Application Security Engineer
Philadelphia, PA - USA
Job Summary
See yourself at Radian We see you here too.
At Radian we see you. For the person you are and the potential you hold. Thats why weve embraced a new way of working that lets our people across the country be themselves be their best and be their boldest. Because when each of us is truly seen each of us gives our best and at Radian well give you our best right back.
See Yourself as an Application Security Engineer
The Application Security Engineer is responsible for executing the strategy operation and continuous optimization of Radians Application Security program through engineering excellence and secure software development expertise. This role designs implements and supports engineering solutions that enable secure software delivery while partnering closely with Application Development and Information Security leadership to define strategy and roadmaps for securing Radians application portfolio.
The Application Security Engineer is a key member of the Information Security team and works closely with Security Architecture Cloud Security Operational Security and Application Development. This position operates with a high degree of technical ownership and influence across the software development lifecycle.
See Your Primary Duties and Responsibilities:
Support and continuously optimize Application Security engineering capabilities. Maintain and enhance tool platforms (SAST/DAST/SCA) custom integrations and supporting processes in alignment with the Application Security program. Design and mature a centralized program leveraging DevSecOps infrastructure through close partnership with Development teams.
Plan and execute a wide range of Application Security activities including penetration testing threat modeling secure design reviews secure code reviews secure open-source software management and developer training and outreach. Partner with Risk Compliance and Assurance functions to support the organization in meeting its security and compliance obligations.
Provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews validate false positive determinations coach developers on effective remediation strategies and retest application and penetration test findings to confirm successful closure. Take a proactive approach to mentoring developers and other staff members.
Represent Application Security engineering on Information Security initiatives and cross-functional projects including the development and support of Python- and SQL-based data analytics ETL solutions. Operate and enhance program tooling DevSecOps integrations and automation to support evolving development environments and business needs.
Other related duties as assigned.
See the Job Specifications
Your Basic Education and Prior Work-Related Experience:
Degree Requirement: Bachelors Degree in Computer Science Cybersecurity Information Assurance or Network Security or a relevant field and/or 7 years of work experience in the IT Security field or Equivalent Experience
Work Experience: 6 or more years of prior work experience
Additional Qualifications:
Strong knowledge of administering Application Security technologies and testing practices including SAST DAST SCA WAF and penetration testing and integrating security controls into CI/CD pipelines and DevSecOps workflows.
Software development experience or demonstrated familiarity with automation and scripting using Python SQL and Git-based collaboration workflows.
Knowledge of securing modern development platforms and ecosystems including GitHub source control and CI/CD workflows AI coding assistants (e.g. GitHub Copilot).
Knowledge of secure coding practices and secure open-source package management across common languages and frameworks including Java JavaScript NodeJS Python React Angular and C#.
Knowledge of secure application design and architecture principles including client-server serverless and microservices-based architectures; access control best practices; and secure secrets management.
Knowledge of Secure SDLC best practices and activities with a process-oriented approach to maturing practices leveraging frameworks such as OWASP SAMM OWASP ASVS AWS Well-Architected Framework and related industry standards.
Strong written and verbal communication skills with the ability to lead and influence diverse groups and clearly explain complex technical concepts to audiences without similar technical backgrounds.
Excellent time management skills and the ability to effectively balance multiple objectives and priorities.
Strong analytical and troubleshooting skills.
A demonstrated desire commitment and ability to be a collaborative team player with a professional attitude and presentation.
Strong ability to mentor software developers in the identification understanding and remediation of application security weaknesses.
Ability to analyze and evaluate complex data and make sound recommendations with less-than-perfect information.
An excellent communicator and relationship builder who can translate complex security concepts into clear actionable guidance for non-technical stakeholders.
Your Preferred Education Level:
Bachelors Degree in Computer Science Cybersecurity Information Assurance or Network Security or in a relevant field.
7 years of work experience in the IT Security field.
