Staff Application Security Engineer

Staff Application Security Engineer

Full-Time No working from home possible
Bazaarvoice

Staff Application Security Engineer

We are seeking a Staff Application Security Engineer to serve as a high-level technical leader and subject matter expert for our application security program. In this role, you will bridge the gap between security and engineering, driving the adoption of secure‑by‑default architectures and robust secrets management practices through a development-centric approach.

You will carry significant influence across all of our engineering offices, tackling complex software security challenges by writing code to automate data correlation and tool integration, while collaborating closely with Offensive Security to validate and remediate systemic risks. As a Professional Level 7, you will operate with a high degree of autonomy, providing critical technical expertise during investigations, participating in technical whiteboard coding sessions, and mentoring engineers to foster a culture of security‑first development.

Responsibilities

  • Lead Application Security Elements – Own the execution and technical oversight of application security components, ensuring robust security controls are integrated throughout the development process.
  • Automated Pipeline Guardrails – Design and write automated security guardrails directly inside the CI/CD pipeline using open‑source and commercial tools to catch vulnerabilities early.
  • Vulnerability Data Orchestration – Write scripts and API tools to query, aggregate, and correlate data from vulnerability datasets, asset management systems, and scanners to drive automated JIRA ticketing and data‑driven risk decisions.
  • Secrets Management Leadership – Lead and manage the enterprise secrets management program, defining technical standards and implementing solutions to protect sensitive credentials across all environments, writing programmatic integrations to securely inject and rotate credentials.
  • Offensive Security Collaboration – Partner closely with the Offensive Security Engineer on complex projects to proactively identify, validate, and remediate deep‑seeded application vulnerabilities.
  • Incident Response & Forensic Support – Provide deep technical expertise and hands‑on assistance during security events or investigations, helping engineering teams perform root‑cause analysis in the codebase and mitigate impact.
  • Secure SDLC & Threat Modeling – Proactively engage with development teams early in the SDLC to conduct threat modeling exercises focused on logical application flaws and provide expert consultation on secure architecture.
  • Mentorship and Advocacy – Act as a security champion and trusted advisor, elevating security knowledge across the organization through training and the development of secure coding guidelines.

Qualifications

  • Education & Experience: Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience with 7+ years of professional experience.
  • Software Engineering Background: Strong background in software development in a SaaS environment, with a proven ability to write clean, maintainable code and pass a live/whiteboard coding session.
  • Application Security Expertise: 5+ years of hands‑on experience in application security, including secure code review, threat modeling, and managing AppSec tooling.
  • API & Data Integration: Proven experience writing code to query APIs, parse datasets (JSON/XML), and integrate disparate tools.
  • Secrets Management Proficiency: Proven experience implementing and managing enterprise‑grade secrets management solutions at scale.
  • Technical Remediation: Expert-level knowledge of OWASP Top 10 and advanced vulnerability classes, with a demonstrated ability to architect and implement scalable remediation solutions.
  • Scripting & Automation: Proficiency in languages such as Python, Go, or Bash to automate security workflows, query APIs, and build custom security integrations.
  • Influence & Communication: Exceptional communication skills with the ability to influence technical and non‑technical stakeholders across multiple global offices.
  • Mentorship: A proven history of mentoring senior‑level engineers and a passion for elevating the skills of those around you.
  • Certifications: Professional certifications such as CSSLP, CASE, GWEB, or equivalent.
  • Cloud Operations: Expertise in AWS or GCP security operations, specifically relating to serverless and containerized application security.
  • DevSecOps: Experience in a Security Development Lifecycle (SDL) environment and a history of implementing DevSecOps principles.
  • Community Engagement: Published security research, conference presentations, or active contributions to the open‑source security community.

Commitment to Diversity and Inclusion

Bazaarvoice provides equal employment opportunities (EEO) to all team members and applicants according to their experience, talent, and qualifications for the job without regard to race, color, national origin, religion, age, disability, sex (including pregnancy, gender stereotyping, and marital status), sexual orientation, gender identity, genetic information, military/veteran status, or any other category protected by federal, state, or local law in every location in which the company has facilities. Bazaarvoice believes that diversity and an inclusive company culture are key drivers of creativity, innovation and performance. Furthermore, a diverse workforce and the maintenance of an atmosphere that welcomes versatile perspectives will enhance our ability to fulfill our vision of creating the world’s smartest network of consumers, brands, and retailers.

Please note: The successful candidate will be required to undergo a basic AccessNI check prior to starting.

#J-18808-Ljbffr

Staff Application Security Engineer employer: Bazaarvoice

Bazaarvoice is an exceptional employer that fosters a dynamic and innovative work culture, perfect for high-performing individuals eager to make an impact in the EMEA market. With a strong focus on employee growth and development, we offer comprehensive training and mentorship opportunities, ensuring you thrive in your role as a Strategic Retail Account Executive. Located in the UK, our team enjoys a collaborative environment that encourages creativity and strategic thinking, making it an ideal place for those looking to excel in their careers.

Bazaarvoice

Contact Details:

Bazaarvoice Recruitment Team