Application Security Engineer enhancing security in applications and CI/CD pipelines at Hewlett Packard Enterprise. Collaborating with engineering and DevOps teams to implement security measures across the organization.
Responsibilities
Integrate security practices throughout the SDLC in partnership with engineering and DevOps teams.
Promote secure coding standards, tooling, and automation.
Design, implement, and maintain security controls within CI/CD platforms (GitHub Actions, Jenkins, GitLab, Azure DevOps, etc.).
Ensure software integrity through code signing, artifact validation, and provenance.
Automate SAST, DAST, SCA, and container image scanning in the build and release pipelines.
Automated AI specific vulnerability scanning into CI/CD to catch insecure LLM orchestration patters.
Identify and remediate misconfigurations and access control gaps in pipeline environments.
Design, deploy, and tune WAF rules and API security protections.
Conduct API risk assessments and promote secure API design patterns.
Perform secure code reviews and support automated security testing coverage across pipelines.
Triage, prioritize, and track vulnerabilities across source code, CI/CD pipelines, and deployed services.
Facilitate threat modeling for applications, APIs, and delivery pipelines.
Perform threat modeling on RAG architecture and autonomous agents.
Expand security automation around API discovery, dependency scanning, SBOM generation, and secrets detection.
Mentor engineering teams on secure coding and secure pipeline practices.
Support the Security Champions program.
Act as a trusted advisor to product, platform engineering, and DevOps teams, translating technical risks into business impact.
Partner with SOC/IR teams during software supply chain or pipeline-related security incidents.
Assess and guide the secure adoption of AI capabilities within enterprise applications—focusing on data security, access controls, model input/output handling, and preventing misuse within internal systems.
Leverage AI‑powered security tools to identify anomalies, code risks, and pipeline misconfigurations within internal applications and CI/CD systems.
Requirements
5–8+ years in Application Security, Product Security, or Secure Software Development
Cloud Application Development Engineer at Intel responsible for designing and developing cloud - native applications. Involves building scalable APIs, ensuring security, and troubleshooting production issues.
Application Support Engineer providing technical support for logistics applications with a focus on troubleshooting and performance monitoring. Collaborating with development and business teams for issue resolution in a hybrid work environment.
Application Engineering Manager leading a team of engineers to integrate products into customer vehicles. Focusing on technical solutions and collaboration with automotive OEMs and Tier 1 suppliers.
Application Security Engineer ensuring security is integral to AI product development. Collaborating with engineers on securing code and overseeing vulnerability management.
Application Engineer delivering solutions to customers in the semi/display industry. Leading execution teams and applying customer technologies in Tainan and Hsinchu, Taiwan.
Sales Application Engineer preparing commercial proposals and technical specifications for solar PV and battery energy storage systems. Collaborating with clients and vendors to define integrated solutions.
Experienced Hardware Applications Engineer at Cirrus Logic driving audio technologies for laptops and desktops. Collaborating with industry customers on technical design and integration efforts.
Application Engineering Manager at MPS leading DDR5 SPD Hub validation and characterization. Develop and prototype solutions for Data Center applications with a focus on PCB design and digital logic.
Application Engineer at Monolithic Power Systems validating DDR5 SPD Hub logic and prototypes for Data Center applications. Collaborating with multi - disciplinary teams to drive and design key DP Hub aspects.