At BlackLine, we're committed to bringing passion and customer focus to the business of enterprise applications. BlackLine is looking for a creative, polished Senior Application Security Engineer to join our team.
Responsibilities- Perform static analysis security reviews using automated tools like Veracode and manual source code review
- Conduct software composition analysis to identify security risks associated with third-party software and effectively prioritize risks
- Identify security risks and areas of exposure in applications developed and/or used by BlackLine
- Collaborate with software development team in remediating the identified security vulnerability and ensure defense mechanisms are implemented of highest standards
- Review technical specification documents, perform threat modelling to determine risks, define Application Security requirements, and develop consistent threat modelling artifacts
- Oversee development of security components throughout all the stages of the Software Development Lifecycle
- Perform Dynamic security assessments or manual penetration testing of BlackLine applications
- Monitor industry trends and threat landscape and recommend necessary controls or countermeasures
- Recommend and lead projects to improve the Application Security risk management posture of Blackline at large
- Lead Security Champions program to train developers on secure coding techniques and security best practices
- Mentor team of Application Security Engineers and provide technical guidance
- Participate in development of security policies, standards, and processes
- Participate in incident handling and perform application-related forensic activitie
- Perform other duties as assigned
- Provide limited supervision to others through motivation, direction, review and feedback of assigned tasks
- Working Conditions: This role will be expected to be online during business hours for most of our customers (North America) and to have coverage for business operations conducted during business hours in other HQ (e.g., EU issues that are Resolve Immediately)
- Application Security office hours are 0800-1700, with overnight incident coverage provided by on call for Security Operations.
- 5+ years of hands-on Application Security experience, strong emphasis on prior development experience.
- Advanced knowledge of OWASP Top 10 risks and CWE TOP 25 (e.g. Broken Access Control, SSRF, Injection, cookie/header/encoding manipulation, Cryptographic failures, Broken Authentication, Insecure Design etc).
- Advanced knowledge of web application technologies, MVC, Ajax, XML, JSON, SOA, SSL, web-related protocols and services.
- Intermediate knowledge of MS SQL. Basic knowledge of other commonly used DBMS.
- Ability to identify security vulnerabilities from static, dynamic and interactive testing tools and techniques.
- Knowledge of encryption technologies, secure communications using TLS, and secure credentials management.
- Intimate familiarity with web application testing tools (eg: Burp, Fiddler, Veracode, Snyk, Whitehat DAST). Ability to write proof-of-concept exploits is a big plus.
- Ability to define Application Security requirements and build secure web application solutions.
- Advanced written and verbal communication skills including ability to present technical subjects to non-technical audiences.
- Strong work ethic, attention to detail, and organizational skills.
- Ability to collaborate in a team and work independently.
- Conceptual understanding of software development principles and SDLC models, Agile experience is a plus.
- Intermediate proficiency with the Microsoft Office suite.