
Senior Security Engineer (AppSec)
- Auckland Wellington
- Permanent
- Full-time
- Develop and implement secure coding practices, working closely with engineers to uplift security awareness and adoption
- Integrate automated security testing (SAST, DAST, SCA, IaC scanning) and security policy enforcement into CI/CD pipelines to identify vulnerabilities early.
- Work with DevOps and engineering teams to build security guardrails, ensuring frictionless security adoption; driving a "shift-left" security mindset by enabling teams with secure coding guidance, tooling, and risk-based security testing.
- Assist engineering teams in threat modeling to proactively identify and mitigate security risks in software designs. Ultimately looking to improve visibility and reporting of application security risks, helping teams understand and measure their security posture.
- Build and manage security automation tools, integrating them into existing developer workflows; contribute to DevSecOps initiatives, ensuring security controls are scalable, efficient, and developer-friendly.
- Participate in cross-functional security initiatives, working on security improvements that impact multiple teams. Continuously evaluate and improve security tools, scanning coverage, and security-as-code implementations.
- Extensive experience in Application Security, Secure Software Development, and DevSecOps practices.
- Hands-on experience with automated security testing tools, including SAST, DAST, SCA, and IaC security scanning.
- Proficiency in programming and scripting languages (Python, Java, Go, JavaScript, or similar); coupled with a strong understanding of secure coding principles, OWASP Top 10, SANS CWE, and software security best practices.
- Hands-on experience securing APIs, microservices, cloud-native applications, and serverless architectures
- Experience integrating security controls into CI/CD pipelines (Jenkins, GitHub Actions, GitLab CI, or similar).
- Solid background in vulnerability management, risk assessment, and application security triage; including incident response, investigating and mitigating application security breaches.