Lead Application Security Specialist

hace 2 meses


Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

About the Position

As a Senior Application Security Engineer, your responsibilities will include: Collaborating with various teams throughout the organization to promote a security-oriented engineering culture and make security accessible to all. Serving as a subject matter expert on cross-functional security initiatives, overseeing areas such as CI/CD integration, automation, SAST/DAST/SCA security, API security, and vulnerability management. Facilitating threat modeling sessions and leading secure remediation planning discussions with application development teams. Assisting in the development and scaling of our Software Supply Chain Security efforts. Contributing to the creation and automation of security tools, along with actionable metrics to enhance our Secure Software Development Life Cycle (S-SDLC). Developing and maintaining PowerBI applications and metrics, as well as providing security guidance and documentation.

About You
To excel in the role of Senior Application Security Engineer, you should possess:

A minimum of 4 years of extensive application security experience. Proven scripting skills and the ability to create solutions for remote APIs, with preferred languages/tools including Bash, Python, GoLang, and Postman. A comprehensive understanding of common security vulnerabilities and risks, along with appropriate countermeasures and compensating controls. Experience with SAST, DAST, and SCA scanning tools (e.g., Veracode, Checkmarx, Semgrep) and the capability to assist developers in identifying and prioritizing genuine threats. Expertise in constructing secure CI/CD pipelines, preferably using GitHub Actions, with a focus on an as-code approach for security teams. Knowledge of application and cloud security frameworks such as OWASP, CIS, and NIST CSF/SSDF. Familiarity with OWASP SAMM or BSIMM is advantageous. A track record of successful collaboration with various product development teams to embed security practices. Experience with Snyk.

What We Offer
Joining our organization means becoming part of a culture that values talent and is dedicated to your personal and professional development through:

Flexible Work Environment: We embrace a hybrid working model that allows for both in-office and remote work, ensuring a connected experience.
Inclusive Culture: We are recognized globally for our commitment to equality, diversity, and inclusion, along with a strong focus on work-life balance.
Wellbeing Initiatives: Comprehensive benefits including flexible plans for work-life balance, mental health days, and resources for overall wellbeing.
Learning Opportunities: Access to LinkedIn Learning and internal projects to foster growth and development.
Social Responsibility: Participation in employee-driven resource groups and initiatives aimed at making a positive impact locally and globally.
Meaningful Work: We are proud to support our clients in their pursuit of justice, truth, and transparency, contributing to a better society.

Accessibility Commitment

As a global entity, we value diverse perspectives and strive to create an inclusive environment where all qualified individuals can thrive, regardless of their background.



  • Ciudad de México, Ciudad de México Solera A tiempo completo

    About the RoleThe Application Security Specialist will work as a member of the Application Security Team to pentest APIs, Web Apps, Mobile Apps and Web Services. This role requires collaboration with the Dev Team to remediate security vulnerabilities.Key ResponsibilitiesConduct vulnerability assessmentsPerform penetration testing to identify weaknesses and...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the Position As a Senior Application Security Engineer, your responsibilities will include: Collaborating with various teams throughout the organization to promote a security-focused engineering culture and make security accessible to all. Serving as a subject matter expert on our cross-departmental security initiatives, taking full ownership of areas...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Position Overview As a Senior Application Security Engineer, your responsibilities will include: Collaborating with various teams throughout the organization to cultivate a security-focused engineering culture and make security accessible to all. Serving as a subject matter expert on cross-functional security initiatives, overseeing critical areas...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Application Security Engineer to join our team at Thomson Reuters. As a key member of our security team, you will play a critical role in ensuring the security and integrity of our applications and systems.Key ResponsibilitiesCollaborate with cross-functional teams to identify and mitigate security risks...

  • Security Specialist

    hace 2 semanas


    Ciudad de México, Ciudad de México Bishop Fox A tiempo completo

    About the RoleWe're seeking a highly skilled Security Specialist - Application Penetration Tester to join our team at Bishop Fox. As a leading authority in offensive security, we provide innovative solutions for clients across various industries.ResponsibilitiesTest web applications and networks to identify vulnerabilitiesReversing software and developing...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Application Security Engineer to join our team at Thomson Reuters. As a key member of our security team, you will play a critical role in ensuring the security and integrity of our applications and systems.Key ResponsibilitiesCollaborate with cross-functional teams to identify and mitigate security risks...


  • Ciudad de México, Ciudad de México solera A tiempo completo

    About SoleraSolera is a global leader in data and software services that strives to transform every touchpoint of the vehicle lifecycle into a connected digital experience. In addition, we provide products and services to protect life's other most important assets: our homes and digital identities. Today, Solera processes over 300 million digital...


