Jobs
>
Santa Ana

    Application Security Lead Engineer - Santa Ana, United States - First American

    Default job background
    Description
    Who We Are

    Join a team that puts its People First Since 1889, First American (


    NYSE:
    FAF) has held an unwavering belief in its people.

    They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential.

    Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For list for eight consecutive years.

    We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists.

    First American will always strive to be a great place to work, for all. For more information, please visit

    What We Do


    As an Application Security Lead, you will be a key member of the Information Security group, leading a team responsible for our overall secure Software Development Life Cycle (SDLC) program.

    The successful candidate will be responsible for defining application security requirements and ensuring the delivery of secure applications and solutions.

    The Application Security program is designed to ensure that any software developed by our engineers meets our overall security goals to protect our data.

    The successful candidate will exhibit the skills of an experienced leader, with a disciplined approach to process.

    You will work with a group tasked with coordinating across many functional teams to ensure that our applications stay at the highest security level.

    In a dynamic rapidly growing organization, you will be required to be innovative and collaborative to be successful. Candidate must be comfortable working and communicating with executives and can work at a deep technical level with engineers.


    What You'll Do:
    Conduct comprehensive security assessments of applications, systems, and networks to identify vulnerabilities, assess risks, and provide recommendations for enhancement.

    Collaborate closely with development and operations teams to integrate robust security practices into the software development lifecycle (SDLC) while ensuring compliance with stringent security requirements.

    Provides consultative leadership and implementation guidance for application teams in the areas of vulnerability remediation and mitigation.

    Develop and enforce secure coding practices, offering guidance to developers on coding best practices, security standards, and effective vulnerability remediation.

    Stay abreast of the latest threats, vulnerabilities, and industry best practices in application security. Proactively identify and mitigate potential risks.

    Monitor, investigate, and respond to security incidents, conducting in-depth root cause analyses, and be consulted on implementing corrective measures to prevent recurrence.

    Execute security testing, encompassing vulnerability scanning, penetration testing, and code review, to pinpoint and address security weaknesses.
    Collaborate with cross-functional teams to undertake threat modeling, risk assessments, and security architecture reviews for new applications and systems.

    Researches, identifies, and documents best practice methods and emerging technologies, evaluating applicability and feasibility to support key business processes and requirements.

    Manages optimal enterprise application security processes, standards, and technologies.
    Define, collect, and communicate application vulnerability metrics across all levels of the organization, utilizing the metrics to aid in analyzing the likelihood of emerging threats impacting the organization and identifying the weaknesses that could be potentially exploited
    Be consulted on incident response efforts, including the investigation, mitigation, and resolution of security incidents.

    What You'll Bring

    A Bachelor's degree in Computer Science, Information Security, or a related field, or relevant working experience.

    A minimum of 5 years of experience in application security, including expertise in web application security, mobile application security, cloud security, and secure coding practices.

    A solid grasp of secure software development practices, encompassing threat modeling, risk assessment, and vulnerability management.
    Familiarity with pertinent industry standards and frameworks such as the OWASP Top Ten Project, NIST Cybersecurity Framework, and ISO/IEC

    Proficiency in handling security tools and technologies, including web application scanners, vulnerability scanners, penetration testing tools, SIEM systems, and Certified Application Security Engineer (CASE) certification.

    In-depth knowledge of common application security vulnerabilities, such as cross-site scripting (XSS), SQL injection, and cross-site request forgery (CSRF). The ability to provide guidance on effective mitigation strategies is essential.
    A strong understanding of network protocols, operating systems, and web technologies.

    Outstanding communication and interpersonal skills, with the capacity to effectively convey intricate security concepts to both technical and non-technical stakeholders.

    Certifications like Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), and Certified Application Security Engineer (CASE) are highly regarded.

    Familiarity with generative AI coding solutions and a substantial technical software development background, enabling you to lead the team in adhering to software best practices.

    Proficiency in scanning code and effectively mitigating and remediating findings.

    Pay Range:
    $96,180- $183,480 annual


    This hiring range is a reasonable estimate of the base pay range for this position at the time of posting.

    Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location.

    #LI-BL1

    What We Offer


    By choice, we don't simply accept individuality – we embrace it, we support it, and we thrive on it Our People First Culture celebrates diversity, equity and inclusion not simply because it's the right thing to do, but also because it's the key to our success.

    We are proud to foster an authentic and inclusive workplace For All. You are free and encouraged to bring your entire, unique self to work. First American is an equal opportunity employer in every sense of the term.


    Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.



  • Banc of California Santa Ana, United States

    Overview: · Banc of California, Inc. (NYSE: BANC) is a bank holding company headquartered in Los Angeles with one wholly-owned banking subsidiary, Banc of California (the "bank"). Banc of California is one of the nation's premier relationship-based business banks focused on provi ...


  • ANDURIL INDUSTRIES Costa Mesa, United States

    Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduri ...

