Application Security Engineer

Location
Quito, Pichincha
Employment Type
Industry
Job Family
Technology
Career Level
Experienced
MAKE STRATEGY A REALITY | ACCELERATE YOUR GROWTH | CHOOSE YOUR PATH

As the world's leading change and transformation consultancy, we're helping businesses move from strategy to reality by taking a pragmatic and practical approach to build solutions that last.

The Application Security Engineer is responsible for implementing and operationalizing application security improvements. This individual partners with development, architecture, DevOps, and security teams to remediate application security findings, embed security controls into the software development lifecycle, and establish sustainable secure engineering practices. 

YOU WILL:
  • Lead remediation of application security findings identified through SAST, DAST, Software Composition Analysis (SCA), and related security assessments. 

  • Partner with application development teams to analyze vulnerabilities, determine root causes, and implement appropriate corrective actions. 

  • Design and implement secure coding standards and security requirements within the SDLC. 

  • Integrate and optimize application security tooling, including static analysis, dynamic analysis, dependency scanning, and license compliance scanning. 

  • Configure and enhance security gates within CI/CD pipelines to ensure consistent enforcement of security and quality standards. 

  • Collaborate with DevOps and platform engineering teams to automate security testing, monitoring, and reporting capabilities. 

  • Assist development teams in triaging vulnerabilities, reducing false positives, and prioritizing remediation activities based on risk. 

  • Support implementation of engineering Definition of Done requirements across product delivery teams. 

  • Develop technical standards, procedures, and documentation to support long-term application security governance. 

  • Contribute to security metrics, dashboards, and reporting to measure remediation effectiveness and program maturity. 

  • Provide mentoring and knowledge transfer to engineering teams on secure development practices and application security principles. 

  • Participate in design reviews, architecture discussions, and security assessments to proactively identify risks before deployment. 



IDEALLY, WE'D LIKE:
  • 5+ years of experience in software engineering, cybersecurity engineering, application security, or DevSecOps. 

  • Demonstrated experience remediating findings from SAST, DAST, SCA, and container security tools. 

  • Strong understanding of secure software development lifecycle (SSDLC) practices. 

  • Experience with CI/CD platforms such as Azure DevOps, GitHub, Jenkins, or similar tooling. 

  • Ability to read, troubleshoot, and remediate vulnerabilities across multiple programming languages and technology stacks. 

  • Experience implementing security controls, security gates, and automated validation within software delivery pipelines. 

  • Strong communication skills with the ability to work directly with engineering and business stakeholders. 


Applicants must be authorized to work in Ecuador, without the need for visa sponsorship by North Highland. Work visa sponsorship will not be provided, either now or in the future, for this position.

North Highland is an equal opportunity employer, and we adhere to all applicable laws and regulations to ensure a fair and equitable workplace. All qualified applicants will receive fair and impartial consideration without regard to race, color, sex, gender identity, religion, national origin, age, sexual orientation, disability, veteran status, or any other characteristic protected by law. We handle all information in accordance local privacy standards and maintain strict confidentiality.

 

Reference: 50494