HomeStreet Bank Logo

HomeStreet Bank

Application Security Engineer

Posted 4 Days Ago
Be an Early Applicant
In-Office
8 Locations
130K-170K Annually
Mid level
In-Office
8 Locations
130K-170K Annually
Mid level
The Application Security Engineer secures the bank's applications through penetration testing, threat hunting, and incident response while leading DevSecOps discussions.
The summary above was generated by AI

Mechanics Bank is currently searching for an Application Security Engineer to join our team. Here at Mechanics Bank, we value connection, partnership, long term relationships and working together in person. This role can work remote within the US.

Under limited direction, the Application Security Engineer is responsible for securing the bank’s network and external-facing applications through continuous penetration testing, application code review, threat hunting, web application firewall management, and vulnerability scanning. This role requires effective communication of remediation requirements to both technical and business leaders. Additionally, the engineer takes a leading role in DevSecOps process discussions and planning.

What you will do:

  • Defines security requirements for the implementation of new applications and projects: Serves as a security engineer/consultant on projects, works closely with the application development team to ensure coding follows security best practices, provides security guidance during the design and implementation phases to ensure robust security controls are integrated from the start.
  • Performs continuous penetration testing: Effectively documents and reports findings, illustrating risks and requirements for resolution. Recommends and implements improvements based on testing outcomes.
  • Leads security research on threats and remediation techniques and technology: Makes informed recommendations to Information Security and Information Technology teams, oversees the implementation of recommended security measures.
  • Conducts security event analysis and intrusion detection (IDS/IPS): Leads incident response efforts, including triage, incident analysis/forensics, and remediation. Develops and refines incident response processes and playbooks.
  • Serves on the Incident Response Team: Focuses on Computer Incident Response, coordinates with various teams to ensure a cohesive and effective incident response.
  • Supports the Bank’s operational information security responsibilities, including the development and maintenance of standards, procedures, and guidelines necessary to satisfy the Information Security department’s network operations.
  • Manages and enhances the bank’s network vulnerability management program: Regularly assesses and updates vulnerability management practices to ensure they meet current security standards and address emerging threats.
  • Assists in conducting risk assessments to evaluate the effectiveness of existing controls and determine the impact of proposed changes to business processes, applications and systems.
  • Provides technical support to regulatory agencies, external auditors, and internal auditors, as required, to respond to audits and examinations of the Bank’s control environment

Who you are:

  • Preferred: Bachelor’s Degree in a related field, or equivalent education, certifications, and experience
  • Required: 3 - 5 years’ experience in application security, penetration testing, or a comparable role
  • Required: Understanding of one or more of the following programming languages: C#, Angular JavaScript, T-SQL
  • Preferred: Industry Standard Certifications, such as: CompTIA CASP+; GIAC, EC-Council, (ISC)2, OSCP, CompTIA Linux+; ISC2 CISSP, CompTIA Network+
  • Understanding of one or more scripting languages.
  • Understanding of Linux, Windows, and Mac OS.
  • Passion for automation and scripting (Python, Perl, Bash, PowerShell, etc.).
  • Strong technical skills with Microsoft Office; must have the ability to effectively communicate and write reports understandable to both business and technical staff.
  • Threat analysis / Incident Response: interpreting events and analyzing network traffic.
  • Mitigating and addressing threat vectors including XSS, broken authentication, SQL injections, SSRF, misconfigurations, insecure designs.
  • Application vulnerabilities/penetration testing/remediation.
  • Knowledge of current and upcoming IT security technologies.
  • Awareness of the latest and common security threats (OWASP Top 10, OWASP for API).
  • Excellent ability to diagnose and troubleshoot accessibility issues.
  • Skill in oral and written communication, including presentations to senior management.
  • Ability to influence and work with employees at all levels of the organization

#LI-HJ1

Pay Range: $130,000 - $170,000 annually

AIP/Bonus : Up to 15%

Our comprehensive employee benefits program is designed for you to live your best life at work, home, and everywhere in between. Employees working 25 hours or more per week are eligible for health benefits effective the first day of the month following or coinciding with their date of hire.
Benefits package includes[1]:

  • Medical, prescription, dental, and vision coverage for employees and their eligible family members

  • Employer paid Employee Assistance Program, Life Insurance, AD&D, and Disability benefits

  • Health Savings Account with employer contribution

  • Healthcare and Dependent Care Flexible Spending Accounts and Commuter/Parking Benefit

  • 401(k) and Roth 401(k) with company contribution

  • 529 Education Savings plan, Tuition Reimbursement Program and Student Loan Assistance Program

  • Supplemental Health plans, Voluntary Legal and Identity Theft Services

  • 11 paid holidays, paid Sick days (accrual of one hour for every 30 hours worked), up to 25 paid vacation days, and 16 hours of paid volunteer time throughout the calendar year

  • Free personal checking and savings account; Discounted rates on primary residence loan with $0 origination fees (restrictions apply)

Final compensation package will be determined by the work experience, education, and/or skill level of the applicant along with internal equity and alignment with geographic market data.

  • Mechanics Bank is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, religion, national origin, age, genetic information, veteran status, or on the basis of disability, gender identity, sexual orientation or other bases prohibited by applicable law.

  • Please view Equal Employment Opportunity Posters provided by OFCCP here.

  • To learn more about Mechanics Bank’s California privacy and security policies, including your right to a Notice At Collection as a California Resident, please visit

    California Privacy Policy for Prospective Employees | Mechanics Bank

[1] The benefits listed in this job posting reflect the Bank’s most reasonable and genuinely expected benefits offered for this position.

Top Skills

Angular Javascript
Bash
C#
Linux
macOS
Perl
Powershell
Python
T-Sql
Windows
HQ

HomeStreet Bank Seattle, Washington, USA Office

601 Union Street, Ste. 2000, Seattle, WA, United States, 98101

Similar Jobs

5 Days Ago
Easy Apply
In-Office
4 Locations
Easy Apply
170K-230K Annually
Senior level
170K-230K Annually
Senior level
Insurance
The Senior Application Security Engineer leads application security initiatives, providing expert guidance and driving secure design practices across engineering teams, focusing on risk assessment and threat modeling.
Top Skills: DastJwtKubernetesOauth2OidcSAMLSastSca
6 Days Ago
In-Office
Austin, TX, USA
175K-240K Annually
Mid level
175K-240K Annually
Mid level
Financial Services
The Staff Application Security Engineer will guide secure software development by identifying vulnerabilities, educating developers, and integrating security into engineering processes.
Top Skills: Application SecurityArmorcodeAWSAzureCloud SecurityContainersDastKubernetesSastScaSecrets Scanning
6 Days Ago
In-Office
3 Locations
Senior level
Senior level
Fintech
The Cloud Security Engineer will implement cloud security solutions, manage databases, troubleshoot issues, train staff, and ensure compliance with security standards.
Top Skills: Aurora PostgresqlAWSAws LambdaCi/CdCloudwatchSQL

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account