Application Security Champion (Software Engineering)
About the role
As an Application Security Champion (Software Engineering), you will make an impact by embedding security into the software development lifecycle and partnering with engineering teams to deliver secure, resilient, and compliant applications. You will be a valued member of the Engineering and Security team and work collaboratively with software architects, developers, DevOps engineers, product owners, QA teams, security stakeholders, and cross-functional technology teams to proactively identify risks, strengthen application security posture, and drive secure-by-design principles across enterprise platforms.
In this role, you will:
• Integrate security throughout the Software Development Lifecycle (SDLC), partnering closely with development teams to ensure secure design, development, testing, and deployment practices.
• Analyze and remediate vulnerabilities identified through SAST, SCA, DAST, IAST, penetration testing, and other security assessment activities while providing technical guidance to engineering teams.
• Conduct threat modeling exercises using methodologies such as STRIDE to identify attack vectors, assess risks, and recommend effective mitigation strategies.
• Promote secure coding practices aligned with OWASP Top 10 and industry standards through code reviews, developer enablement, and security awareness initiatives.
• Leverage automation and AI-assisted security tools to streamline vulnerability management, improve remediation workflows, and enhance overall security operations efficiency.
Work Model
We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role’s business requirements, this is a hybrid position requiring 3 days a week in a client or Cognizant office in Phoenix, AZ. Regardless of your working arrangement, we are here to support a healthy work-life balance through our various wellbeing programs.
The working arrangements for this role are accurate as of the date of posting. This may change based on the project you’re engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations.
What you need to have to be considered
• 8+ years of experience in Application Security, Product Security, Software Engineering, or Cybersecurity roles.
• Strong experience embedding security into Agile and DevSecOps development environments.
• Hands-on experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Interactive Application Security Testing (IAST), and vulnerability management processes.
• Experience conducting application penetration testing across web applications, APIs, and mobile applications.
• Strong knowledge of secure coding principles, OWASP Top 10, security architecture, and application security best practices.
• Experience performing threat modeling using methodologies such as STRIDE and assessing risks using frameworks such as CVSS.
• Proficiency reviewing application source code and providing remediation guidance for vulnerabilities within Java, .NET, or similar development environments.
• Experience integrating security controls and automated testing into CI/CD pipelines using tools such as GitLab, Jenkins, or equivalent DevOps platforms.
• Strong understanding of vulnerability lifecycle management, security risk assessment, and remediation tracking processes.
• Experience collaborating with software development, architecture, QA, and DevOps teams to design and implement secure applications.
• Excellent communication, leadership, and stakeholder management skills with the ability to influence secure engineering practices across organizations.
• Experience mentoring developers and engineering teams on application security concepts and secure software development methodologies.
These will help you stand out
• Experience leveraging AI-driven security tools and automated remediation platforms to improve vulnerability management and developer productivity.
• Experience securing cloud-native applications, microservices architectures, APIs, and containerized workloads.
• Knowledge of banking, financial services, fintech, or other highly regulated industry security requirements.
• Experience conducting security reviews for REST and SOAP APIs.
• Familiarity with DevSecOps frameworks and security automation within enterprise CI/CD environments.
• Experience reducing false positives through optimization and tuning of SAST, DAST, and other security scanning solutions.
• Strong understanding of security architecture reviews, secure design patterns, and application hardening techniques.
• Experience participating in or leading security champions programs within large engineering organizations.
• Security certifications such as CSSLP, GWAPT, OSCP, CEH, CISSP, Security+, or related credentials.
• Experience driving security culture initiatives and establishing security-first engineering practices across development teams.
We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply, even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role.
Salary and Other Compensation:
Applications will be accepted until July 24, 2026.
The annual salary for this position is between $63,000 - $125,000 depending on experience and other qualifications of the successful candidate.
This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.
Benefits:
Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:
• Medical/Dental/Vision/Life Insurance
• Paid holidays plus Paid Time Off
• 401(k) plan and contributions
• Long-term/Short-term Disability
• Paid Parental Leave
• Employee Stock Purchase Plan
Disclaimer:
The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
À propos de Cognizant
Cognizant (NASDAQ : CTSH) est un AI Builder et une entreprise de services numériques (ESN) élaborant des solutions complètes d’IA maximisant les investissements pour des résultats concrets. Sa profonde expertise des métiers, des processus et des technologies lui permet d’intégrer dans les systèmes technologiques le contexte unique de chaque organisation de l’ingénierie à la production à l’échelle. Son objectif : améliorer l’efficacité des équipes, créer de la valeur et permettre aux grandes entreprises de rester performantes dans un monde qui évolue rapidement. Pour en savoir plus : cognizant.ai ou @cognizant.
Renseignments suppplémentaires sur l'emploi
Les informations sur la rémunération sont exactes à la date de publication. Cognizant se réserve le droit de modifier ces informations à tout moment, conformément aux lois applicables.
Les exigences linguistiques varient selon les postes, mais nous demandons à tous les candidats d’avoir une connaissance de base de l’anglais afin de faciliter les communications internes à l’échelle de l’entreprise. Pour les postes basés au Québec, une maîtrise de l’anglais est requise puisque vous fournirez des services et collaborerez avec des parties prenantes situées hors de la province, qui ne parlent pas nécessairement le français.
Cognizant est un employeur souscrivant au principe de l’égalité d’accès à l’emploi. Votre candidature et votre dossier ne seront pas examinés en fonction de la race, de la couleur, du sexe, de la religion, des croyances, de l'orientation sexuelle, de l'identité de genre, de l'origine nationale, du handicap, de l'information génétique, de la grossesse, du statut d'ancien combattant ou de toute autre caractéristique protégée telle que décrite par les lois fédérales, provinciales ou locales.
Si vous avez un handicap qui nécessite un aménagement raisonnable pour rechercher une offre d'emploi ou poser une candidature, envoyiez un courriel à [email protected] avec votre demande et vos coordonnées.











