What are the responsibilities and job description for the Senior Application Security / Product Security SME position at Amtex System Inc.?
Amtex Systems Inc is an information technology and talent solutions company offering talent and BI consulting to the companies in US for over 25 years.
Our solutions are designed to fill resource gaps, by providing the right candidates who deliver value to the organization. Our propensity to nurture and build strong relationships with our clients helps us better understand their business demands and gives us the ability to provide services that are on time and rise above the rest.
Job Location: NYC, NY (Hybrid)
Duration: 6-12 Months (Strong possibility of extension)
Work Model: On-site - 4 days per week
Interview Process: 3-stage interview process.
Position Overview:
Client is looking for a Senior Application Security / Product Security Subject Matter Expert (SME) to join their established product security team. In this role, you will evaluate products, review application code security, conduct threat modeling, and ensure robust security architectures are implemented across internal systems and outbound products (such as web application gateways).
Key Responsibilities
- Security Assessments & Reviews: Conduct comprehensive security reviews and assessments on software products, gateways, and applications following well-defined workflows.
- Code & Static Analysis: Review application source code for security vulnerabilities, analyze static scanning findings, separate true positives from false positives, and evaluate security architecture.
- Documentation & Reporting: Document all security findings and artifacts clearly, delivering actionable remediation reports to engineering teams.
- Workflow Management: Manage the security review ticket intake lifecycle, processing requests submitted by engineering teams efficiently.
- Threat Modeling: Lead threat modeling sessions to identify and mitigate architectural risks early in the development lifecycle.
Required Qualifications & Technical Stack
- Cybersecurity Background: Deep expertise in application security, security architecture, and threat modeling.
- Development Experience: Strong software development background with practical coding and code-review proficiency in languages such as C , Python (MUST), and Rust.
- AppSec Principles: Comprehensive understanding of web application security fundamentals, including secure authentication, authorization, and Single Sign-On (SSO).
- Scanning Tools: Experience working with static analysis security testing (SAST) tools, including proprietary or in-house scanning solutions.