About this role
About the Role The Senior Application Security Engineer provides technical leadership across application security engineering, enabling secure software delivery through SDLC practices, tooling, and automation. The role focuses on designing, integrating, and continuously improving enterprise application security capabilities, including secure CI/CD integrations, vulnerability detection, and remediation workflows, and ensuring tooling and processes protect the Bank and its customers in compliance with regulatory requirements and risk management standards. What You'll Do
- Provide technical leadership and guidance in a multi-geography team to support Application Security toolsets, ensuring their effectiveness, reliability, and outcomes.
- Lead design, integration, and implementation of enterprise application security tooling (e.g., SAST, DAST, SCA, SBOM, API security, secrets detection).
- Make technical prioritization and trade-off decisions across application security tooling, balancing risk, scalability, developer experience, and operational efficiency.
- Apply analytical and troubleshooting expertise and mentor, train others to investigate complex system integration problems, owning problems with patience and empathy for the difficulty of diagnosing cross‑team software and architecture issues.
- Enable secure by design and secure by default software delivery by integrating application security controls and tooling into DevOps pipelines and developer workflows across diverse deployment environments.
- Define and implement SDLC processes and best practices used across engineering and security DevOps teams.