Your Preferred Years of Prior Work-Related Experience:
Technical: 5-8 years
Other Qualifications including any special skills capabilities and competencies:
Security certifications such as CISSP CSSLP GWAPT AWS Solutions Architect or similar are desired
See Why You Should Work With Us
Competitive Compensation:anticipated base salary from $89000 to $146000 based on skills and experience. This position is eligible to participate in an annual incentive program.
Rest and Relaxation.This role is eligible for 25 days of paid time off annually which is prorated in the year of hire based on hire addition based on your hire date you will be eligible for 9 paid holidays 2 floating holidays. Parental leave is also offered as an opportunity for all new parents to embrace this exciting change in their lives.
Our Company Makes an Impact.Weve been recognized by multiple organizations like BloombergsGender-Equality IndexHousingWiresTech 100 and The Forum of Executive WomensChampion of Board Diversity. Radian has also pledged to SHRMsCEO Action for Inclusion & Diversitycommitment.
Comprehensive Health Benefits.Multiplemedical plan choices including HSA and FSA options dental vision and basic life insurance.
Prepare for your Future.401(k) with a top of market company match (did we mention the company match is immediately vested!) and an opportunity to participate in Radians Employee Stock Purchase Plan (ESPP).
Homebuyer Perks.Our Homebuyer Perks program helps employees navigate the home searching buying selling and refinancing processes and provides valuable financial benefits to encourage enable and support home ownership.
Additional Benefits.To learn more about our benefits offerings visit ourBenefits Page.
#LI-AB
The application period for the job is estimated to be 20 days from the job posting date. However this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.
Radian will consider for employment qualified applicants with arrest or conviction records in a manner consistent with the requirements of the law including any applicable fair chance law.
See More About Radian
Radian Group Inc. (NYSE: RDN) is a trusted global multi-line specialty insurer that helps businesses navigate risk with confidence. Built on financial strength and disciplined risk management Radian brings clarity to complex risk decisions through its proprietary view of risk and a global perspective.
Defining Roles for Radians Future
Understanding the qualities and characteristics that define a Leader and an Employee is important to building our future-fit workforce. Radians future is only as bright as its people. For that reason our People Plan includes profiles to support the qualities and characteristics that each Leader as well as each Employee should embody upon hire or via development.
EEO Statement
Radian complies with all applicable federal state and local laws prohibiting discrimination in employment. All qualified applicants will receive consideration for employment without regard to gender age race color religious creed marital status gender identity sexual orientation national origin ethnicity ancestry citizenship genetic information disability protected veteran status or any other characteristic protected by applicable federal state or local law.
An applicants criminal history may have a direct adverse and negative relationship with some of the material job duties of this position. The material duties include those listed in the Primary Duties and Responsibilities section above as well as the ability to adhere to Company policies exercise sound judgment effectively manage stressful situations work safely and respectfully with others exhibit trustworthiness and safeguard confidential information belonging to the Company and its customers. Pursuant to the California Fair Chance Act Los Angeles County Fair Chance Ordinance for Employers Fair Chance Initiative for Hiring Ordinance and San Francisco Fair Chance Ordinance we will consider for employment qualified applicants with arrest and conviction records.
Equal Opportunity Employer Details
To learn more about Radians Code of Conduct and Ethics and workplace conduct please click here. Radian participates in E-Verify Link (en español Link). Learn more about your rights under immigration laws Link (en español Link). View the Know Your Rights: Workplace Discrimination is Illegal poster Link. View Employee Rights under FMLA Link. View Employee Rights under EPPA Link.
Accommodation
Whether you require an accommodation for the job application or interview process Radian is dedicated to a barrier-free employment process and encourages a diverse workforce. If you have questions about the accommodation process please e-mail .
Please note that you may redact or remove age-related information that identifies your age date of birth or dates of attendance at or graduation from an educational institution on any additional application materials you submit as part of the application. Additional application materials include but are not limited to resumes CVs transcripts or certifications.
Required Experience:
IC