Cybersecurity Application Security Engineer

Rivian Rivian · Auto · Atlanta, GA · Information Technology

Seeking an experienced Application Security Engineer to enhance and maintain the secure software development lifecycle (SSDLC) at Rivian. The role involves guiding software development teams to write secure code, identifying and remediating application security vulnerabilities, assessing scanner findings, integrating security tooling into CI/CD pipelines, reviewing source code and architectures, and collaborating with penetration testing and bug bounty teams.

What you'd actually do

  1. Assess security scanner findings (SAST, DAST) within our source code and help guide application teams prioritize and resolve these issues.
  2. Integrated and optimized security tooling within Gitlab CI/CD and other DevOps technologies to ensure 'secure-by-design' development
  3. Review source code and application architectures to identify and communicate security vulnerabilities in proposed designs.
  4. Work closely with Rivian’s penetration testing team to identify remediations for security vulnerabilities identified.
  5. Coordinate the ingestion and prioritization of vulnerabilities reported through Bug Bounty initiatives.

Skills

Required

  • software development or scripting (e.g., Go, Python)
  • application security experience
  • reviewing and remediating common software vulnerabilities
  • Gitlab CI/CD or other popular DevOps technologies
  • problem-solving and decision-making capabilities

Nice to have

  • automating security workflows
  • cloud native (AWS preferred)
  • Kubernetes hosted applications
  • threat modeling
  • security reviews

What the JD emphasized

  • secure software development lifecycle
  • application security vulnerabilities
  • security vulnerabilities