Senior Application Security Engineer
M&T BankFull Time
Senior (5 to 8 years), Expert & Leadership (9+ years)
Candidates should possess high integrity, humility, and a strong drive to learn. Experience with building internal tooling for secure access, implementing detection and monitoring systems, and analyzing security issues is required. Familiarity with threat modeling, penetration testing, security scans, and vulnerability disclosure is necessary. The ability to work with developers on sensitive code paths and educate them on secure design patterns is essential. Experience liaising with customers regarding security and compliance needs and communicating security risks to stakeholders is also required. Staying up-to-date with the latest security threats, vulnerabilities, and best practices is a must.
The Software Engineer, Security will build internal tooling to enable secure access to resources, including wrappers, utilities, authentication services, and proxies. They will implement detection and monitoring systems to alert the team to high signal vulnerabilities. This role involves analyzing and assessing security issues identified through threat modeling, penetration testing, security scans, and vulnerability disclosure. The engineer will work with developers on sensitive code paths and educate them on secure design patterns. They will also liaise with customers regarding their security and compliance needs, informing the security program in return. Communicating security risks and solutions to technical and non-technical stakeholders as part of company-wide planning and prioritization processes is a key responsibility. Additionally, the engineer will stay up-to-date with the latest security threats, vulnerabilities, and best practices, making recommendations for improvements to the security posture and partnering with product engineering teams to inform and build security features.
Cloud infrastructure for application deployment
Render simplifies the deployment and management of applications for developers and businesses through its cloud infrastructure platform. Users can deploy their code with just a few clicks using an "infrastructure as code" approach, which allows for easier automation and scaling of applications. The platform supports various programming languages and frameworks, making it versatile for different development needs. Render differentiates itself from competitors like AWS and Salesforce by offering a user-friendly experience and a freemium business model, where users can start for free and upgrade to paid plans for advanced features and better performance. The company's goal is to provide an efficient and accessible solution for application deployment, helping developers and businesses scale their operations effectively.