Phaxis is seeking an experienced Application Security Engineer focused on ISO 27001 compliance to enhance software security. The role involves collaborating with engineering and compliance teams to integrate security throughout the software development lifecycle.
Seeking 110k to 120k We are seeking an experienced Application Security Engineer to help secure our software products and development lifecycle, with a strong emphasis on ISO 27001 compliance. In this role, you will work closely with engineering, DevOps, and compliance teams to ensure security is integrated into every phase of the software development lifecycle (SDLC), while supporting ongoing audit and governance efforts. Key Responsibilities: • Embed secure coding practices and threat mitigation strategies across the SDLC through developer enablement, code reviews, and architectural input. • Perform application risk assessments, threat modeling (e.g., STRIDE), and design reviews to proactively identify and reduce vulnerabilities. • Integrate security tools into CI/CD pipelines (e.g., SAST, DAST, SCA) to enable continuous security scanning and automated policy enforcement. • Support internal and external ISO 27001 audits, producing technical documentation, security controls evidence, and audit responses. • Collaborate with risk, compliance, and IT teams to align application security practices with broader information security frameworks and regulatory requirements (e.g., SOC 2, GDPR, HIPAA, FDA). • Track, triage, and remediate vulnerabilities discovered through internal testing or reported via bug bounty programs. • Contribute to security awareness initiatives and training sessions tailored for software engineers and DevOps personnel. Qualifications: Required: • 3+ years of experience in Application Security, DevSecOps, or related role • Strong knowledge of secure coding practices, OWASP Top 10, and threat modeling • Familiarity with ISO 27001 controls, audit preparation, and compliance documentation • Hands-on experience with security tools such as Snyk, Veracode, Checkmarx, or similar • Proficiency in at least one programming language (e.g., Python, JavaScript, Java, C#) • Experience working with CI/CD pipelines and cloud-native environments (e.g., GitHub Actions, GitLab CI, Azure DevOps) Preferred: • ISO 27001 Lead Implementer or Lead Auditor certification • Experience with SBOM formats (CycloneDX, SPDX) and dependency management • Familiarity with FDA or SaMD regulatory requirements • Bachelor’s degree in Computer Science, Cybersecurity, or related field • Experience with Kubernetes, container security, and cloud security best practices (AWS, Azure, or GCP)
Phaxis is seeking an experienced Application Security Engineer focused on ISO 27001 compliance to enhance software security. The role involves collaborating with engineering and compliance teams to integrate security throughout the software development lifecycle.
The Director of Application Security at American Express Global Business Travel will lead the strategic development of a world-class application security program, focusing on integrating security into the software development lifecycle. This role involves managing a global team and collaborating with various technical teams to enhance security practices across the organization.
American Express Global Business Travel is seeking a Director of Application Security to lead the development of a world-class application security program. This role involves embedding security across the software development lifecycle and managing a global team of security engineers.
The Associate Principal, Security Engineering (Application Security) at The Options Clearing Corporation focuses on enhancing application and software security through collaboration with IT development teams. The role involves performing security assessments, automating security checks, and implementing secure SDLC processes.
American Express Global Business Travel is seeking a Director of Application Security to lead the development of a world-class application security program. This role involves shaping security strategies across the software development lifecycle and managing a global team of security engineers.
American Express Global Business Travel is seeking a Director of Application Security to lead the development of a comprehensive application security program. This role involves integrating security practices across the software development lifecycle and managing a global team of security engineers.
Phaxis is seeking an experienced Application Security Engineer focused on ISO 27001 compliance to enhance software security. The role involves collaborating with engineering and compliance teams to integrate security throughout the software development lifecycle.
The Director of Application Security at American Express Global Business Travel will lead the strategic development of a world-class application security program, focusing on integrating security into the software development lifecycle. This role involves managing a global team and collaborating with various technical teams to enhance security practices across the organization.
American Express Global Business Travel is seeking a Director of Application Security to lead the development of a world-class application security program. This role involves embedding security across the software development lifecycle and managing a global team of security engineers.
The Associate Principal, Security Engineering (Application Security) at The Options Clearing Corporation focuses on enhancing application and software security through collaboration with IT development teams. The role involves performing security assessments, automating security checks, and implementing secure SDLC processes.
American Express Global Business Travel is seeking a Director of Application Security to lead the development of a world-class application security program. This role involves shaping security strategies across the software development lifecycle and managing a global team of security engineers.
American Express Global Business Travel is seeking a Director of Application Security to lead the development of a comprehensive application security program. This role involves integrating security practices across the software development lifecycle and managing a global team of security engineers.
Phaxis is seeking an experienced Application Security Engineer focused on ISO 27001 compliance to enhance software security. The role involves collaborating with engineering and compliance teams to integrate security throughout the software development lifecycle.
The Director of Application Security at American Express Global Business Travel will lead the strategic development of a world-class application security program, focusing on integrating security into the software development lifecycle. This role involves managing a global team and collaborating with various technical teams to enhance security practices across the organization.
Phaxis is seeking an experienced Application Security Engineer focused on ISO 27001 compliance to enhance software security. The role involves collaborating with engineering and compliance teams to integrate security throughout the software development lifecycle.