Hiring.Camp

Sr Application Security Engineer - Cyber Security

Sands

·

Yesterday

Location
Las Vegas (LVSC), United States of America
Type
Full-time
Department
Engineering
Experience
21+ years
Source
Workday

Description

Job Description:

Position Overview

The primary responsibility of the Sr Engineer – Cyber Security is to design, implement, and support application security capabilities that integrate into the company’s Software Development Lifecycles (SDLCs). This role partners with development, quality assurance, and cyber security teams to evaluate application risk, operate AppSec technologies, support secure coding practices, and guide remediation of software vulnerabilities.

All duties are to be performed in accordance with departmental and Las Vegas Sands Corp.’s policies, practices, and procedures. All Las Vegas Sands Corp. Team Members are expected to conduct and carry themselves in a professional manner at all times. Team Members are required to observe the Company’s standards, work requirements and rules of conduct.

Essential Duties & Responsibilities

  • Develop, implement, and support application security programs across Software Development Lifecycles (SDLCs), including technology integration, workflow design, documentation, training, and stakeholder enablement.

  • Evaluate SDLCs and advise on application security technologies, integration points, and process improvements to reduce software security risk.

  • Perform code, vulnerability, and configuration analysis using manual review and automated application security testing solutions, including SAST and DAST tools.

  • Partner with development teams to prioritize product vulnerabilities, validate mitigation urgency, and provide remediation guidance and recommendations.

  • Configure, implement, maintain, troubleshoot, and support capacity planning for cyber security tools, devices, infrastructure, and application security technologies.

  • Monitor tool health, respond to security outputs, and tune solutions to support reliable performance, business-focused monitoring, and program objectives.

  • Respond to cyber security events and incidents with professionalism and support practice exercises for use case driven alerts and incidents.

  • Identify security requirements and support cyber security architecture, secure configuration, and product security reviews across heterogeneous computing environments.

  • Create and maintain cyber security documentation, including design materials, standard operating procedures, protocols, diagrams, metrics, reports, and presentations.

  • Collaborate with cyber security, IT, business, development, quality assurance, and administrative teams to troubleshoot issues, support operational needs, and promote secure software development practices.

  • Manage operational requests by submitting and responding to tickets, preparing change management items, and participating in Change Approval Board (CAB) meetings.

  • Stay current on malware, infiltration and investigative techniques, forensics, application security practices, and the evolving threat environment.

  • Mentor junior engineers to develop job competency, technical skills, and cyber security expertise.

  • Perform job duties in a safe manner.

  • Attend work as scheduled on a consistent and regular basis.

  • Perform other related duties as assigned.

Minimum Qualifications

  • At least 21 years of age.

  • Proof of authorization to work in the United States.

  • Bachelor’s degree in Computer Science or related field.

  • Must be able to obtain and maintain any certification or license, as required by law or policy. 

  • 5 - 7 years of experience in cyber security or information technology.

  • Experience in at least 5 of the following:

    • Secure SDLC, DevSecOps, or application security program support.

    • Implementing application security testing tools, including SAST, DAST, SCA, secrets scanning, or container scanning.

    • CI/CD pipeline security, release gating, and developer workflow integration.

    • Cloud architecture security, including secure configuration, identity, network, and workload protection.

    • Application vulnerability assessment, triage, and remediation validation.

    • Software composition analysis, open-source risk management, and dependency vulnerability management.

    • API security testing, web application security testing, and secure coding practices.

    • Container, Kubernetes, and cloud workload security.

    • Cloud security posture management and application security configuration scanning.

    • Threat modeling for applications, APIs, cloud services, and emerging technologies.

    • Secrets management, credential exposure detection, and secure key management practices.

    • Application and cloud security logging, detection, alerting, and use case development.

    • Application security incident response, vulnerability disclosure, and product security response processes.

    • Infrastructure as Code security, policy-as-code, and secure configuration management.

    • Application, cloud, and software supply chain threat intelligence.

    • Application security metrics, risk reporting, and program maturity measurement.

  • Problem solving skills and the ability to work under pressure in a constantly changing environment.

  • Ability to manage deadlines and changing priorities.

  • Must be self-motivated and a team player collaborating with a team that spans the globe.