  • Ciudad de México, Ciudad de México PepsiCo Deutschland GmbH A tiempo completo

    Secure the Future of Applications at PepsiCoPepsiCo Deutschland GmbH is at the forefront of integrating automated security testing into our CI/CD pipelines and ensuring continuous monitoring to identify and manage security risks. As an Application Security Engineer, you will be responsible for driving the integration of these automated security tools into...

  • Security Specialist

    hace 17 horas


    Ciudad de México, Ciudad de México MX003 Marsh And Mclennan Servicios S.A. De Cv A tiempo completo

    About the RoleMX003 Marsh And Mclennan Servicios S.A. De Cv is seeking a highly skilled Security Specialist to join our team in Mexico City. As a Security Specialist, you will play a key role in ensuring the security and integrity of our applications and systems.Key ResponsibilitiesAct as a security advisor to various teams across the organization.Develop...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleAs a Senior Application Security Engineer at Thomson Reuters, you will be responsible for fostering our engineering-centric security culture and bringing palatable security to the masses. You will work closely with teams across multiple functions across the organization to instill security in our products and services.Key ResponsibilitiesBe a...


  • Ciudad de México, Ciudad de México Sequoia Connect A tiempo completo

    Job Title: Security Governance SpecialistSequoia Connect is seeking a highly skilled Security Governance Specialist to join their team. As a key member of the organization, you will be responsible for coordinating audit and assessment processes, developing and maintaining security policies and procedures, and conducting security training and awareness...


  • Naucalpan de Juárez, México Zurich Insurance Company A tiempo completo

    Zurich Insurance Company is seeking a skilled professional to fill the role of Application Security Specialist.This position is responsible for administering the Security Testing automated scanning tools, providing global support to Zurich IT projects, and enabling them to perform SAST, DAST, and IAST toolset management.The ideal candidate will have...

  • Security Specialist

    hace 4 semanas


    Ciudad de México, Ciudad de México Abb A tiempo completo

    Job Title: Security SpecialistAbout the Role:We are seeking a highly skilled Security Specialist to join our team at ABB. As a Security Specialist, you will be responsible for managing ABB security programs for the assigned area of responsibility, providing risk-appropriate security advice and guidance, and monitoring the implementation of security...


  • Naucalpan de Juárez, México Zurich Insurance Company A tiempo completo

    Zurich Insurance Company is seeking a skilled Application Security Specialist to join our team.The ideal candidate will have expertise in application security toolset administration, providing global support to Zurich IT projects and enabling them to perform SAST, DAST, and IAST toolset management.Key Responsibilities:Administrate Security Testing automated...


  • Ciudad de México, Ciudad de México Kal A tiempo completo

    Job Title: Windows Security SpecialistAbout the Role:We are seeking a skilled Windows Security Specialist to join our team at Kal in Mexico City. The ideal candidate will have a strong background in developing software solutions for Windows systems, with a focus on security and system hardening.Key Responsibilities:* Develop and implement software solutions...

  • Cloud Security Specialist

    hace 3 semanas


    Ciudad de México, Ciudad de México Thales A tiempo completo

    Cloud Security SpecialistAt Thales, we're committed to creating a safer world by providing innovative solutions to our customers. As a Cloud Security Specialist, you'll play a critical role in helping us achieve this goal. Key ResponsibilitiesProvide comprehensive security services to our customers, including proactive monitoring, configuration, and...


  • Ecatepec de Morelos, México Hedera Hashgraph, Llc A tiempo completo

    Job Title: Application Security SpecialistAvery Dennison Corporation is a global materials science and digital identification solutions company that provides a wide range of branding and information solutions. We are seeking an experienced Application Security Specialist to join our IT team.Job Summary:We are looking for a skilled Application Security...

  • Security Engineer

    hace 1 semana


    Ciudad de México, Ciudad de México Udemy A tiempo completo

    About the RoleAs an Application Security Engineer at Udemy, you will be responsible for ensuring the security of our software development processes. You will collaborate closely with development teams to implement security practices that enable teams to build secure applications from the ground up.Your Key ResponsibilitiesCollaborate with development teams...


  • Ciudad de México, Ciudad de México Amazon Web Services Mexico S. de R.L. de C.V. A tiempo completo

    About the RoleWe are seeking a highly motivated and experienced Security Sales Specialist to join our team at Amazon Web Services Mexico S. de R.L. de C.V. in Mexico City, DIF, MEX. As a Security Sales Specialist, you will be responsible for promoting AWS's native security services portfolio and partner security solutions featured on AWS Marketplace to large...

  • Security Consultant

    hace 3 semanas


    Ciudad de México, Ciudad de México Sequoia Connect A tiempo completo

    Job Title: Security Consultant - Cloud and Application ExpertSequoia Connect is seeking a highly skilled Security Consultant to join our team. As a Security Consultant, you will be responsible for leading security reviews for cloud-based systems, applying secure engineering concepts, and identifying and mitigating vulnerabilities in applications, cloud, and...