Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Associate, Application Security Engineer image - Rise Careers
Job details

Principal Associate, Application Security Engineer - job 2 of 2

We have an exciting opportunity for an Application Security Engineer to join our expanding team. Under the direction of the Manager of Software Security, this individual is a vital member of our Information Security team that will provide expertise in secure coding practices and the security of our applications. This position offers the opportunity to work closely with a vary talented group of Software Engineers to mature security practices that maintain the trust placed in the company and align with our business objectives. This position is an individual contributor role with responsibilities for software security across the organization.• Who We Are: *We're a $10+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform.• Responsibilities: *Maintain relationships with software engineers, scrum masters, architects, and other security teams to incorporate security principles into the SDLC.Take part in architecture design reviews.Conduct vulnerability assessments and software composition analysis on applications within the organization to unveil concealed vulnerabilities in the code.Collaborate with development teams to remediate vulnerabilities.Develop and maintain security assessment procedures and guidelines.Develop security best practices to be used as security standards within Aya.Stay up to date on emerging threats that affect the security of Aya's software and applicationsAssist with training of Security Champions, when requiredRequired Qualifications:Bachelor's degree preferred, and/or equivalent experience5+ years' experience in software, product, or application securityFamiliarity with one or more programming languages, such as C#, PHP, Python, and JavaExperience with Agile Development MethodologiesUnderstanding and experience with OWASP Top 10 Risks, software security maturity models (such as SAMM or BSIMM), and secure software development lifecycle (SLDC) processes/techniquesExperience performing software threat modeling, such as STRIDESelf-starter requiring minimal supervisionStrong tendency to action and able to work in a fast paced environmentExperience in an Azure Environment are preferredIndustry certifications (Security+, GWAPT, OSCP, CISSP) are preferredWhat We Offer:Free premium medical, dental, life and vision insuranceGenerous 401(k) matchWe also offers other benefits to those that are eligible and where required by applicable law, including reimbursements and discretionary bonusesAya provides paid sick leave in accordance with all applicable state, federal, and local laws. Aya's general sick leave policy is that employees accrue one hour of paid sick leave for every 30 hours worked. However, to the extent any provisions of the statement above conflict with any applicable paid sick leave laws, the applicable paid sick leave laws are controllingCelebrations! We hit our goals and reward ourselves.Company-sponsored virtual events, happy hours and team-building activities are always on the horizon --- plus, you get a special treat on your birthday!
Capital One Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Capital One DE&I Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Capital One
Capital One CEO photo
Richard D. Fairbank
Approve of CEO

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Associate, Application Security Engineer, Capital One

Are you ready to elevate your career as a Principal Associate, Application Security Engineer at Aya? Located in the heart of Ettrick, VA, this is not just another job; it's an invitation to be part of a dynamic, rapidly growing team that's making waves in the healthcare industry. Here, you’ll join forces with highly skilled Software Engineers and the Manager of Software Security to enhance secure coding practices and safeguard our innovative applications. Your expertise will play a crucial role in maintaining the trust that healthcare organizations place in us while aligning with our overarching business goals. As an individual contributor, you’ll take charge of software security across the company, focusing on building strong relationships with various teams, conducting vulnerability assessments, and developing best practices for security standards at Aya. With over five years of experience in application security, along with familiarity in programming languages like C#, PHP, Python, and Java, you will leverage your knowledge of OWASP Top 10 Risks and secure software development lifecycle processes to lead and teach security strategies throughout the organization. Plus, you’ll benefit from a competitive package of resources and support, including free premium medical insurance and a generous 401(k) match. Joining Aya also means embracing celebrations and team-building experiences, ensuring that hard work is recognized and rewarded. If you're a proactive self-starter looking to make a significant impact whilst working in an exciting environment, then we want to hear from you!

Frequently Asked Questions (FAQs) for Principal Associate, Application Security Engineer Role at Capital One
What are the responsibilities of a Principal Associate, Application Security Engineer at Aya?

As a Principal Associate, Application Security Engineer at Aya, your key responsibilities will include maintaining relationships with software engineers and scrum masters while implementing security principles into the software development lifecycle (SDLC). You'll participate in architecture design reviews, conduct vulnerability assessments, and collaborate closely with development teams to remediate any identified vulnerabilities. Additionally, you'll develop and maintain security procedures, stay informed about emerging threats, and assist with training security champions across the organization.

Join Rise to see the full answer
What qualifications are required for the Principal Associate, Application Security Engineer position at Aya?

