Application Security Engineer

| Chicago
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.
JOB DESCRIPTION

Application Security Engineer (Donnelley Financial LLC; Chicago, IL): Functionally support product engineering and development teams to secure company’s SaaS products portfolio. Assess and understand the security posture and attack surface of all DFIN products, and for assistance in the development of the appropriate security controls. Conduct security assessments, security penetration testing, and validation of test results. Provide security insights to vulnerability scan/pen test results. Work closely with development teams to assess the security posture/risk of the product features being developed. Perform architectural risk analysis, threat modeling, secure design and source code review. Effectively manage relationship with external application security and penetration testing partners. Incorporate security tools and tasks into automated product development and deployment lifecycle (SAST/DAST/IAST integration into CI/CD pipeline). Provide expert knowledge and guidance to the product development teams about security vulnerabilities and applicable remediation paths. Serve as a critical resource to ensuring each DFIN product is developed in alignment with industry-leading Secure Product/Software Development standards. Participate in development of the DFIN Application Security Standards, best practices and associated metrics. 40 hrs/wk, 9:00 am – 5:00 pm. 

MINIMUM REQUIREMENTS

Master's degree in Computer Science or a related field and 3 years of related work experience.

Must also have at least 2 years of experience in each of the following:

  • Developing technical (XSS) and functional (fraud) abuse test cases;
  • Using CI/CD pipelines including tools and technologies such as Azure DevOps (former VSTS), Github, And Jenkins:
  • Applying OWASP security concepts to common application security risks including XSS, CSRF, SOL Injection, and Cookie Manipulation;
  • Utilizing vulnerability management and penetration testing tools such as NMAP, Core Security, Burp, Zap, Rapid7 Nexpose, Kali Linux, and Metasploit;
  • Demonstrating knowledge of NIST framework, Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM);
  • Deploying fundamental application security building blocks such as: authenticatin, authorization, data validation, encryption, exception handling and logging; and
  • Utilizing SAST/DAST/IAST tools such as Checkmarx, Veracode, Rapid 7 AppSpider, IBM AppScan and HP/Microfocus Fortifty.

Must have at least 1 year of experience in the following:

  • Analyzing the inherent security risks of cloud platforms such as MS Azure and Amazon AWS and developing relevant security controls.

Up to 10% travel required. 100% telecommuting permitted. Applicant may reside anywhere in the U.S.A.

How to apply:

To apply, please visit https://jobs.dfinsolutions.com/ and search Job ID 2467.

This notice is provided as a result of the filing of an application for permanent alien labor certification for the relevant job opportunity, in compliance with 20 CFR 656.10(d). Any person may provide documentary evidence bearing on the application to the Certifying Officer of the U.S. Department of Labor holding jurisdiction over the location of the proposed employment. Contact information for these offices can be found on the Internet at:

http://www.foreignlaborcert.doleta.gov/contacts.cfm#npc

U.S. Department of Labor

Employment and Training Administration

Office of Foreign Labor Certification

200 Constitution Avenue NW, Room N- 5311

Washington DC 20210

Read Full Job Description
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
    • .NETLanguages
    • C#Languages
    • JavaLanguages
    • PythonLanguages
    • SqlLanguages
    • AzureLanguages
    • jQueryLibraries
    • ReactLibraries
    • AngularJSFrameworks
    • ASP.NETFrameworks
    • Node.jsFrameworks
    • Microsoft SQL ServerDatabases
    • SAP HANADatabases
    • TeradataDatabases
    • IllustratorDesign
    • PhotoshopDesign
    • Aha!Management
    • ConfluenceManagement
    • JIRAManagement
    • Microsoft ProjectManagement
    • DocuSignCRM
    • LinkedIn SalesNavigatorCRM
    • Microsoft DynamicsCRM
    • SalesforceCRM
    • MarketoLead Gen
    • Oracle EloquaLead Gen

Location

Located in the heart of downtown Chicago’s financial district, we are steps from all Metra stations, good eats and entertainment.

An Insider's view of DFIN

What projects are you most excited about?

In transforming and improving FinTech products, excitement comes from the challenge of knowing that the problems are complex, yet the solutions must be easy to use. When we start a new project, I can't wait to sink my teeth into understanding the problem space, talking to users, designing the solution, and seeing it through to release.

Dan

Principal Product Designer

What makes someone successful on your team?

Active and honest listening – Contrary to the stereotypical, extroverted sales rep, some of my most effective and insightful client interactions are when I do the least amount of talking, and the most active listening. Client insight is exponentially easier to excavate when you stop “pitching” – and start listening.

Carey

Senior Sales Representative

What is your vision for the company?

Our business plan reflects the change in products DFIN is selling today versus what we sell in five years. DFIN today is a company that offers a lot of professional services that we added software to, but the goal is to become a SaaS company that has services to support it.

Stephen

SVP, Global Head of Engineering

What does your typical day look like?

The role of a software engineer is really about creating computational systems and ensuring they behave as designed. My day-to-day is focused mostly on writing code that provides new functionality within our products that we see a need for in the market—and providing quality control to be certain it works properly.

Herve

Senior Software Engineer

What are DFIN Perks + Benefits

DFIN Benefits Overview

The world continues to change in ways we never expected, but there is one constant: your safety and well-being is a top priority, and DFIN has you covered with our benefits.

Culture
Partners with Nonprofits
Friends outside of work
Eat lunch together
Intracompany committees
Daily sync
Open door policy
Team owned deliverables
Team based strategic planning
Group brainstorming sessions
Open office floor plan
Diversity
Documented equal pay policy
Dedicated Diversity/Inclusion Staff
Highly diverse management team
Unconscious bias training
Diversity manifesto
Diversity Employee Resource Groups
Hiring Practices that Promote Diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability Insurance
Dental Benefits
Vision Benefits
Health Insurance Benefits
Life Insurance
Wellness Programs
Onsite Gym
Mental Health Benefits
Retirement & Stock Options Benefits
401(K)
401(K) Matching
Company Equity
Performance Bonus
Child Care & Parental Leave Benefits
Generous Parental Leave
Flexible Work Schedule
We value a work / life balance at DFIN.
Remote Work Program
We have partial and fully remote opportunities at DFIN.
Family Medical Leave
Family Medical Leave granted under the Family and Medical Leave Act (FMLA).
Adoption Assistance
Return-to-work program post parental leave
Vacation & Time Off Benefits
Generous PTO
Paid Holidays
Paid Sick Days
Perks & Discounts
Casual Dress
Commuter Benefits
Company Outings
Stocked Kitchen
Happy Hours
Parking
Employee parking available
Fitness Subsidies
Professional Development Benefits
Job Training & Conferences
Diversity Program
Lunch and learns
Cross functional training encouraged
Promote from within
Mentorship program
Time allotted for learning
Online course subscriptions available
Customized development tracks
Paid industry certifications
More Jobs at DFIN27 open jobs
All Jobs
Finance
Data + Analytics
Dev + Engineer
HR + Recruiting
Marketing
Operations
Product
Project Mgmt
Sales
Content
Data + Analytics
new
Chicago
Product
new
Chicago
Project Mgmt
new
Chicago
HR + Recruiting
new
Chicago
Developer
new
Chicago
Developer
new
Chicago
Sales
new
Chicago
Operations
new
Chicago
Developer
new
Chicago
Developer
new
Chicago
Developer
new
Chicago
HR + Recruiting
new
Chicago
Finance
new
Chicago
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.
Save jobView DFIN's full profileSee more DFIN jobs