Cyber Security – Application Security Engineer, Associate
About this roleWe are seeking a motivated Application Security Penetration Tester and Code Reviewer to join our team. The ideal candidate will be responsible for ensuring the security and integrity of our software applications using comprehensive tools, heavily using AI and all types of security testing. This role involves performing penetration tests, secure designs, static code analysis, dynamic code analysis, and software composition analysis to identify and mitigate security vulnerabilities. The role could also include other tasks such as automations, pipeline configurations and more. Key Responsibilities: Configure and manage automated security testing tools to perform regular scans of the codebase in static code analysis, dynamic, and API tests. Perfom penetration tests on web apps, mobile apps, APIs, thick clients, network, cloud, AI Analyze the results of security scans and identify true positive findings. Collaborate with the development team to provide detailed feedback and recommendations for remediation of identified security issues. Document and report security findings, including mitigation strategies Handle the bug bounty program, help with analysis and triage where needed Qualifications and Tech skills: Bachelor's degree in Computer Science, Information Security, or a related field. Experience in application security, code review, and security testing. Basic knowledge of static and dynamic code analysis tools and techniques. Familiarity with software composition analysis tools and methodologies. Experience with automated security testing tools and their configuration. Familiarity with Java, C, C++, or .Net. Strong understanding of Object-Oriented Programming. Proficient in reading SQL statements. Knowledgeable about ADO pipelines. Familiarity with coding agent AI tools like Claude, Devin, Codex. Strong analytical and problem-solving skills. Good communication and collaboration skills to work effectively with development teams. Relevant certifications such as CISSP, CEH, or OSCP are a plus. Our benefitsTo help you stay energized, engaged and inspired, we offer a wide range of employee benefits including: retirement investment and tools designed to help you in building a sound financial future; access to education reimbursement; comprehensive resources to support your physical health and emotional well-being; family support programs; and Flexible Time Off (FTO) so you can relax, recharge and be there for the people you care about.Our hybrid work modelBlackRock’s hybrid work model is designed to enable a culture of collaboration and apprenticeship that enriches the experience of our employees, while supporting flexibility for all. Employe...