Application Security Engineer
Georgia-Pacific LLC · Atlanta, GA · Yesterday
RemoteRemoteInformation TechnologyFull-time
Your Job As the Application Security Engineer, you will be dedicated to strengthening and expanding our application security posture. You will collaborate closely with development, engineering, product, and other teams during every stage of the software development lifecycle (SDLC), and your insights will influence broader security initiatives throughout the organization. Within the GP Cyber Security Organization, this position is crucial in shaping the future of security at Georgia-Pacific. You will be part of a larger team comprised of Vulnerability Management, Security Operations, Application Security, and GRC capabilities. This role is based in Atlanta, GA at the GP HQ on Peachtree St. Expectation is three days in office per week. Our Team The Application Security team within GP Cyber Security is focused on reducing risk across the software development lifecycle by embedding secure development practices, operating our application security testing platforms, and driving vulnerability remediation. We partner closely with development, engineering, and product teams to deliver risk-based insights that enable secure, profitable business decisions. The team manages and tunes our application security tooling and collaborates with stakeholders onboarding applications into those tools to identify vulnerabilities and drive timely remediation across the enterprise. What You Will Do Partner with development teams to embed security standards and best practices into their work processesIdentify web application vulnerabilities, prioritize and risk-adjust findings, consult on mitigation strategies, and ensure timely resolutionDemonstrate self-motivation and direction while applying strong organizational and project management skills to plan, execute, and complete tasks in a timely and efficient mannerDesign and deliver training sessions for developers and stakeholders on secure coding practices, threat modeling, and risk assessmentMature our Application Security Testing (GHAS/Orca) platforms, collaborating with developers to address findings and minimize false positivesLead proactive code reviews to pinpoint vulnerabilities while refining and incorporating the Secure Development Lifecycle into our engineering processesOffer specialized application security guidance on projects, system issues, and in stakeholder meetings, including guidance on relevant industry standards and practices such as OWASP and CISAssist in developing and maintaining an ongoing security assurance program, including appropriate scripts and monitoring capabilities to verify security effectiveness, analyze data, develop trend analysis, and ensure compliance with existing standards, policies, and proceduresConduct technical security risk assessments with internal and external resources as needed Who You Are (Basic Qualifications) Experience testing and identifying vulnerabilities in web applications that utilize industry-standard frameworks such as React.js, Next.js, ASP.NET, and the .NET FrameworkExperience analyzing code and prioritizing findings using SAST, SCA, and DAST for security vulnerabilitiesExperience with programming and scripting languages (e.g., Python, PowerShell, C#, Java) and modern development practices such as CI/CD, containers, microservices, and infrastructure-as-codeExperience securing cloud environments (AWS and/or Azure), including IAM, security groups, and other native cloud security controlsExperience partnering across teams and influencing without direct authority to achieve business outcomesMust have legal authorization to work permanently in the United States for any employer without requiring a visa transfer or visa sponsorship What Will Put You Ahead Experience with citizen development within ServiceNowExperience troubleshooting network security controls, firewalls, and remote access technologiesExperience aggregating data from various sources for security analysis and reporting (e.g., scripting, SQL, PowerShell, Python, .NET, Java, JavaScript, Go)Experience building tools utilizing AI, LLM, machine learning, and code analysis platformsApplication security certifications (e.g., EC-Council Certified Application Security Engineer (CASE), Offensive Security Certified Professional (OSCP), etc.)AWS Certified Solutions Architect or comparable certification At Koch companies, we are entrepreneurs. This means we openly challenge the status quo, find new ways to create value and get rewarded for our individual contributions. Any compensation range provided for a role is an estimate determined by available market data. The actual amount may be higher or lower than the range provided considering each candidate’s knowledge, skills, abilities, and geographic location. If you have questions, please speak to your recruiter about the flexibility and detail of our compensation philosophy. Hiring Philosophy All Koch companies value diversity of thought, perspectives, aptitudes, experiences, and backgrounds. We are Military Ready and Second Chance employers. Learn more about our hiring philosophy here. Who We Are As a Koch company and a leading manufacturer of bath tissue, paper towels, paper-based packaging, cellulose, specialty fibers, building products and much more, Georgia-Pacific works to meet evolving needs of customers worldwide with quality products. In addition to the products we make, we operate one of the largest recycling businesses. Our more than 30,000 employees in over 150 locations are empowered to innovate every day – to make everyday products even better. At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company. Our Benefits Our goal is for each employee, and their families, to live fulfilling and healthy lives. We provide essential resources and support to build and maintain physical, financial, and emotional strength focusing on overall wellbeing so you can focus on what matters most. Our benefits plan includes medical, dental, vision, flexible spending and health savings accounts, life insurance, ADD, disability, retirement, paid vacation/time off, educational assistance, and may also include infertility assistance, paid parental leave and adoption assistance. Specific eligibility criteria is set by the applicable Summary Plan Description, policy or guideline and benefits may vary by geographic region. If you have questions on what benefits apply to you, please speak to your recruiter. Equal Opportunities Equal Opportunity Employer, including disability and protected veteran status. Except where prohibited by state law, all offers of employment are conditioned upon successfully passing a drug test. This employer uses E-Verify. Please visit the following website for additional information: http://www.kochcareers.com/doc/Everify.pdf