This job offer is no longer available
Application Security Architect
WEX
- Portland, Oregon, United States
- Portland, Oregon, United States
About
A highly motivated security architect who loves working on small, high‑performing teams that interface with the entire enterprise A collaborative, solid communicator who works well with your team and stakeholders to drive projects from inception to completion Someone who cares deeply for team results but is able to work independently to deliver high quality solutions for projects and operational tasks Comfortable balancing the need to move fast with the realities of working in a highly regulated organization Passionate about security, but pragmatic about delivering business value Customer focused – whether it's internal teams that we're supporting or the WEX partner, you prioritize ensuring they have a great experience with WEX and our team A skilled worker that has the motivation, expertise, and work ethic to operate independently across global time zones, and who is able to complete tasks and deliverables with minimal oversight A leader who builds consensus and drives change through buy‑in and education rather than mandates Work closely with development teams on securing Wex’s applications Able to mentor other engineers & architects on your team and other teams both technically and professionally Champion of a shift‑left and DevSecOps approach to security, but tenacious enough to build such a program from the ground up A lifelong learner that is excited by new technologies and challenges
Technically, you
Are a Subject Matter Expert in software development and software security, particularly with web applications, APIs, mobile apps and enterprise applications delivered in a SaaS model Perform manual and automated secure code reviews, assisted with commercial static and dynamic application security scanning tools (SAST, DAST, SCA, etc) Do web application and mobile app penetration testing Deliver actionable security guidance to project teams Analyze security assessments and effectively communicate requirements to appropriate software development, network and configuration management teams Actively participate in Security Development Lifecycle efforts such as performing secure architecture reviews, secure code reviews, threat models and penetration testing through the software development lifecycle Keep abreast of security industry best practices and OWASP recommendations utilizing knowledge to contribute to remediation efforts across the platform, as well as security policies and procedures Identify and partner with security champions in the development organization to scale security expertise and awareness Write comprehensive reports including assessment‑based findings, outcomes and recommendations for security enhancement Deep experience working with compliance and regulatory frameworks such as PCI‑DSS, HIPAA/HITRUST, SOX, GDPR, NIST, etc.
At a minimum, you
Have 3‑5+ years of progressive experience in software development. C#, Java, Go or Python preferred Have 3+ years experience with software security or information security Have 2+ years experience with application and container security tools such as SAST, DAST, SCA, IaC scanning and container image scanning, including integrating them into build and ticketing tools Are very familiar with common application security issues, i.e., OWASP Top10, and appropriate mitigation strategies Are able to troubleshoot security issues within a complex on‑prem and multi‑cloud environment A degree in Business, Computer Science or equivalent combination of education and relevant experience Have experience working closely with many teams across departmental and business unit boundaries Can commit and deliver on very specific project/delivery timelines with minimal supervision Have excellent communication skills, both written and verbal
It would be nice if you have
Security certifications such as CEH, OSCP, GWAPT or similar and cloud certifications Have an understanding of modern CI/CD approaches and tooling, preferably with multiple toolsets such as Azure DevOps, GitHub Actions, Jenkins and others Experience with designing and securing container technologies - Kubernetes, Docker, EKS, ECS, AKS, service mesh 3+ years of cloud‑hosted applications and public cloud experience (IaaS, PaaS, FaaS, SaaS) Experience working on agile teams
Benefits include health, dental and vision insurance, retirement savings plan, paid time off, health savings account, flexible spending accounts, life insurance, disability insurance, tuition reimbursement, and more. WEX’s comprehensive and market‑competitive benefits are designed to support your personal and professional well‑being. Pay Range: $109,300.00 - $133,000.00 #J-18808-Ljbffr
Languages
- English
Notice for Users
This job was posted by one of our partners. You can view the original job source here.