  • Demonstrates responsibility and accountability.

  • Must be able to communicate effectively with team members, management, senior management and consultants both verbally and in writing.

  • Must be able to create and document network and system diagrams.

  • Must be able to write understandable procedures.

  • Must be able to respond to calls as needed (24/7).

  • Must be able to design, install and implement cyber infrastructure solutions that integrate with the existing infrastructure.

  • Ability to demonstrate a calm demeanor when faced with chaotic circumstances.

  • Knowledge of networking concepts and principles.

  • Strong interpersonal skills with the ability to communicate effectively with guests and other Team Members of different backgrounds and levels of experience.

  • Must be able to work varied shifts, including nights, weekends and holidays.

Physical Requirements

Must be able to:

  • Physically access assigned workspace areas with or without reasonable accommodation.

  • Work remotely as necessary.

  • Work indoors and be exposed to various environmental factors such as, but not limited to, CRT, noise, and dust.

  • Utilize laptop and standard keyboard to perform essential functions of the job.

Skills

KubernetesCI/CDRisk ManagementChange Management

Similar Jobs

24

Sr. Application Security

Coherehealth · Hyderabad, Telangana, India

1 month ago

Sr. Application Security Engineer

Miteksystems 2 · United States · Remote

6 days ago

Sr Application Security Architect

Sas · Cary HQ, NC, US +2 · Remote

6 days ago

Sr Application Security Architect

Global Sas · Cary HQ, NC, US +2 · Remote

6 days ago

Sr Application Security Engineer

Thetradedesk · Bellevue; Ventura +1

1 week ago

Sr. Application Security Manager

Doubleverify · NYC Global HQ

2 weeks ago

Sr. Application Security Testing Engineer

3M · US, Texas, Austin, United States of America · Onsite

2 weeks ago

Sr. Application Security Engineer

Spacex · Redmond, WA +1

2 weeks ago

Sr Application Security Architect

Global Sas · Pune, IN · Hybrid

1 month ago

Sr Application Security Architect

Global Sas · Pune, IN · Hybrid

1 month ago

Sr Application Security Engineer - AI-First Development

Sands · Las Vegas (LVSC), United States of America · Remote

1 month ago

Security Analyst/Sr. Security Analyst (Application Security)-ITDSGGR (Contractual)

IMF works to foster global · IMF Headquarters 2, United States

1 week ago

Security Analyst/Sr. Security Analyst (Application Security)-ITDSGGR (Contractual)

Imf · IMF Headquarters 2, United States

1 week ago

Sr. Manager, Application Security

Prosper · United States · Remote

3 months ago

Sr Director Analyst – Application Security and Governance

Gartner · Remote - United Kingdom +3 · Remote

3 weeks ago

Sr Director Analyst – Application Security and Governance (Remote - U.S.)

Gartner · Remote - Texas, United States of America · Remote

3 weeks ago

Sr. Software Engineer - Application Security

Backblaze External Website · Remote - Argentina; Remote - Colombia ; Remote - Costa Rica ; Remote - Mexico · Remote

2 months ago

Sr. Security Software Engineer, Application Security

Pinterest · Chicago, IL, US; Remote, US +1 · Remote

5 months ago

Sr Staff Application Engineer - Firmware & Security

Renesas Electronics · Bengaluru, KA, India

1 week ago

Sr Exec Corporate Audit - Application Security Auditor / IT Process Auditor

EXL Talent Acquisition Team · Noida, Uttar Pradesh, India · Hybrid

5 months ago

Sr Exec Corporate Audit - Application Security Auditor / IT Process Auditor

EXL · Noida, Uttar Pradesh, India · Hybrid

5 months ago

Sr. IT PLM Technical Application & Infra Security Engineer

Asml · Veldhoven, Building 71, Netherlands

1 month ago

Security Testing Specialist Sr - Sunday - Thursday 11pm - 7am MST - Application Security

PNC Bank · Denver - 12345 W Colfax (CO147), United States of America +1 · Onsite

1 month ago

Security Testing Specialist Sr - Sunday - Thursday 3pm - 11pm MST - Application Security

PNC Bank · Denver - 12345 W Colfax (CO147), United States of America +1 · Onsite

1 month ago