  • Stellar Innovations

    Lead Engineer

    1 day ago


    Stellar Innovations Upland, United States

    Bühler Leybold Optics stands for innovative technologies and continuous growth. As part of the Bühler Group, a globally operating mechanical engineering company with over employees, we are one of the leading manufacturers of high-tech thin-film vacuum coating systems. For more t ...

  • Avangrid

    Lead Engineer

    3 weeks ago


    Avangrid Orange, United States Full time

    Job Title: Lead Engineer- Protection and Control · Reports to: Supervisor - Protection & Control - Philosophy and Standards · Reporting hybrid to Orange CT, Rochester NY, Augusta ME, Binghamton NY · Salary Range $101,400 -$139,431 · The Philosophy and Standards group is a support ...

  • Meta

    QA Engineering Lead

    2 weeks ago


    Meta Los Angeles, United States

    **QA Engineering Lead - Dogfooding Responsibilities**: · - Build a user-centric engineering culture that drives improvements in quality · - Implement process changes to scale testing efforts across multiple products · - Partner with internal first-party product development teams ...


  • Sargent & Lundy Santa Ana, United States

    Lead Electrical Engineer City Santa Ana State CA Country United States Area of Interest Electrical Engineering Type Full Time - Regular Job ID Business Group Electric Grid Infrastructure Services Department Substation Engineering Descripti Electrical Engineer, Electrical, Project ...

  • Akkodis

    Lead DevOps Engineer

    3 weeks ago


    Akkodis Santa Ana, United States

    **PLEASE ONLY APPLY IF YOU ARE LOCATED IN CALIFORNIA AND OPEN TO WORKING ON-SITE · Job Summary · The Lead DevOps Engineer will be responsible for overseeing and orchestrating the technical delivery of our Clients products and services. This role requires a blend of technical expe ...

  • First American

    Lead DevOps Engineer

    3 weeks ago


    First American Santa Ana, United States

    Who We Are · Join a team that puts its People First Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and emp ...


  • First American Santa Ana, United States

    Who We Are · Join a team that puts its People First As a member of the First American family of companies, First American Trust is a federal savings bank that has provided banking, wealth management, and trust solutions on a national, full-service basis for more than five decade ...


  • First American Santa Ana, United States

    Who We Are · Join a team that puts its People First Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and emp ...


  • First American Santa Ana, United States

    Who We Are · Join a team that puts its People First As a member of the First American family of companies, First American Trust is a federal savings bank that has provided banking, wealth management, and trust solutions on a national, full-service basis for more than five decade ...


  • Akkodis Santa Ana, United States

    **PLEASE ONLY APPLY IF YOU ARE LOCATED IN CALIFORNIA AND OPEN TO WORKING ON-SITE · Apply promptly A high volume of applicants is expected for the role as detailed below, do not wait to send your CV. · Job Summary · The Lead DevOps Engineer will be responsible for overseeing an ...


  • BlueWave Solutions Azusa, CA, United States Freelance

    For our client, Sunfire GmbH, we are looking for a Direct Hire Lead Mechanical Engineer for Piping and Plant Construction (m/f/d) in Dresden, Germany. The position is available immediately and is full-time. · Benefits: · - Competitive salary: Up to 60,000€ per year, depending on ...


  • First American Santa Ana, United States

    Who We Are · Join a team that puts its People First Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empo ...


  • First American Santa Ana, United States

    Who We Are · Join a team that puts its People First Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and emp ...

  • Kaiser Permanente

    Lead Engineer

    4 weeks ago


    Kaiser Permanente Irvine, United States

    Job Summary: · Under general supervision, the Lead Engineer directs the activity of assigned personnel and service contractors in the preventive and corrective maintenance of buildings, grounds as well as related fixed and portable equipment, minor construction and equipment inst ...

  • Kaiser Permanente

    Lead Engineer

    3 weeks ago


    Kaiser Permanente Irvine, United States

    : Job Summary: · Under general supervision, the Lead Engineer directs the activity of assigned personnel and service contractors in the preventive and corrective maintenance of buildings, grounds as well as related fixed and portable equipment, minor construction and equipment i ...

  • ABM Industries

    Lead Engineer

    2 weeks ago


    ABM Industries Irvine, United States

    Job Description · Pay: $52.00 per hour · The pay listed is the hourly range or the hourly rate for this position. A specific offer will vary based on applicant's experience, skills, abilities, geographic location, and alignment with market data. · Benefits Information · ABM o ...


  • Banc of California, N.A. Santa Ana, United States

    Lead and mentor a software delivery team. Collaborate with stakeholders and team members. Investigate and propose solutions to development and design problems. Develop meaningful architectures, designs, implementations, security standards, and best p Software Engineer, Technical, ...

  • ABM Industries

    Lead Engineer

    3 weeks ago


    ABM Industries Irvine, United States

    Job Description · Pay: $52.00 per hour · The pay listed is the hourly range or the hourly rate for this position. A specific offer will vary based on applicant's experience, skills, abilities, geographic location, and alignment with market data. · Benefits Information · ABM offe ...