Senior Application Security Engineer

hace 2 semanas


Ciudad de México, Ciudad de México Avantor A tiempo completo
The Opportunity:Under limited supervision, responsible for the operations of secure and highly available computing platforms, servers, and networks. Install, maintain, upgrade, and continuously improve the company's operating environment. Maintain the ongoing reliability, performance and support of the infrastructure. Deploy the release of new technologies as well as design, install, configure, maintain and perform testing of PC/server operating systems, networks, and related utilities and hardware.

Job Title: Senior Application Security Engineer
Location: Remote
Department: Global Information Security / Information Security Risk Intelligence & Response
Reports To: Senior Manager, IS Risk Intelligence & Response

Key Responsibilities:

  • Lead and conduct comprehensive security assessments of our software applications, identifying vulnerabilities and potential risks in alignment with industry standards like CMMC, PCI, HIPAA, and GDPR

  • Mentor and collaborate with development teams, guiding them to integrate security best practices throughout the software development lifecycle (SDLC).

  • Utilize your extensive background in software development, especially in Java or PHP, to identify and address security vulnerabilities effectively.

  • Design and implement advanced security controls, authentication mechanisms, and encryption techniques to protect sensitive data and ensure compliance with relevant regulations.

  • Leverage operational technology experience to assess and enhance the security of applications in this domain.

  • Stay informed about the evolving threat landscape, security trends, and compliance requirements to continually enhance our application security posture and guide the team accordingly.

  • Provide expert guidance to developers on secure coding practices and work closely with cross-functional teams to ensure the resolution of identified security issues.

  • Collaborate cross-functionally to interpret and implement security measures in accordance with applicable data privacy laws and regulations.

  • Develop and design policies, processes, and procedures to provide guidance to software teams to help build our software more securely.

  • Mentor junior application security team members.

  • Lead initiatives to advance our OWASP SAMM v2 maturity level.

Qualifications:

  • Bachelor's degree in computer science, Information Security, or a related field, or equivalent real-world experience.

  • Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional (CSSLP), or equivalent certifications or trainings are a plus, but not required.

  • 5 or more years of experience in application security, with a proven track record of leading security assessments and projects.

  • 2 or more years in software development or adjacent fields, with expertise in Java, Javascript, Python, etc.

  • In-depth knowledge and understanding of compliance standards such as CMMC, PCI DSS, HIPAA, or GDPR

  • In-depth knowledge of security standards such as ISO 270001, NIST CSF (CyberSecurity Framework), and/or NIST

  • Extensive familiarity with OWASP SAMM v2

  • Familiarity with operational technology security concepts and practical experience in this domain.

  • Ability to identify and mitigate complex security vulnerabilities in web, mobile applications, and/or embedded applications.

  • Excellent understanding of security leading practices, advanced authentication mechanisms, and encryption techniques.

  • Exceptional communication and collaboration skills to effectively lead and collaborate with teams and present security findings to technical and non-technical stakeholders.

  • Proven ability to work independently and as part of a team, with a proactive attitude toward problem-solving.

  • Strong passion for application security and a commitment to staying up-to-date with the latest industry trends.

Disclaimer:
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Avantor is proud to be an equal opportunity employer.

Why Avantor?

Dare to go further in your career. Join our global team of 14,000+ associates whose passion for discovery and determination to overcome challenges relentlessly advances life-changing science.
 
The work we do changes people's lives for the better. It brings new patient treatments and therapies to market, giving a cancer survivor the chance to walk his daughter down the aisle. It enables medical devices that help a little boy hear his mom's voice for the first time. Outcomes such as these create unlimited opportunities for you to contribute your talents, learn new skills and grow your career at Avantor.
 
We are committed to helping you on this journey through our diverse, equitable and inclusive culture which includes learning experiences to support your career growth and success. At Avantor, dare to go further and see how the impact of your contributions set science in motion to create a better world. Apply today

EEO Statement:

We are an Equal Employment/Affirmative Action employer and VEVRAA Federal Contractor. We do not discriminate in hiring on the basis of sex, gender identity, sexual orientation, race, color, religious creed, national origin, physical or mental disability, protected Veteran status, or any other characteristic protected by federal, state/province, or local law.

If you need a reasonable accommodation for any part of the employment process, please contact us by email at  and let us know the nature of your request and your contact information. Requests for accommodation will be considered on a case-by-case basis. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this email address.

For more information about equal employment opportunity protections, please view the Know Your Rights poster.

3rd Party Non-Solicitation Policy:

By submitting candidates without having been formally assigned on and contracted for a specific job requisition by Avantor, or by failing to comply with the Avantor recruitment process, you forfeit any fee on the submitted candidates, regardless of your usual terms and conditions. Avantor works with a preferred supplier list and will take the initiative to engage with recruitment agencies based on its needs and will not be accepting any form of solicitation.



  • Ciudad de México, Ciudad de México TTEC A tiempo completo

    Application Security EngineerBe the spark that brightens days and ignite your career with TTEC's award-winning employment experience. As an Application Security Engineer working remotely in Mexico, you'll be a part of creating and delivering amazing customer experiences while you also #experienceTTEC, an award-winning employment experience and company...


  • Ciudad de México, Ciudad de México Udemy A tiempo completo

    Join Udemy. Helpdefinethe future of learning.Udemy is an AI-powered skills acceleration platform built to help people and teams grow. It's personalized, practical, and focused on real-world impact.Our mission is simple: to transform lives through learning. Your work helps people around the world build skills they can use, whether they're picking up something...


  • Ciudad de México, Ciudad de México McDonald's A tiempo completo

    McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru)....


  • Ciudad de México, Ciudad de México Lyft A tiempo completo

    At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.Lyft connects people to transportation to change the way we live and get around our communities. Lyft's engineering team is growing, and we are looking for Engineers  with a passion in...


  • Ciudad de México, Ciudad de México McDonald's Corporation A tiempo completo

    Company Description McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital...


  • Ciudad de México, Ciudad de México Stefanini Latam A tiempo completo

    DescriptionSé parte de Stefanini En Stefanini somos más de genios, conectados desde 41 países, haciendo lo que les apasiona y co-creando un futuro mejor.Seguro no te quieres quedar fueraResponsibilities We're Hiring Senior Application Packager (Latin America) Remote | USD Salary via Deel | Flexible Allocation (80 hrs/month)We are looking for an...


  • Ciudad de México, Ciudad de México McDonald's Corporation A tiempo completo

    Company Description McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital...


  • Ciudad de México, Ciudad de México McDonald's Corporation A tiempo completo

    Company Description McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital...


  • Ciudad de México, Ciudad de México McDonald's A tiempo completo

    McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru)....


  • Ciudad de México, Ciudad de México Lyft A tiempo completo

    At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.Lyft connects people to transportation to change the way we live and get around our communities. Lyft's engineering team is growing rapidly, and we are looking for Senior Software Engineers...