Lead Application Security/DevSecOps Engineer

Brak informacji o wynagrodzeniu
SeniorFull-time
#394475·Dodano 3 dni temu·4
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

AWSAzureCI/CDAppSecRuby on Rails.NETPHPLaravelPythonGitHub Advanced SecurityFERPAGDPR

Firma i stanowisko

Faria Education Group is a leader in international education systems & services, offering an integrated suite of products such as ManageBac, OpenApply, SchoolsBuddy, and Vectare, trusted by over 10,000 schools and 4 million students across 155 countries.

Wymagania

  • 7+ years in application/product security, including standing up or maturing an AppSec program from near-zero to functioning.
  • Strong knowledge and curiosity in AI, aiming for proactive protection and AI-first problem-solving.
  • Experience working across multiple stacks including Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep expertise in one or two, competency across others).
  • Strong expertise in cloud security across AWS and Azure.
  • Deep understanding of common vulnerability classes and secure coding practices.
  • Hands-on experience with AppSec tooling and DevSecOps/CI/CD integration.
  • Threat modeling experience.
  • Excellent communication and influencing skills, able to drive change in engineering organizations new to formal security.

Nice to have:

  • Experience with GitHub Advanced Security.
  • Experience working with student data or PII-heavy regulated environments (e.g., FERPA, COPPA, GDPR for UK/EU).
  • Proven experience managing large vulnerability backlogs with classification, deduplication, and remediation management across many repositories.

Obowiązki

  • Conduct an initial deep-dive assessment and evaluation to drive risk-based prioritisation.
  • Stand up and own the application security program across all five products (greenfield).
  • Define and embed a secure SDLC (shift-left): security requirements, design reviews, guardrails, and coding standards suited for AI engineering.
  • Select, deploy, and operationalise AppSec tooling including SAST, DAST, SCA/dependency and secrets scanning integrated into CI/CD pipelines.
  • Implement and operationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines.
  • Build risk-based vulnerability management: triage, prioritise, and drive remediation across teams and technology stacks.
  • Lead remediation of some vulnerabilities to support the software engineering team.
  • Run threat modeling and security reviews for new architecture and significant features.
  • Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra teams.
  • Lead technical incident response.

Benefity

  • Competitive compensation and career development opportunities.
  • Access to an online learning platform, unlimited book purchases, and diverse internal and external training programs.
  • Friendly atmosphere with group activities and corporate events.
  • Equipment provision including MacBook Pro or another laptop of choice, peripherals, and displays.
Dofinansowanie szkoleń
Spotkania integracyjne

Inne informacje

All qualified applicants will be considered without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, or sex. The successful applicant may be required to complete an enhanced DBS disclosure and an Enhanced Check for Regulated Activity. Only shortlisted candidates will be contacted due to high volume of applicants.

Faria Education Group

Faria Education Group

2 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz