Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Associate, Application Security Engineer image - Rise Careers
Job details

Principal Associate, Application Security Engineer - job 1 of 2

Position: Application Security Engineer This is a contract to hire 6 to 12 month conversion. This requirement is a hybrid position that requires 5 days per month onsite in Albany, NY Education: Bachelor's degree in Computer Science, or related technical field, OR equivalent combination of education and experience Required Experience : § 8+ years Information Technology. § 5+ years in software development role as a Developer, or Architect § Java/Web development with strong secure coding background in RHEL and JBoss. § 3+years with Application Security Engineering conducting assessments, penetration testing, implementing tools for dynamic /automated code review, dynamic and static application scanning (Fortify, SonarQube); consulting on security designs of applications, potential vulnerabilities, and remediation, and creating training materials on key security concepts. Skills : § Strong oral and written communication skills, with a demonstrated ability to communicate complex topics to colleagues, and management. § Demonstrated collaboration and teaching abilities. § Strong analytical skills. § Identify and resolve problems in a timely manner; gather and analyze information skillfully; develop alternative solutions. § Critical thinking and creative problem solving Plus: CISSP, CEH, CISA, OSCP, OSCE, or OSWE Certifications
Capital One Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Capital One DE&I Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Capital One
Capital One CEO photo
Richard D. Fairbank
Approve of CEO

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Associate, Application Security Engineer, Capital One

Are you ready to take your career to the next level as a Principal Associate, Application Security Engineer at an innovative company in Newport News, VA? This exciting opportunity involves working in a hybrid role that has you on-site just five days a month in beautiful Albany, NY. We're seeking experienced professionals who possess a Bachelor's degree in Computer Science or a related technical field, or who have a qualified equivalent. Bring your 8+ years of Information Technology experience and at least 5 years in software development, architecture, or both, where you'll showcase your expertise in Java/Web development and secure coding practices. Your in-depth experience with Application Security Engineering will be crucial as you conduct assessments, penetration testing, and implement tools like Fortify and SonarQube. You'll also play a key role in consulting on security designs for applications, identifying potential vulnerabilities, and devising effective remediation plans. Strong communication skills are vital, enabling you to present complex topics to diverse audiences and work collaboratively with your team. If you hold certifications like CISSP, CEH, or OSCP, that’s a great bonus! This position is not just about technical prowess; it's about nurturing a culture of security design and awareness throughout our organization. Join us in creating secure, robust applications that stand out in the industry!

Frequently Asked Questions (FAQs) for Principal Associate, Application Security Engineer Role at Capital One
What are the responsibilities of the Principal Associate, Application Security Engineer at our company?

As a Principal Associate, Application Security Engineer, your primary responsibilities will include conducting security assessments, penetration testing for various applications, and implementing tools for automated code reviews. You will also consult on application security designs, identify vulnerabilities, and create comprehensive training materials on security practices.

Join Rise to see the full answer
What qualifications do I need to apply for the Principal Associate, Application Security Engineer position?

To apply for the Principal Associate, Application Security Engineer role, candidates should have a Bachelor's degree in Computer Science or a related field, or an equivalent combination of education and experience. Additionally, 8+ years in Information Technology and 5+ years in a software development role are essential, along with specific experience in application security engineering.

Join Rise to see the full answer
Is experience in Java/Web development required for the Principal Associate, Application Security Engineer role?

Yes, for the Principal Associate, Application Security Engineer position, a strong background in Java/Web development is required. Candidates should demonstrate secure coding practices in RHEL and JBoss environments to ensure they effectively contribute to our application security initiatives.

Join Rise to see the full answer
What tools should I be familiar with as a Principal Associate, Application Security Engineer?

Familiarity with tools such as Fortify, SonarQube, and other dynamic/static application scanning tools is essential for the Principal Associate, Application Security Engineer role. These tools will help you conduct effective assessments and implement necessary security measures.

Join Rise to see the full answer
Are there any preferred certifications for the Principal Associate, Application Security Engineer position?

Yes, preferred certifications for the Principal Associate, Application Security Engineer position include CISSP, CEH, CISA, OSCP, OSCE, or OSWE. These certifications will enhance your credentials and indicate your commitment to the field of application security.

Join Rise to see the full answer
Common Interview Questions for Principal Associate, Application Security Engineer
Can you describe your experience with conducting penetration testing?

When answering this question, focus on specific examples of past penetration tests you've conducted. Highlight tools you used, the types of applications you assessed, and how your findings were implemented to improve security measures.

Join Rise to see the full answer
How do you stay updated on security vulnerabilities and best practices?

Candidates should discuss their commitment to continuous learning in the security field, mentioning resources such as security blogs, webinars, professional groups, and certifications that keep them informed about the latest threats and solutions.

Join Rise to see the full answer
What steps would you take to assess an application's security design?

Outline a systematic approach, including reviewing architecture diagrams, evaluating control measures, conducting threat modeling, and identifying potential vulnerabilities while considering the application's use case and deployment environment.

Join Rise to see the full answer
Describe a situation where you had to communicate complex security concepts to a non-technical audience.

Share a specific incident where you successfully conveyed technical information to non-technical stakeholders. Emphasize your ability to simplify concepts and how this ensured everyone understood the importance of security measures.

Join Rise to see the full answer
What methodologies do you utilize for secure coding practices?

Explain methodologies such as OWASP guidelines, secure coding standards, and any practices specific to the programming languages you’ve worked with. Highlight how you integrate these into your development workflow.

Join Rise to see the full answer
How do you prioritize security issues when you find multiple vulnerabilities?

Discuss the criteria you use for prioritizing vulnerabilities, such as impact assessment, exploitability, and relevance to the business context. This showcases your analytical skills and understanding of risk management.

Join Rise to see the full answer
What tools and environments do you prefer for performing application security testing?

Mention the tools you are experienced with, like Fortify and SonarQube, and any testing environments or setups you've used to execute application security assessments effectively.

Join Rise to see the full answer
Have you ever developed security training materials? If so, can you provide feedback on that process?

Describe your process for creating security training materials, the audience you aimed for, and the impact of the training on staff awareness or application security practices.

Join Rise to see the full answer
What is your approach to collaborating with development teams for security integration?

Emphasize your belief in communication and partnership when collaborating with development teams. Highlight specific strategies you employ to ensure that security is ingrained throughout the development lifecycle.

Join Rise to see the full answer
Can you provide an example of a significant security issue you successfully remediated?

Share a detailed story of a severe security issue, including the context, your assessment and analysis, the remediation steps you took, and the results that followed. This shows your critical thinking in real-world applications.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Youlend Hybrid No location specified
Posted 14 days ago
Photo of the Rise User
Mattel Hybrid 333 Continental Blvd, El Segundo, CALIFORNIA
Posted 20 hours ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Photo of the Rise User
Surfshark Remote No location specified
Posted 9 days ago

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran

808 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Contract, hybrid
DATE POSTED
December 8, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!