Application Security Engineer - ADR
State Street · Atlanta, GA · 1 mo ago
Information Technology$120k–$203k/yrFull-time
About the role
The State Street Cyber Security Architecture & Engineering team is seeking an accomplished professional with proven expertise in Application Security (AppSec), Application Detection and Response (ADR), and DevSecOps.
Responsibilities
- Help define and build the organization's Application Detection and Response (ADR) strategy, integrating runtime application security monitoring and threat detection into the broader Application Security and DevSecOps programs.
- Partner with Engineering, Security Operations, Cloud Security, and Application Development teams to implement and operationalize ADR technologies and processes.
- Lead the deployment, onboarding, and operational support of ADR platforms, ensuring effective integration with enterprise applications and security tooling.
- Maintain and monitor application-layer security events, attack patterns, and anomalous behaviors identified through ADR solutions.
- Collaborate with application teams to triage, prioritize, and remediate security findings, threats, and attack indicators detected within applications.
- Develop use cases, detection logic, alerting mechanisms, and response workflows to improve visibility into application threats and reduce response times.
- Integrate ADR platforms with incident response processes.
- Deliver and communicate security reporting, dashboards, metrics, and executive-level summaries related to application threats, attacks, and remediation activities.
- Develop and maintain ADR, AppSec, and DevSecOps documentation, standards, and operational procedures.
- Support internal and external audits by providing evidence, documentation, and process adherence related to application security monitoring and response capabilities.
- Work with stakeholders to continuously improve application monitoring, detection accuracy, response effectiveness, and security processes.
- Provide technical leadership and support for strategic projects through planning, implementation, and operationalization.
Qualifications
- Strong software development background with technologies such as Java, .NET, Python, Node.js, or similar platforms.
- Experience with cloud technologies including Azure and AWS.
- Experience in Application Security disciplines, including SAST, DAST, SCA, API Security, Container Security, and Secure SDLC practices.
- Experience implementing or supporting Application Detection and Response (ADR), Runtime Application Self-Protection (RASP), Web Application and API Protection (WAAP), API Security, Threat Detection, or related application security technologies.
- Strong understanding of attack techniques targeting web, mobile, cloud-native, and API-based applications, including OWASP Top 10, API security risks, and advanced threat scenarios.
- Experience analyzing application telemetry, logs, traces, and security events to identify malicious activity and investigate incidents.
- Current information security certifications such as CISSP, GCIH, GWAPT, or equivalent is highly desirable.
- Experience with automation and orchestration technologies such as Ansible, Terraform, Kubernetes, and Infrastructure as Code (IaC) practices.
- Proven technical solutioning experience with current and emerging technologies including Agile Development, DevOps, Cloud Engineering, Cloud Security, Application Security, Threat Detection, Incident Response, and Cybersecurity.
- Excellent verbal and written communication skills with the ability to communicate effectively across technical, operational, and executive audiences.
- Able to prioritize and manage multiple initiatives, operational responsibilities, incidents, and projects simultaneously.
Education & Preferred Qualifications
- Bachelor’s degree in information technology (IT), computer science, or related field with 6 years of relevant experience.
- Experience in software development and secure software development lifecycle (SDLC).
- Experience with application security tooling and its operations with modern CI/CD, and DevSecOps best practices.
- Experience partnering with Dev community to influence without authority to adopt application security best practices, and tooling.
- Security+ or other cybersecurity security certification.
- Experience with Agile and scrum practices.
Pay
$120,000 - $202,500 Annual
Schedule
N/A
Benefits
N/A
Application Instructions
N/A