To qualify for the Principal Associate, Application Security Engineer position at Aya, candidates should have a bachelor's degree or equivalent experience, alongside over five years in software, product, or application security. Proficiency in programming languages such as C#, PHP, Python, and Java is required, along with familiarity with Agile Development Methodologies. Knowledge of the OWASP Top 10 Risks and secure software development lifecycle processes is crucial, as is experience in software threat modeling. Industry certifications such as Security+, GWAPT, or CISSP are preferred.

Join Rise to see the full answer
What types of projects will I work on as a Principal Associate, Application Security Engineer at Aya?

In your role as a Principal Associate, Application Security Engineer at Aya, you will work on a variety of projects aimed at enhancing application security. This will include conducting vulnerability assessments to identify and mitigate security risks, collaborating with software teams on secure coding practices, and developing security assessment procedures. You will also be involved in architecture design reviews and staying ahead of emerging security threats, ensuring that Aya's applications remain robust and secure against potential vulnerabilities.

Join Rise to see the full answer
How does Aya support the professional development of a Principal Associate, Application Security Engineer?

At Aya, professional development for a Principal Associate, Application Security Engineer is highly valued. The company encourages staying current with industry trends and practices, providing opportunities for advanced training and learning. Additionally, you will have the chance to mentor security champions within the organization, enhancing your leadership skills while fostering a culture of security awareness and best practices throughout the software development teams.

Join Rise to see the full answer
What culture can I expect as a Principal Associate, Application Security Engineer at Aya?

The culture at Aya is one of collaboration, innovation, and celebration. As a Principal Associate, Application Security Engineer, you will find yourself in a supportive environment where teamwork is paramount. The company organizes various events, including virtual gatherings and team-building activities, to maintain high morale and foster relationships among employees. Moreover, Aya places a strong emphasis on recognizing achievements, ensuring that hard work doesn't go unnoticed and is rewarded.

Join Rise to see the full answer
Common Interview Questions for Principal Associate, Application Security Engineer
Can you explain your experience with secure coding practices as a Principal Associate, Application Security Engineer?

When answering this question, highlight specific secure coding practices you’ve implemented in your past roles. Discuss your familiarity with coding guidelines and how you’ve collaborated with developers to ensure security is baked into the development process from the very start.

Join Rise to see the full answer
How do you stay updated on the latest security vulnerabilities and threats?

Emphasize your commitment to continuous learning by mentioning specific resources or communities you follow, such as security blogs, forums, or industry conferences. Discuss any professional certifications you are pursuing or have completed, as well as how you share knowledge with your team.

Join Rise to see the full answer
Describe your experience with vulnerability assessments and how you conduct them.

Speak about the methodologies you use for conducting vulnerability assessments, such as tools or frameworks, and how you determine which vulnerabilities to prioritize. Give an example of a time when your assessment led to significant improvements in security.

Join Rise to see the full answer
What strategies do you employ to collaborate with software engineering teams effectively?

Discuss your approach to fostering open communication and building relationships with development teams. You might mention regular meetings, collaborative tools, or feedback sessions that help in integrating security practices without disrupting workflows.

Join Rise to see the full answer
Can you share an experience where you had to tackle a significant security challenge?

When responding, choose a specific instance where you responded to a serious security issue. Detail how you approached it, the outcome, and any lessons learned that improved your future practices.

Join Rise to see the full answer
What is your understanding of the OWASP Top 10, and how have you applied this in your work?

Explain the OWASP Top 10 risks briefly and discuss how you’ve addressed each in your projects. Highlight specific examples where your awareness of these risks contributed to the development of secure applications.

Join Rise to see the full answer
How do you prioritize security tasks in a fast-paced Agile environment?

Discuss your strategies for prioritization, such as using risk assessments to determine the most critical vulnerabilities or tasks. Mention how you integrate security checkpoints into the Agile process to maintain focus on security without slowing down development.

Join Rise to see the full answer
Have you mentored others in security best practices? Can you provide an example?

Share experiences where you educated or mentored colleagues on security awareness. Highlight any specific training sessions or initiatives you've led or contributed to that improved the security posture of your teams.

Join Rise to see the full answer
What tools do you prefer for software threat modeling, and why?

Discuss specific threat modeling tools you've used, explaining their features and how they help you identify vulnerabilities in early development stages. Mention how clear threat modeling can lead to more secure application designs.

Join Rise to see the full answer
Why do you want to work as a Principal Associate, Application Security Engineer at Aya?

Share your passion for application security and interest in the healthcare sector. Discuss how Aya's focus on innovation aligns with your career aspirations and how you believe you can contribute to the company’s mission.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago
Avint Hybrid No location specified
Posted 12 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
NBCUniversal Remote 100 Universal City Plaza, Universal City, CALIFORNIA
Posted 9 days ago

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran

844 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
November 28, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!