Application Security Engineer
Contract
Farmington Hills MI (Onsite)
Job Description:
Application Security
Deploy and operate application security capabilities tools and standardized requirements across the region.
Identify analyze and document application level vulnerabilities in a systematic and repeatable manner.
Communicate identified risks and mitigation strategies to technical and non technical stakeholders.
Collaborate with development teams and market units to coordinate and track remediation activities.
Provide hands-on support for secure design remediation efforts and secure SDLC practices.
Report on remediation progress risk posture and compliance readiness.
Deliver targeted application security training and awareness sessions.
Support deployment and monitoring of applications hosted in Microsoft Azure.
Explain and support application authentication and authorization concepts.
Secure Profiling & Threat Modeling
Identify and document application threats using STRIDE C4 modeling and MITRE methodologies.
Build data flow diagrams and comprehensive threat models for critical applications.
Provide actionable security recommendations based on threat modeling outputs.
Maintain tracking and coordination of remediation activities resulting from secure profiling engagements.
Identity & Access Architecture
Design secure authentication and authorization models using:
o OAuth 2.0
o OpenID Connect (OIDC)
o SAML 2.0
Implement secure integrations with Microsoft Entra ID (Azure AD).
Guide teams on:
o JWT token validation
o Managed identities
o Service-to-service authentication
o RBAC and Conditional Access
o Secure API authorization
Azure Cloud Security
Secure Azure-native workloads including App Services Azure Functions AKS and Virtual Machines.
Architect secure network configurations: NSGs private endpoints firewalls.
Implement secrets management with Azure Key Vault.
Use Defender for Cloud and Azure Policy for governance and continuous security improvement.
Ensure observability and monitoring via Log Analytics and Sentinel.
Application Security Engineer Contract Farmington Hills MI (Onsite) Job Description: Application Security Deploy and operate application security capabilities tools and standardized requirements across the region. Identify analyze and document application level vulnerabilities in a systemati...
Application Security Engineer
Contract
Farmington Hills MI (Onsite)
Job Description:
Application Security
Deploy and operate application security capabilities tools and standardized requirements across the region.
Identify analyze and document application level vulnerabilities in a systematic and repeatable manner.
Communicate identified risks and mitigation strategies to technical and non technical stakeholders.
Collaborate with development teams and market units to coordinate and track remediation activities.
Provide hands-on support for secure design remediation efforts and secure SDLC practices.
Report on remediation progress risk posture and compliance readiness.
Deliver targeted application security training and awareness sessions.
Support deployment and monitoring of applications hosted in Microsoft Azure.
Explain and support application authentication and authorization concepts.
Secure Profiling & Threat Modeling
Identify and document application threats using STRIDE C4 modeling and MITRE methodologies.
Build data flow diagrams and comprehensive threat models for critical applications.
Provide actionable security recommendations based on threat modeling outputs.
Maintain tracking and coordination of remediation activities resulting from secure profiling engagements.
Identity & Access Architecture
Design secure authentication and authorization models using:
o OAuth 2.0
o OpenID Connect (OIDC)
o SAML 2.0
Implement secure integrations with Microsoft Entra ID (Azure AD).
Guide teams on:
o JWT token validation
o Managed identities
o Service-to-service authentication
o RBAC and Conditional Access
o Secure API authorization
Azure Cloud Security
Secure Azure-native workloads including App Services Azure Functions AKS and Virtual Machines.
Architect secure network configurations: NSGs private endpoints firewalls.
Implement secrets management with Azure Key Vault.
Use Defender for Cloud and Azure Policy for governance and continuous security improvement.
Ensure observability and monitoring via Log Analytics and Sentinel.
View more
View less