Senior Application Security Engineer
Verisign · Reston,Virginia,United States
About this role
**Verisign — Senior Application Security Engineer** Verisign helps enable the security, stability, and resiliency of the internet through trusted internet infrastructure services—delivering unmatched performance in DNS. ## Role Overview The **Senior Application Security Engineer** will lead efforts to secure all software built and/or used by Verisign. You’ll partner with application development teams and third parties to ensure **security, privacy, and compliance** are built into applications from design through production. You’ll help shape the future of the application security program by leading assessments, staying current on security research and best practices, and setting program standards. ## Responsibilities - Serve as the **application security subject matter expert** during requirements, design, and architecture (including **application threat modeling**) - Perform and lead **manual and automated application vulnerability assessments**, document findings, and provide clear remediation guidance - Own the **application security vulnerability management lifecycle** across the security toolchain, including: - Software composition analysis - Static and dynamic testing - Interactive testing - Secrets scanning - Review and provide remediation guidance for submissions from Verisign’s **public Bug Bounty** program - Track open issues against defined **SLAs**, follow up with development teams, and escalate overdue items to engineering and InfoSec leadership - Guide integration of security testing into **CI/CD pipelines** - Review third-party/vendor-supplied applications against internal security requirements - Mentor junior engineers and analysts; review peer work and provide constructive feedback - Contribute to security standards and secure coding guidance; participate in the broader Verisign technical community ## AI and Application Security - Assess applications that embed **large language models (LLMs)** or other AI services for risks such as: - Prompt injection - Sensitive data exposure - Insecure output handling - Over-permissioned agents and integrations - Develop and maintain internal guidance for developers using **AI coding assistants** (review, testing, and scanning expectations) - Evaluate and pilot AI-assisted capabilities in the application security workflow (triage, false positive reduction, remediation guidance) - Track AI security guidance/standards and translate them into practical internal requirements ## Key Skills & Experience - **10+ years** in Information Technology, including hands-on application development experience - **6+ years** conducting application security assessments using COTS/open-source tooling (e.g., **Burp Suite, Fortify**, or equivalent) - Hands-on experience with: - Software composition analysis - Dynamic application security testing - Secrets scanning platforms - Experience running a vulnerability management program through ticketing/workflow systems, including **SLA definition** and executive reporting - Strong working knowledge of **OWASP Testing Framework** and **OWASP Top 10** - Proficiency with accepted software development life cycles and related standards/procedures - Knowledge of application architectures (SPA, 3-tier, microservices, containerized workloads) - Practical familiarity with AI/LLM application security risks and current industry guidance - Methodical and organized; able to manage multiple opportunities/projects/partners concurrently - Excellent co
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.