メインコンテンツに移動します。

Application Security Engineer

00069983261

Application Security Champion (Software Engineering)

About the role

As an Application Security Champion (Software Engineering), you will make an impact by embedding security into the software development lifecycle and partnering with engineering teams to deliver secure, resilient, and compliant applications. You will be a valued member of the Engineering and Security team and work collaboratively with software architects, developers, DevOps engineers, product owners, QA teams, security stakeholders, and cross-functional technology teams to proactively identify risks, strengthen application security posture, and drive secure-by-design principles across enterprise platforms.

In this role, you will:

• Integrate security throughout the Software Development Lifecycle (SDLC), partnering closely with development teams to ensure secure design, development, testing, and deployment practices.
• Analyze and remediate vulnerabilities identified through SAST, SCA, DAST, IAST, penetration testing, and other security assessment activities while providing technical guidance to engineering teams.
• Conduct threat modeling exercises using methodologies such as STRIDE to identify attack vectors, assess risks, and recommend effective mitigation strategies.
• Promote secure coding practices aligned with OWASP Top 10 and industry standards through code reviews, developer enablement, and security awareness initiatives.
• Leverage automation and AI-assisted security tools to streamline vulnerability management, improve remediation workflows, and enhance overall security operations efficiency.


Work Model

We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role’s business requirements, this is a hybrid position requiring 3 days a week in a client or Cognizant office in Phoenix, AZ. Regardless of your working arrangement, we are here to support a healthy work-life balance through our various wellbeing programs.

The working arrangements for this role are accurate as of the date of posting. This may change based on the project you’re engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations.


What you need to have to be considered

• 8+ years of experience in Application Security, Product Security, Software Engineering, or Cybersecurity roles.
• Strong experience embedding security into Agile and DevSecOps development environments.
• Hands-on experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Interactive Application Security Testing (IAST), and vulnerability management processes.
• Experience conducting application penetration testing across web applications, APIs, and mobile applications.
• Strong knowledge of secure coding principles, OWASP Top 10, security architecture, and application security best practices.
• Experience performing threat modeling using methodologies such as STRIDE and assessing risks using frameworks such as CVSS.
• Proficiency reviewing application source code and providing remediation guidance for vulnerabilities within Java, .NET, or similar development environments.
• Experience integrating security controls and automated testing into CI/CD pipelines using tools such as GitLab, Jenkins, or equivalent DevOps platforms.
• Strong understanding of vulnerability lifecycle management, security risk assessment, and remediation tracking processes.
• Experience collaborating with software development, architecture, QA, and DevOps teams to design and implement secure applications.
• Excellent communication, leadership, and stakeholder management skills with the ability to influence secure engineering practices across organizations.
• Experience mentoring developers and engineering teams on application security concepts and secure software development methodologies.


These will help you stand out

• Experience leveraging AI-driven security tools and automated remediation platforms to improve vulnerability management and developer productivity.
• Experience securing cloud-native applications, microservices architectures, APIs, and containerized workloads.
• Knowledge of banking, financial services, fintech, or other highly regulated industry security requirements.
• Experience conducting security reviews for REST and SOAP APIs.
• Familiarity with DevSecOps frameworks and security automation within enterprise CI/CD environments.
• Experience reducing false positives through optimization and tuning of SAST, DAST, and other security scanning solutions.
• Strong understanding of security architecture reviews, secure design patterns, and application hardening techniques.
• Experience participating in or leading security champions programs within large engineering organizations.
• Security certifications such as CSSLP, GWAPT, OSCP, CEH, CISSP, Security+, or related credentials.
• Experience driving security culture initiatives and establishing security-first engineering practices across development teams.


We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply, even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role.


Salary and Other Compensation:

Applications will be accepted until July 24, 2026.

The annual salary for this position is between $63,000 - $125,000 depending on experience and other qualifications of the successful candidate.

This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.


Benefits:

Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:

• Medical/Dental/Vision/Life Insurance
• Paid holidays plus Paid Time Off
• 401(k) plan and contributions
• Long-term/Short-term Disability
• Paid Parental Leave
• Employee Stock Purchase Plan


Disclaimer:

The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.


コグニザントについて   
コグニザント(NASDAQ: CTSH)は、AI Builderおよびテクノロジーサービスプロバイダーとして、お客様にフルスタックのAIソリューションを構築することで、AI投資と企業価値を結ぶ架け橋となっています。業界、ビジネスプロセス、エンジニアリングに関する当社の深い専門知識を活かし、組織固有のビジネス環境をテクノロジー・システムに組み込みます。これにより、人間の可能性を最大限に引き出し、確かな成果を実現するとともに、急速に変化する世界においてグローバル企業が常に一歩先を行くための支援を行っています。 詳細については、cognizant.ai をご覧ください。  

雇用に関する追加情報
本募集に記載されている報酬情報は、掲載日時点で正確なものです。Cognizantは、適用される法令に従い、いつでも本情報を変更する権利を留保します。

応募者は、対面またはビデオ会議による面接への参加を求められる場合があります。また、各面接の際に、現在有効な州政府または政府発行の身分証明書の提示を求められる場合があります。

Cognizantは機会均等雇用主です。応募および選考において、人種、肌の色、性別、宗教、信条、性的指向、性自認、国籍、障がい、遺伝情報、妊娠、退役軍人の地位、その他連邦法・州法・地方自治体の法律により保護されるいかなる特性に基づく差別も行いません。

あなたが成長し、活躍できるよう支える福利厚生

当社の福利厚生プログラムは、あなたを第一に考えて設計されており、充実し、バランスの取れた健やかな生活を送れるようサポートします。

葉のある植物の青い線画

経済的なウェルビーイング

当社では市場データを定期的に見直し、皆さんがもたらす価値が正しく報酬に反映されるよう努めています。福利厚生は給与だけにとどまらず、退職金・年金制度や金融教育などが含まれる場合があります。

Stay Healthy Midnight Blue RGB

身体的およびメンタルヘルス

有給休暇、可能な範囲での柔軟な働き方、医療保険制度、カウンセリング、メンタルヘルス・アライシップ・プログラムなどを通じて、あなたが自身のウェルビーイングを大切にできるよう支援します。

Build The Career You Want Midnight Blue RGB

あなたのキャリアは、あなたの思い描くかたちで

Cognizantでは35万人以上の職種があり、新しいテクノロジー、業界、勤務地に挑戦する機会が広がっています。キャリア成長に必要なスキルを身につけ、自分らしいキャリアを築くことができます。
Making A Meaningful Impact Midnight Blue RGB

現実社会へのインパクト

あなたが信頼している世界的な大手ブランドを思い浮かべてみてください。その多くが、ビジネスをさらに強化するために私たちを頼りにしています。ここでは、大胆なアイデアを、世界中の人々の暮らしをより良くするソリューションへと形にしていくことができます。

まだ最適なポジションが見つかっていませんか?

あなたに合わせてカスタマイズされた、最新の求人情報、採用イベント、そして会社からのお知らせをお届けします!

最新情報を見逃さない