
Senior Application Security Engineer
CoBank
Visa & sponsorship
- The posting says it will not sponsor a visa for this role.
Job description
Benefits Overview:
A career at CoBank can offer you the opportunity to make a personal impact on the people and communities where we do business. In order to be the best, we hire the best!
Benefits Offered by CoBank
-
Careers with a purpose
-
Time-Off Packages, 15 days of vacation, 10 paid sick days and 11 paid holidays
-
Competitive Compensation & Incentive
-
Hybrid work model: flexible arrangements for most positions
-
Benefits Packages, including Medical, Dental and Vision coverage, Disability, AD&D, and Life Insurance
-
Robust associate training and development with CoBank University
-
Tuition reimbursement for higher education
-
Outstanding 401k: up to 6% matching and additional 3% non-elective contribution & Student Loan Match
-
Community Impact: United Way Angel Day, Volunteer Day and Associate Directed Contribution
-
Associate Resource Groups: creating a culture of respect and inclusion
-
Recognize a fellow associate through our GEM awards
Job Description:
Join CoBank's high-performing Application Security team and help protect the applications, cloud services, and data that support our business. You will collaborate with engineering and DevOps teams to integrate security into application development, CI/CD pipelines, cloud platforms, and containerized environments. In this role, you will support enterprise application and cloud security technologies, conduct security testing and risk assessments, help drive vulnerability remediation, and participate in security investigations. You will also provide expertise in secure coding, cloud-native security controls, software supply chain security, and third-party risk. By exploring emerging threats and technologies and recommending practical improvements, you will help ensure CoBank's technology remains secure, compliant, and resilient.
Essential Functions:
-
Implements and supports Enterprise Security projects related to application and cloud solutions and technologies. Ensures security standards and best practices are appropriately integrated into the development, deployment, and hosting of applications, including GitHub repositories, AWS, and Kubernetes environments.
-
Acts as champion for secure coding principles, performs Static & Dynamic Application Security Testing (SAST/DAST), and administers application security testing tools such as Checkmarx, Upwind and other similar capabilities. Partners with DevOps teams to embed security into CI/CD pipelines and remediate vulnerabilities.
-
Administers and manages the Cloud Native Application Protection Platform (CNAPP), such as Upwind, providing runtime protection, vulnerability management, and workload security across cloud and container environments.
-
Conducts software supply chain security and third-party and vendor risk assessments using tools such as Venminder, evaluating SaaS and third-party hosted services to identify and mitigate risk to CoBank data.
-
Assists with the scheduling, oversight, and execution of annual Penetration Testing events with external, 3rd party testing partners. Evaluates findings and communicates remediation plans to internal stakeholders.
-
Participates in large-scale projects as an application and cloud security subject matter expert. Advises on secure application and cloud architectural design and controls.
-
Monitors, evaluates, and responds to alerts or notifications from various security systems. Participates in Security team on-call rotation (24/7), approximately 1 week/quarter.
-
Reviews and provides input to security policies, standards, procedures and guidelines.
-
Understands legislative, regulatory, and marketplace environments to ensure the bank security practices comply with those requirements and remains current with accepted practices.
-
Conducts investigations of potential non-compliance with Enterprise Security policies and procedures.
-
Reviews IAM policies and permissions with cloud administrators to ensure least-privilege access and regulatory compliance for cloud applications.
-
Researches, evaluates, and makes recommendations on emerging application and cloud security trends and technologies, including the secure and governed use of AI-assisted development tools.
Education:
-
Bachelor's Degree in Computer Science, Cybersecurity, Engineering, or a related field required
-
Bachelor's degree may be substituted with four years of related experience (four years is in addition to what is minimally required for the role), or an equivalent combination of education and related experience.
