Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Application Security Engineer image - Rise Careers
Job details

Application Security Engineer

Basic Function

The Application Security Engineer at Lumin Digital is responsible for ensuring the security of digital banking solutions by integrating security practices throughout the product and software development lifecycle. This role involves vulnerability analysis, threat modeling, and collaborating with cross-functional teams to maintain a robust application security posture. Success in this role requires a proactive approach to identifying and mitigating risks, supporting compliance efforts, and staying ahead of evolving security threats.


Essential Functions, Responsibilities, Experience:

Collaborate with Product and Development teams to embed security into the software development lifecycle, from design to maintenance.

Provide guidance on secure architecture, coding practices, and CI/CD pipeline protection.

Implement and maintain automated application vulnerability scanning tools, including static (SAST) and dynamic (DAST) security testing solutions.

Coordinate manual application penetration testing assessments through third-party engagements and validate results.

Respond to application security incidents using industry-standard practices to identify, contain, and remediate vulnerabilities.

Monitor and optimize reporting and alerting systems to identify, prioritize, and address application security risks effectively.

Maintain comprehensive records of vulnerability detections and security posture across all systems, ensuring consistent improvement.

Support risk management, compliance, and audit activities by collecting evidence and producing reports to demonstrate security program effectiveness.

Serve as a first point of contact for reported vulnerabilities, triaging issues from internal sources, clients, and external researchers.

Conduct architectural and code reviews to identify vulnerabilities and recommend improvements to the application security posture.

Perform other duties as assigned.


Growth Opportunities:

30 Days: Gain familiarity with Lumin Digital’s security tools, applications, and processes. Begin triaging security issues and working on initial vulnerability assessments.

90 Days: Take ownership of vulnerability scanning tools, coordinate with third-party testing partners, and contribute to improving application security processes.

1 Year: Lead application threat modeling initiatives, implement enhancements to the vulnerability management program, and provide strategic recommendations to improve Lumin Digital’s security posture.


Knowledge, Skills, & Abilities:

Four (4) years of experience in a relevant technology domain, including security engineering, software engineering, or application vulnerability analysis.

Three (3) years of demonstrated experience in identifying and technically qualifying application security vulnerabilities in a full-time capacity for large-scale web, financial services, or mobile applications.

Ability to read and comprehend application source code (e.g., TypeScript, JavaScript, C#, Java, Swift) and identify vulnerabilities such as command injection and inappropriate cryptographic usage.

Working knowledge of security vulnerabilities, including OWASP Top 10 and CWE.

Specialized knowledge of authentication and authorization frameworks, such as SAML, OIDC, OAuth 2.0, SCIM, JWT, WebAuthn, and OPA

Familiarity with authentication and authorization frameworks (e.g., SAML, OIDC, OAuth 2.0) and applied cryptography concepts.

Strong analytical skills to validate and reproduce reported vulnerabilities through manual testing or scripting.

Effective written and verbal communication skills, with the ability to raise awareness and coordinate remediation activities.


Education: 

Bachelor’s degree in Computer Science, Management Information Systems, Cybersecurity, or a related field. Equivalent experience with demonstrated expertise may be considered.



$110,000 - $130,000 a year

LIFE AT LUMIN DIGITAL


Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people. We empower credit unions and banks by creating cutting-edge digital experiences that continuously serve, engage, and grow their membership base. Lumin is 100% cloud-native, purpose-built to unlock the full advantages of the cloud for financial institutions and their users.


At Lumin, we thrive on curiosity and innovation. Our culture fosters trust - in our expertise and decisions, respect - for diverse perspectives and talents, and boldness - in pursuing innovative paths. These values guide us, shaping a workplace where collaboration thrives, ideas flourish, and new possibilities are discovered. Focused on continuous improvement and innovation, we encourage our team to explore, experiment, and put new ideas into action, challenging the usual way of doing things.


All qualified applicants, including those with arrest or conviction records, will be considered for employment. Any conditional offer will include a notice regarding the review of the candidate’s criminal history as part of the hiring process.


For more information, visitlumindigital.com.

Lumin Digital Glassdoor Company Review
4.9 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Lumin Digital DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Lumin Digital
Lumin Digital CEO photo
Jeff Chambers
Approve of CEO

Average salary estimate

$120000 / YEARLY (est.)
min
max
$110000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Application Security Engineer, Lumin Digital

Join the team at Lumin Digital as an Application Security Engineer and play a crucial role in safeguarding digital banking solutions! In this remote position, you'll ensure that security practices are integrated throughout the product and software development lifecycle. You'll get the chance to collaborate with Product and Development teams, guiding them on secure architecture and coding practices. Your expertise in automated application vulnerability scanning tools like SAST and DAST will help keep our applications safe, while manual penetration testing will ensure thorough assessments. Reacting to application security incidents, you’ll utilize industry-standard practices to swiftly identify and resolve vulnerabilities. You will also have the opportunity to monitor systems for application security risks and maintain detailed records to improve our security posture continuously. With a Bachelor’s degree in Computer Science or related fields, along with several years of experience in security engineering and vulnerability analysis, you’re the perfect fit. At Lumin Digital, we’re not just about security; we’re about empowering financial institutions through innovation. If you thrive on curiosity, enjoy working in a collaborative environment, and want to explore and experiment with new ideas, apply today and help us create cutting-edge digital banking experiences!

