Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
BankUnited

BankUnited

via LinkedIn

Apply Now
All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

Sr. Application Security Engineer (Hybrid/Miami Lakes)

Hialeah, FL
full-time
Posted 10/16/2025
Verified Source
Key Skills:
Application security testing (Veracode, GitHub Dependabot, Wiz, StackHawk)
Programming/scripting (Python, PowerShell, .NET, Rego, JavaScript)
Infrastructure as Code security (Terraform, CloudFormation)
DevSecOps and SDLC security integration
Cloud security (AWS, Azure, IAM, container security)
Threat modeling (PASTA, STRIDE)
Compliance frameworks (NIST CSF, PCI-DSS, SOX, GLBA)
Security certifications (CSSLP, CISSP, CCSP, GCSA, AWS/Azure Security Specialty)

Compensation

Salary Range

$110K - 140K a year

Responsibilities

Lead secure development and delivery of applications and cloud workloads by embedding security into SDLC, DevSecOps pipelines, and cloud architectures, including threat modeling, code reviews, vulnerability remediation, and compliance support.

Requirements

3-5 years in application/cloud security or DevSecOps, proficiency with security testing tools, scripting languages, IaC security, cloud security services, compliance knowledge, and preferred security certifications.

Full Description

SUMMARY: The Sr. Application Security Engineer is responsible for leading the secure development and delivery of applications, services, and cloud workloads across BankUnited. This role combines deep technical expertise with strategic oversight to ensure that security is embedded into the software development lifecycle (SDLC), DevSecOps pipelines, and cloud architectures. The Engineer partners closely with development, DevOps, cloud, and security architecture teams to design, implement, and validate security controls--while providing technical guidance in application threat modeling, secure coding, and vulnerability remediation. ESSENTIAL DUTIES AND RESPONSIBILITIES include the following. Other duties and special projects may be assigned. • Oversee application security initiatives, ensuring security is integrated into all stages of the SDLC. • Establish, implement, and maintain DevSecOps security standards, procedures, and automation pipelines. • Perform application threat modeling to identify and address risks during design and development phases. • Conduct security code reviews, dynamic application security testing (DAST), and static application security testing (SAST). • Assess the security posture of web, mobile, and SaaS/PaaS/IaaS applications. • Provide remediation guidance to developers and ensure vulnerabilities are addressed in line with SLAs. • Evaluate encryption algorithms, key management practices, and cryptographic implementations. • Develop and track application security metrics, KPIs, and program maturity measures. • Design and implement secure Infrastructure-as-Code (IaC) templates using tools like Terraform and CloudFormation. • Implement cloud deployment security automation and container security hardening. • Perform vulnerability assessments and risk analysis for cloud-native and hybrid workloads. • Maintain deep knowledge of AWS and/or Azure security services, IAM, and cloud-native security tools. • Research emerging security threats, vulnerabilities, and frameworks to inform security strategy. • Create, maintain, and disseminate application security policies, standards, and guidelines to development teams. • Collaborate with architecture, engineering, and product teams to align on secure design patterns and requirements. • supporting security initiatives focused on secure coding practices and secure system design. • Partner with leadership to evaluate new security tools, technologies, and integrations for application and cloud security. • Support compliance audits and provide technical evidence for regulatory requirements (NIST CSF, PCI-DSS, SOX, GLBA). • Adheres to and complies with applicable, federal and state laws, regulations and guidance, including those related to anti-money laundering (i.e. Bank Secrecy Act, US PATRIOT Act, etc.). • Adheres to Bank policies and procedures and completes required training. • Identifies and reports suspicious activity. EDUCATION Bachelor's Degree or Master's degree in Computer Science, Information Technology, Cybersecurity, or related field Experience • 3-5 years of experience in application security, cloud security, or DevSecOps roles • Hands-on experience with application security testing tools such as Veracode, GitHub Dependabot, Wiz, StackHawk • Proficiency in at least one programming or scripting language (Python, PowerShell, NET, Rego, JavaScript) • Experience with IaC security tools (Terraform, CloudFormation) • Strong understanding of SDLC methodologies, CI/CD security integration, and DevSecOps principles • Familiarity with compliance frameworks and regulatory requirements (NIST CSF, PCI-DSS, SOX, GLBA) • Experience with container orchestration platforms (Docker, Kubernetes, EKS/AKS) and their security hardening preferred • Background in financial services or other highly regulated industries preferred • Experience with threat modeling methodologies (PASTA, STRIDE) preferred CERTIFICATES, LICENSES, REGISTRATIONS • CSSLP, CISSP, CCSP, GCSA, AWS/Azure Security Specialty. preferred Knowledge, Skills And Abilities • Strong knowledge of secure coding principles and common vulnerabilities (OWASP Top 10, CWE). • Knowledge of AWS and/or Azure security services, IAM, and cloud-native security tooling. • Excellent communication skills with the ability to influence cross-functional teams. Additional Information • Candidates residing in locations within BankUnited's footprint may be given preference. #GoForMore

This job posting was last updated on 10/20/2025

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt