Senior Application Security Engineer

Eli Lilly Eli Lilly · Pharma · Cork, Ireland

Senior Application Security Engineer responsible for integrating security testing tools into the SDLC, partnering with engineering teams on secure coding, and coordinating vulnerability remediation. The role involves developing and implementing application security strategies, performing threat analysis, and ensuring secure configurations for containers.

What you'd actually do

  1. Lead and deliver the integration of security testing tools in the Software Development Lifecycle (SDLC), including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secrets scanning, and Dynamic Application Security Testing (DAST) tools.
  2. Support and encourage secrets management practices and tooling.
  3. Partner with DevOps teams to build security testing and verification into the application development and deployment processes.
  4. Secure containers in on-prem and cloud container hosting services, collaborating with Cloud Service delivery teams to ensure secure configuration and deployment.
  5. Build relationships with internal and external customers, partnering with them to monitor and coordinate the remediation of vulnerabilities.

Skills

Required

  • Technical expertise in application security concepts, tools, and best practices
  • Problem-solving skills for identifying and addressing security issues
  • Collaboration and communication skills with technical and non-technical audiences
  • Agility to adapt to the changing threat landscape
  • Knowledge of application security trends
  • Ability to balance security and operational needs
  • Experience integrating SAST, SCA, Secrets scanning, and DAST tools
  • Experience with secrets management practices and tooling
  • Experience partnering with DevOps teams
  • Experience securing containers in on-prem and cloud environments
  • Experience with threat analysis and modeling

Nice to have

  • Experience with cloud security best practices
  • Familiarity with security architecture principles

What the JD emphasized

  • application security testing tools
  • secure coding practices
  • vulnerability remediation
  • application security strategies
  • SAST
  • SCA
  • Secrets scanning
  • DAST
  • threat analysis
  • vulnerability remediation initiatives