Application Security Engineer I - AppFolio - Santa Barbara, CA
AppFolio
Overview Join to apply for the Application Security Engineer I role at AppFolio Application Security Engineer I will work closely with developers and other security team members to maintain and improve the security posture of AppFolio applications. They will contribute to security initiatives as an individual contributor and work on high-impact projects as a member of the security engineering team. This will be accomplished with computer programming experience, an understanding of common application security vulnerabilities, an ability to use security testing tools, and a strong passion for the technical aspects of information security. Your impact Responsibilities Identify vulnerabilities in software applications and help get them fixed Provide security guidance and education to developers in order to build a strong security culture and bake security into products early Continuously improve tools and techniques in an application security pipeline Must have B.S. in Computer Science or equivalent work experience 2-5 years of work experience programming in Ruby or a similar language 2-5 years of work experience with a CI/CD pipeline 2-5 years of work experience with threat modeling or risk assessment 2-5 years hands-on work experience evaluating applications for OWASP Top 10 security risks and recommending fixes/mitigations 2-5 years hands-on work experience with an enterprise Linux command line 2-5 years hands-on experience with application security testing tools (SAST, DAST, SCA, Web Proxies like Burp or ZAP) Familiarity with an MVC Framework like Rails Nice to have Knowledge of networking principles and cloud platforms Knowledge of databases and SQL Knowledge of Cloud technologies Compensation & Benefits The base salary that we reasonably expect to pay for this role is: $104,000 - 130,000 The actual base salary for this role will be determined by a variety of factors, including but not limited to: the candidates skills, education, experience, etc. Please note that