Senior Application Security Engineer
M&T BankFull Time
Senior (5 to 8 years), Expert & Leadership (9+ years)
Candidates should have at least 4 years of relevant application security industry experience and a data-driven mindset. Strong knowledge of security fundamentals, particularly in Web Application Security and Cloud Security primitives, is required. Experience with common software development stacks, CI/CD systems, and coding for software automation and security test cases (preferably in GoLang, Python, Java) is necessary. The role also requires experience working with distributed teams and cross-functional stakeholders, along with the ability to own outcomes, influence stakeholders, and provide leadership in security matters.
The Senior Application Security Engineer will drive and influence software security across the organization by partnering with key stakeholders. Responsibilities include staying updated on emerging security vulnerability classes, performing triage, conducting security threat modeling, and design reviews to provide secure design guidance. The role involves performing product security feature implementation reviews, API security testing, and code reviews to identify vulnerabilities. Enhancing security automation by leveraging or building tooling to scale product security operations and support vulnerability management is also a key duty. Additionally, the engineer will propose, design, build, and deploy security solutions, frameworks, automation, and orchestration for cloud applications, and identify opportunities for implementing additional technology controls.
Data streaming solutions for real-time processing
Confluent specializes in data streaming solutions, focusing on helping businesses manage and process real-time data streams. Its main product is built on Apache Kafka, an open-source platform that allows users to create real-time data pipelines and streaming applications. Clients, including large enterprises and financial institutions, utilize Confluent's tools to collect, process, and analyze data streams, which helps them make quicker and more informed decisions. Unlike many competitors, Confluent offers a subscription-based model for its cloud platform, Confluent Cloud, and its on-premises software, Confluent Platform, ensuring a steady revenue stream. The company also provides professional services like training and consulting to assist clients in optimizing their data streaming solutions. Confluent's goal is to be a leader in the data streaming market, enabling organizations to leverage real-time data for improved operational efficiency.