At a Glance
- Tasks: Ensure the security of web, API, and mobile applications through collaboration and testing.
- Company: Join Planet, a global leader in integrated technology and payments solutions for retail and hospitality.
- Benefits: Enjoy a hybrid work model, diverse culture, and opportunities for career growth.
- Why this job: Be part of a fast-paced tech environment that values security and innovation.
- Qualifications: 3+ years in application security; proficiency in security tools and methodologies required.
- Other info: Planet promotes diversity and offers reasonable accommodations for all employees.
The predicted salary is between 42000 - 84000 £ per year.
About Planet
Planet is a global provider of integrated technology and payments solutions for retail and hospitality customers. We create great experiences for the millions of people who use our payments, software, and tax-free solutions every minute of every day. Planet empowers its customers to deliver great customer experiences by combining payments and software in ways that drive greater loyalty, increase revenue and save time. Founded over 35 years ago and with our headquarters in London, today we have more than 2,500 employees located across six continents serving our customers in more than 120 markets.
Role Overview:
As an Application Security Engineer, you will be responsible for ensuring the security of web applications, APIs, and mobile applications (APKs). You will work closely with Product and Engineering teams to conduct threat modeling for new applications, embedding security into the development lifecycle and enabling a 'shift left' approach to secure engineering practices. Additionally, you will empower engineering teams to write secure code by providing guidance, implementing security best practices, and conducting application security testing, including penetration testing, to proactively identify and mitigate vulnerabilities.
What you will do:
- Collaborate with product and engineering teams to integrate security good practice, and threat modelling into the software development lifecycle.
- Continuously improve security testing methodologies, processes and tools (SAST and DAST) with the Engineering teams.
- Conduct comprehensive manual penetration tests on web applications, APIs, and mobile applications (APKs) to identify vulnerabilities.
- Work with Product and Engineering teams to manage vulnerabilities and security penetration test findings from discovery to timely remediation.
- Perform segmentation tests to ensure proper network segmentation and isolation of critical assets.
- Support the definition and implementation of security requirements for new solutions.
- Enable teams compliance to comply with industry standards and regulations including PCI DSS.
Who you are:
- Minimum 3 years of experience in application security or related roles.
- Proficiency in using application security tools such as Nexpose, Tenable, Rapid7, OpenVAS, Invicti, DASTerdly, Snyk, Checkmarx, Sonar and penetration testing tools such as Burp Suite, Metasploit, etc.
- Preferred certifications include eWPT, PNPT, OSCP, CISSP, GWAPT, or similar.
- Great awareness of cybersecurity trends and hacking techniques.
- Knowledge of IT general controls, and of standards and methodologies related to OWASP, PTES, NIST, CIS, PCI DSS, ISO 27001.
- A clear understanding of pentest methodologies.
- Promote a culture of security within the organization.
- Ability to work under pressure in a fast-paced environment.
- Strong attention to detail with an analytical mind and outstanding problem-solving skills.
- Excellent communication skills, both verbal and written.
Why Planet:
Planet is an equal opportunity employer where diversity is valued, and all employment is decided based on qualifications, merit, and business need. Come and grow your career in the most exciting, fast paced technology market, with a business that delivers feel-good connected commerce. We would love to hear from you - Apply now. At Planet, we embrace a hybrid work model, with three days a week in the office. Reasonable accommodations may be made in order to allow for an individual to perform the essential functions of this role successfully.
Application Security Engineer employer: Planet
Contact Detail:
Planet Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Application Security Engineer
✨Tip Number 1
Familiarise yourself with the specific application security tools mentioned in the job description, such as Burp Suite and Metasploit. Having hands-on experience with these tools will not only boost your confidence but also demonstrate your practical skills during interviews.
✨Tip Number 2
Stay updated on the latest cybersecurity trends and hacking techniques. Being knowledgeable about current threats and vulnerabilities will show your passion for the field and your commitment to continuous learning, which is crucial for an Application Security Engineer.
✨Tip Number 3
Prepare to discuss your experience with threat modelling and secure coding practices. Be ready to share specific examples of how you've integrated security into the software development lifecycle in previous roles, as this aligns closely with the responsibilities of the position.
✨Tip Number 4
Highlight your ability to work under pressure and your problem-solving skills during the interview. Provide examples of past experiences where you successfully managed vulnerabilities or conducted penetration tests, showcasing your analytical mindset and attention to detail.
We think you need these skills to ace Application Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in application security, including specific tools and methodologies you've used. Emphasise your proficiency with security tools like Burp Suite and Nexpose, as well as any certifications you hold.
Craft a Strong Cover Letter: In your cover letter, explain why you're passionate about application security and how your skills align with the role at Planet. Mention your experience with threat modelling and secure coding practices to demonstrate your fit for the position.
Showcase Your Problem-Solving Skills: Provide examples of past projects where you identified vulnerabilities and implemented solutions. Highlight your analytical mindset and attention to detail, which are crucial for an Application Security Engineer.
Research Planet: Familiarise yourself with Planet's products and services. Understanding their technology and customer base will help you tailor your application and show your enthusiasm for contributing to their mission.
How to prepare for a job interview at Planet
✨Showcase Your Technical Skills
Be prepared to discuss your experience with application security tools and penetration testing methodologies. Highlight specific projects where you successfully identified and mitigated vulnerabilities, as this will demonstrate your hands-on expertise.
✨Understand the Company’s Security Needs
Research Planet's approach to security and their specific requirements for the role. Familiarise yourself with their products and services, and think about how your skills can enhance their security posture.
✨Communicate Clearly
Since excellent communication skills are essential for this role, practice explaining complex security concepts in simple terms. Be ready to discuss how you would collaborate with product and engineering teams to embed security into the development lifecycle.
✨Stay Updated on Cybersecurity Trends
Demonstrate your awareness of current cybersecurity trends and hacking techniques during the interview. This shows that you are proactive and committed to staying informed in a rapidly evolving field.