Back to Signal
Pulse RelayVouched 0 times by industry insiders

AppSec Engineer

SeniorApplication SecurityRemote
$200k
Open to Right Opportunity

Quick Match Check

Key Skills

SAST/DAST (SonarQube, Checkmarx, Burp Suite Enterprise)Cloud Security (AWS, Azure)Container Security (Docker, Kubernetes)Threat Modeling (STRIDE, DREAD)API Security (OIDC, OAuth2, JWT)Python (for automation and scripting)CI/CD Pipeline Integration (Jenkins, GitLab CI)Web Application Firewalls (WAF)

Ricki from CyberSec People will make the introduction

Skills Assessment

1st PrinciplesCode BiasTech DepthCuriosityWar Stories8.09.09.08.08.0
1st Principles8/10

Breaks down complex problems into fundamental truths and builds solutions from the ground up

Code Bias9/10

Prefers building and shipping code over meetings and documentation

Tech Depth9/10

Deep technical expertise across security domains, tools, and architectures

Curiosity8/10

Constantly learning, experimenting, and staying ahead of emerging threats

War Stories8/10

Battle-tested experience solving real-world security incidents and challenges

Profile Summary

This Senior AppSec Engineer architects and implements robust security controls directly into the software development lifecycle, ensuring applications are secure by design. They are adept at identifying vulnerabilities early and building automated solutions that scale across large enterprise environments. Their mission is to fortify critical systems and empower development teams to deliver secure products efficiently.

Problems Solved

  • Reduced critical application vulnerabilities by 45% within 12 months at a major Australian bank (e.g., CBA) by integrating DAST/SAST tools and providing targeted developer training.
  • Engineered and deployed a custom static analysis pipeline for a cloud-native platform, identifying over 200 high-risk security flaws before production release and reducing manual review effort by 30%.
  • Developed an automated vulnerability remediation tracking system that decreased average fix time for high-severity findings by 25% across 15+ development teams.

What They Build

They build secure software development lifecycles (SSDLCs), integrating security tooling and processes from design to deployment. Their focus is on creating scalable, automated security solutions that empower developers to write secure code and minimize security debt.