Frequently Asked Questions (FAQs) for Application Security Engineer Role at Lumin Digital
What are the main responsibilities of the Application Security Engineer at Lumin Digital?

The Application Security Engineer at Lumin Digital is responsible for integrating security practices into the software development lifecycle. This includes providing guidance on secure architecture, conducting vulnerability analyses, coordinating penetration testing, responding to security incidents, and maintaining robust records of security posture.

Join Rise to see the full answer
What qualifications are needed for the Application Security Engineer position at Lumin Digital?

To qualify for the Application Security Engineer position at Lumin Digital, candidates should have a Bachelor’s degree in Computer Science, Cybersecurity, or a related field, along with at least four years of experience in a relevant technology area and three years of demonstrated experience in application security vulnerability identification.

Join Rise to see the full answer
How does Lumin Digital ensure continuous improvement in application security?

Lumin Digital ensures continuous improvement in application security by regularly monitoring vulnerabilities, supporting compliance and audit activities, using automated scanning tools, and encouraging a culture of collaboration and innovation among teams to address any potential risks.

Join Rise to see the full answer
What tools and techniques will the Application Security Engineer at Lumin Digital use?

The Application Security Engineer at Lumin Digital will use various automated application vulnerability scanning tools, including static and dynamic testing solutions. They will also employ scripting for manual testing, support third-party engagements for penetration testing, and leverage knowledge of security protocols and frameworks.

Join Rise to see the full answer
What is the expected salary range for the Application Security Engineer role at Lumin Digital?

The expected salary range for the Application Security Engineer role at Lumin Digital is between $110,000 and $130,000 annually, reflecting the expertise and experience level required for this pivotal position in the organization.

Join Rise to see the full answer
Common Interview Questions for Application Security Engineer
Can you explain your experience with application vulnerability analysis?

When answering this question, highlight specific tools and methodologies you've used for conducting vulnerability assessments. Describe how you identified, prioritized, and remediated vulnerabilities, focusing on both individual contributions and collaborative efforts with development teams.

Join Rise to see the full answer
What security standards or frameworks are you familiar with?

You should mention relevant security standards such as OWASP Top 10, NIST, or CIS benchmarks. Discuss specific frameworks you've applied in your work, and how you’ve integrated them into your security practices to enhance application safety.

Join Rise to see the full answer
Describe your process for conducting a threat modeling session.

Give a step-by-step description of your threat modeling process, including identifying assets, potential threats, vulnerabilities, and risk levels. Emphasize the importance of collaboration with stakeholders to ensure comprehensive coverage.

Join Rise to see the full answer
How do you keep up to date with evolving security threats?

Talk about your strategies for staying informed about the latest security threats, such as reading industry blogs, participating in webinars, and engaging with professional networks, which help you remain vigilant in your security practices.

Join Rise to see the full answer
Can you provide an example of a security incident you've managed?

When answering, select a specific incident where you played a significant role. Detail what the incident was, your action plan for response, and how you worked to contain and remediate the issue, highlighting lessons learned.

Join Rise to see the full answer
What are some common application security vulnerabilities you’ve encountered?

Discuss vulnerabilities like SQL injection, cross-site scripting (XSS), or broken authentication. Provide examples from your experience that demonstrate how you've identified and addressed these vulnerabilities in past projects.

Join Rise to see the full answer
How do you prioritize and manage vulnerabilities in a project?

Explain your methodology for assessing risks associated with each vulnerability by severity and impact. Discuss tools you might use for tracking vulnerabilities and your approach to communicating these priorities with development teams.

Join Rise to see the full answer
What coding languages are you proficient in that relate to secure coding practices?

List the coding languages you're experienced with, such as Java, C#, or JavaScript. Discuss your understanding of secure coding principles and how you would apply them while reviewing and writing code.

Join Rise to see the full answer
How do you conduct an architectural review for security?

Describe your approach to performing an architectural review, focusing on identifying security controls, assessing third-party integrations, and ensuring compliance with best practices within architecture design.

Join Rise to see the full answer
What do you consider to be the most critical aspect of application security?

Discuss the importance of a proactive security culture that involves continuous monitoring, education, and collaboration across teams. Highlight how early integration of security can prevent vulnerabilities from arising in the first place.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
1GLOBAL Remote No location specified
Posted 5 days ago
Photo of the Rise User
OTIP Group of Companies (OGC) Remote 17704 103 Ave NW, Edmonton, AB T5S 1J9, Canada
Posted 3 days ago
Photo of the Rise User
Posted 13 days ago
Inclusive & Diverse
Mission Driven
Empathetic
Collaboration over Competition
Transparent & Candid
Growth & Learning
Customer-Centric
Medical Insurance
Dental Insurance
Vision Insurance
Health Savings Account (HSA)
Mental Health Resources
Equity
Maternity Leave
Paternity Leave
Paid Time-Off
Life insurance
Photo of the Rise User
Devoteam Remote Av. Dom João II, 1990 Lisboa, Portugal
Posted 9 days ago
Photo of the Rise User
Veeva Systems Remote Massachusetts - Boston
Posted 10 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Family Medical Leave
Maternity Leave
Paternity Leave
Lactation Facilities
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Paid Time-Off
Paid Volunteer Time
Photo of the Rise User
Posted 3 days ago

Our mission is to build a dynamic digital banking platform that helps financial institutions preserve and grow their consumer relationships in today’s evolving market.

19 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 9, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!