, supporting the remediation of identified risks and vulnerabilities. • Perform automated and manual vulnerability assessments on a recurring basis using industry-standard tools to validate findings across applications, cloud infrastructure, and endpoints. • Review new or proposed applications and provide guidance on secure architecture and design considerations. • Support regulatory and compliance-related initiatives as required. • Act as a subject matter expert in application security, secure coding practices, and penetration testing. • Participate in the internal CSIRT on-call rotation and support incident response activities as needed. • Qualifications: Knowledge, Skills, and Abilities • Bachelor’s degree and 2–4 years of related experience, or equivalent practical experience. • 1+ years of hands-on experience implementing or maintaining CI/CD, security, and data pipelines. • Hands-on experience designing, securing, and delivering cloud-based applications and services in AWS, Azure, or GCP environments. • Strong understanding of application security practices and CI/CD integration, with experience securing cloud infrastructure. • Experience conducting threat modeling and a solid understanding of common application security vulnerabilities (OWASP Top 10, SANS). • Experience performing security design and architecture reviews for new technologies and applications. • Familiarity with SDLC methodologies and experience securing APIs and web services. • Experience using industry-standard application and security testing tools, including Burp Suite, Kali Linux, Metasploit, and WebInspect. • Understanding of infrastructure as code, automation, container security, and orchestration technologies. • Experience with programming or scripting languages such as Python, C#, Java, or PowerShell, and familiarity with modern web technologies. • Experience performing static and dynamic application security testing (SAST/DAST). • Strong knowledge of CI/CD pipelines, including source control, build, and deployment processes. • Experience securing cloud deployments and containerized environments. • Strong analytical and problem-solving skills, with the ability to work across development and security disciplines. • Ability to clearly communicate security concepts to both technical and non-technical stakeholders.
Benefits
• $98.9K – $134.5K • MeridianLink runs a comprehensive background check, credit check, and drug test as part of our offer process. • It is not typical for offers to be made at or near the top of the salary range. The actual salary will be determined based on experience and other job-related factors permitted by law including geographical location. • t is not typical for offers to be made at or near the top of the salary range. • Meridianlink offers: • Insurance coverage (medical, dental, vision, life, and disability) • Flexible paid time off • 401(k) plan with company match • All compensation and benefits are subject to the terms and conditions of the underlying plans or programs, as applicable and as may be amended, terminated, or superseded from time to time. • Upload your resume here to autofill key application fields. • Drop your resume here! • Parsing your resume. Autofilling key fields... • or drag and drop here • If above question is "Other" please add the source below. • I prefer not to answer • Black or African American • Hispanic, Latino, or Spanish origin • Indigenous Peoples, First Nations, Native American, or Alaska Native • Native Hawaiian or Other Pacific Islander • White / Caucasian • Middle Eastern or North African • Decline to self-identify • Hispanic or Latino - A person of Cuban, Mexican, Puerto Rican, South or Central American, or other Spanish culture or origin regardless of race. • Hispanic or Latino • White (Not Hispanic or Latino) - A person having origins in any of the original peoples of Europe, the Middle East, or North Africa. • White • Black or African American (Not Hispanic or Latino) - A person having origins in any of the black racial groups of Africa. • Native Hawaiian or Other Pacific Islander (Not Hispanic or Latino) - A person having origins in any of the peoples of Hawaii, Guam, Samoa, or other Pacific Islands. • Asian (Not Hispanic or Latino) - A person having origins in any of the original peoples of the Far East, Southeast Asia, or the Indian Subcontinent, including, for example, Cambodia, China, India, Japan, Korea, Malaysia, Pakistan, the Philippine Islands, Thailand, and Vietnam. • Asian • American Indian or Alaska Native (Not Hispanic or Latino) - A person having origins in any of the original peoples of North and South America (including Central America), and who maintain tribal affiliation or community attachment. • American Indian or Alaska Native • Two or More Races (Not Hispanic or Latino) - All persons who identify with more than one of the above five races. • Two or More Races • Hispanic or Latino • White (Not Hispanic or Latino) • Black or African American (Not Hispanic or Latino) • Native Hawaiian or Other Pacific Islander (Not Hispanic or Latino) • Asian (Not Hispanic or Latino) • American Indian or Alaska Native (Not Hispanic or Latino) • Two or More Races (Not Hispanic or Latino) • I identify as one or more of the classifications of protected veteran listed above • I am not a protected veteran