Lead Application Security Specialist

hace 2 meses


Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

About the Position

As a Senior Application Security Engineer, your responsibilities will include: Collaborating with various teams throughout the organization to promote a security-focused engineering culture and make security accessible to all. Serving as a subject matter expert on our cross-departmental security initiatives, taking full ownership of areas such as CI/CD integration, automation, SAST/DAST/SCA security, API security, and vulnerability management programs. Facilitating threat modeling sessions and leading secure remediation planning discussions with application development teams. Contributing to the development and enhancement of our Software Supply Chain Security initiatives. Assisting in the creation and automation of security tools, along with developing actionable metrics to improve TR's Secure Software Development Life Cycle (S-SDLC). Developing and maintaining PowerBI applications and metrics, as well as providing security guidance and documentation.

About You
To be a suitable candidate for the Senior Application Security Engineer role, you should possess:

A minimum of 4 years of substantial experience in application security. Proven scripting skills with the ability to create solutions that interact with remote APIs. (Preferred languages/tools include Bash, Python, GoLang, Postman). A comprehensive understanding of common security vulnerabilities and risks, along with effective countermeasures and compensating controls. Experience with SAST, DAST, and SCA scanning tools (such as Veracode, Checkmarx, Semgrep, etc.) and the capability to assist developers in prioritizing genuine threats. Expertise in constructing secure CI/CD pipelines (preferably using GitHub Actions) and promoting an as-code approach within security teams. Familiarity with application and cloud security frameworks, including OWASP, CIS, and NIST CSF/SSDF. Experience with OWASP SAMM or BSIMM is advantageous. A track record of successful collaboration with various product development teams to instill security practices. Experience with Snyk.

What We Offer
By joining us, you will be part of a culture that values world-class talent and is dedicated to your personal and professional development through:

Hybrid Work Model: A flexible hybrid working environment that ensures a seamless digital and physical connection.
Culture: A globally recognized reputation for equality, diversity, and inclusion, along with a strong emphasis on work-life balance.
Wellbeing: Comprehensive benefits, including flexible plans for work-life balance, mental health days, and resources for overall wellbeing.
Learning & Development: Access to LinkedIn Learning and opportunities for cross-company projects.
Social Impact: Participation in employee-driven initiatives and paid volunteer days.
Purpose-Driven Work: A commitment to helping customers pursue justice, truth, and transparency, making a meaningful impact in society.

Accessibility

As a global organization, we value diversity in culture and thought, seeking talented individuals from all backgrounds to achieve our goals.



  • Ciudad de México, Ciudad de México Solera A tiempo completo

    About the RoleThe Application Security Specialist will work as a member of the Application Security Team to pentest APIs, Web Apps, Mobile Apps and Web Services. This role requires collaboration with the Dev Team to remediate security vulnerabilities.Key ResponsibilitiesConduct vulnerability assessmentsPerform penetration testing to identify weaknesses and...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the Position As a Senior Application Security Engineer, your responsibilities will include: Collaborating with various teams throughout the organization to promote a security-oriented engineering culture and make security accessible to all. Serving as a subject matter expert on cross-functional security initiatives, overseeing areas such as CI/CD...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Position Overview As a Senior Application Security Engineer, your responsibilities will include: Collaborating with various teams throughout the organization to cultivate a security-focused engineering culture and make security accessible to all. Serving as a subject matter expert on cross-functional security initiatives, overseeing critical areas...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Application Security Engineer to join our team at Thomson Reuters. As a key member of our security team, you will play a critical role in ensuring the security and integrity of our applications and systems.Key ResponsibilitiesCollaborate with cross-functional teams to identify and mitigate security risks...

  • Security Specialist

    hace 2 semanas


    Ciudad de México, Ciudad de México Bishop Fox A tiempo completo

    About the RoleWe're seeking a highly skilled Security Specialist - Application Penetration Tester to join our team at Bishop Fox. As a leading authority in offensive security, we provide innovative solutions for clients across various industries.ResponsibilitiesTest web applications and networks to identify vulnerabilitiesReversing software and developing...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Application Security Engineer to join our team at Thomson Reuters. As a key member of our security team, you will play a critical role in ensuring the security and integrity of our applications and systems.Key ResponsibilitiesCollaborate with cross-functional teams to identify and mitigate security risks...


  • Ciudad de México, Ciudad de México solera A tiempo completo

    About SoleraSolera is a global leader in data and software services that strives to transform every touchpoint of the vehicle lifecycle into a connected digital experience. In addition, we provide products and services to protect life's other most important assets: our homes and digital identities. Today, Solera processes over 300 million digital...