Work Experience:
-
5 years of hands-on cybersecurity experience in application security including experience with modern CI/CD pipeline and containerized environments required
-
3 years of experience reviewing code via static and dynamic application security testing tools (SAST/DAST), utilizing management tools such as GitHub, and providing secure coding guidance required
-
2 years of hands-on and in-depth security experience with major cloud platforms, such as AWS, and container orchestration platforms, such as Kubernetes required
-
Prior Experience , exposure to and comfort utilizing AI tools for workflow automation. Familiarity with AI security concepts and impacts on application security preferred
-
Prior Experience in the financial services industry, particularly the banking sector preferred
-
Thorough understanding of OWASP Top 10 Projects with a focus on Web Applications, APIs, and CI/CD security
-
Thorough understanding of MITRE Common Weaknesses and Exposures (CWE) and ability to communicate scanning results and remediations to DevOps partners
-
Experience with scripting languages and ability to automate secure deployment of cloud apps and workloads (e.g. Terraform)
-
Understanding of logging and monitoring in the cloud, and experience with log analysis (CloudTrail, Splunk, Upwind)
-
Hands-on experience with application and cloud security tools such as SAST/DAST, CNAPP, SASE, CASB, and WAF (Checkmarx, Upwind)
-
Able to configure and manage application scanning and static code analysis tools. Thorough understanding of Web application security concepts, principles, and guidelines
-
Solid understanding of cloud security frameworks and implementing best practices, such as MITRE ATT&CK, CSA, CIS, and NIST.
-
Experience with DevOps and DevSecOps methodologies and practices
-
Excellent analytical, time management, decision making, and problem solving skills
-
Excellent customer service, interpersonal, and verbal and written communication skills, with the ability to build and maintain effective relationships with all levels of management, team members and customers
-
Ability to work independently, as well as collaboratively in a team environment
-
High degree of personal integrity and trustworthiness
Physical Exertion Details:
Sedentary Exerting up to 10 pounds of force occasionally (Occasionally: activity or condition exists up to 1/3 of the time) and/or a negligible amount of force frequently (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull, or otherwise move objects, including the human body. Sedentary work involves sitting most of the time, but may involve walking or standing for brief periods of time. Jobs are sedentary if walking and standing are required only occasionally and all other sedentary criteria are met.
Travel Requirement Details:
Occasional Travel occurs infrequently (typically, once a month or less).
About CoBank:
The typical base pay range for this role is between $121,000 - $148,900. Compensation may vary based on individual job-related knowledge, skills, expertise, and experience. This position is eligible for a discretionary annual incentive program driven by organization and individual performance. The listed salary, other compensation and benefits information is accurate as of the date of this posting. This job will be posted for a minimum of five (5) business days or until the position is filled. CoBank reserves the right to adjust compensation for all positions and to modify or discontinue benefits programs at any time in its sole discretion, subject to applicable law.
CoBank is a cooperative bank serving vital industries across rural America. The bank provides loans, leases, export financing and other financial services to agribusinesses and rural power, water and communications providers in all 50 states. The bank also provides wholesale loans and other financial services to affiliated Farm Credit associations serving more than 76,000 farmers, ranchers and other rural borrowers in 23 states around the country. CoBank is a member of the Farm Credit System, a nationwide network of banks and retail lending associations chartered to support the borrowing needs of U.S. agriculture, rural infrastructure and rural communities. Headquartered outside Denver, Colorado, CoBank serves customers from regional banking centers across the U.S. and also maintains an international representative office in Singapore.
REASONABLE ACCOMMODATION
We are committed to ensuring that our online application process provides an equal employment opportunity to all applicants, including qualified individuals with disabilities. If you are an applicant with a disability, or are assisting an applicant with a disability, and require accessibility assistance or would like to request a reasonable accommodation for any aspect of the application process, including completing an application, interviewing, or otherwise participating in the employee selection process, please submit a request by emailing recruiting@cobank.com. Include your contact information and specific details about your requested accommodation.
Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time.
CoBank is an Equal Opportunity Employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability, or status as a protected veteran.