  • Ciudad de México, Ciudad de México PepsiCo Deutschland GmbH A tiempo completo

    Secure the Future of Applications at PepsiCoPepsiCo Deutschland GmbH is at the forefront of integrating automated security testing into our CI/CD pipelines and ensuring continuous monitoring to identify and manage security risks. As an Application Security Engineer, you will be responsible for driving the integration of these automated security tools into...

  • Security Specialist

    hace 17 horas


    Ciudad de México, Ciudad de México MX003 Marsh And Mclennan Servicios S.A. De Cv A tiempo completo

    About the RoleMX003 Marsh And Mclennan Servicios S.A. De Cv is seeking a highly skilled Security Specialist to join our team in Mexico City. As a Security Specialist, you will play a key role in ensuring the security and integrity of our applications and systems.Key ResponsibilitiesAct as a security advisor to various teams across the organization.Develop...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleAs a Senior Application Security Engineer at Thomson Reuters, you will be responsible for fostering our engineering-centric security culture and bringing palatable security to the masses. You will work closely with teams across multiple functions across the organization to instill security in our products and services.Key ResponsibilitiesBe a...


  • Ciudad de México, Ciudad de México Sequoia Connect A tiempo completo

    Job Title: Security Governance SpecialistSequoia Connect is seeking a highly skilled Security Governance Specialist to join their team. As a key member of the organization, you will be responsible for coordinating audit and assessment processes, developing and maintaining security policies and procedures, and conducting security training and awareness...


  • Naucalpan de Juárez, México Zurich Insurance Company A tiempo completo

    Zurich Insurance Company is seeking a skilled professional to fill the role of Application Security Specialist.This position is responsible for administering the Security Testing automated scanning tools, providing global support to Zurich IT projects, and enabling them to perform SAST, DAST, and IAST toolset management.The ideal candidate will have...

  • Security Specialist

    hace 4 semanas


    Ciudad de México, Ciudad de México Abb A tiempo completo

    Job Title: Security SpecialistAbout the Role:We are seeking a highly skilled Security Specialist to join our team at ABB. As a Security Specialist, you will be responsible for managing ABB security programs for the assigned area of responsibility, providing risk-appropriate security advice and guidance, and monitoring the implementation of security...


  • Naucalpan de Juárez, México Zurich Insurance Company A tiempo completo

    Zurich Insurance Company is seeking a skilled Application Security Specialist to join our team.The ideal candidate will have expertise in application security toolset administration, providing global support to Zurich IT projects and enabling them to perform SAST, DAST, and IAST toolset management.Key Responsibilities:Administrate Security Testing automated...


  • Ciudad de México, Ciudad de México Kal A tiempo completo

    Job Title: Windows Security SpecialistAbout the Role:We are seeking a skilled Windows Security Specialist to join our team at Kal in Mexico City. The ideal candidate will have a strong background in developing software solutions for Windows systems, with a focus on security and system hardening.Key Responsibilities:* Develop and implement software solutions...

  • Cloud Security Specialist

    hace 3 semanas


    Ciudad de México, Ciudad de México Thales A tiempo completo

    Cloud Security SpecialistAt Thales, we're committed to creating a safer world by providing innovative solutions to our customers. As a Cloud Security Specialist, you'll play a critical role in helping us achieve this goal. Key ResponsibilitiesProvide comprehensive security services to our customers, including proactive monitoring, configuration, and...


  • Ecatepec de Morelos, México Hedera Hashgraph, Llc A tiempo completo

    Job Title: Application Security SpecialistAvery Dennison Corporation is a global materials science and digital identification solutions company that provides a wide range of branding and information solutions. We are seeking an experienced Application Security Specialist to join our IT team.Job Summary:We are looking for a skilled Application Security...

  • Security Engineer

    hace 1 semana


    Ciudad de México, Ciudad de México Udemy A tiempo completo

    About the RoleAs an Application Security Engineer at Udemy, you will be responsible for ensuring the security of our software development processes. You will collaborate closely with development teams to implement security practices that enable teams to build secure applications from the ground up.Your Key ResponsibilitiesCollaborate with development teams...


  • Ciudad de México, Ciudad de México Amazon Web Services Mexico S. de R.L. de C.V. A tiempo completo

    About the RoleWe are seeking a highly motivated and experienced Security Sales Specialist to join our team at Amazon Web Services Mexico S. de R.L. de C.V. in Mexico City, DIF, MEX. As a Security Sales Specialist, you will be responsible for promoting AWS's native security services portfolio and partner security solutions featured on AWS Marketplace to large...

  • Security Consultant

    hace 3 semanas


    Ciudad de México, Ciudad de México Sequoia Connect A tiempo completo

    Job Title: Security Consultant - Cloud and Application ExpertSequoia Connect is seeking a highly skilled Security Consultant to join our team. As a Security Consultant, you will be responsible for leading security reviews for cloud-based systems, applying secure engineering concepts, and identifying and mitigating vulnerabilities in applications, cloud, and...