Application Security Engineer at The Pokémon Company International
on-site · full-time · Visa sponsorship
Apply for this role at The Pokémon Company International
Responsibilities:
- Administer and enforce security policies for systems and application access.
- Perform application security testing (SAST/DAST), configuration reviews, and secure code assessments.
- Plan and run penetration tests and vulnerability assessments across apps, OS, and networks.
- Lead threat modeling and security design reviews for new features and technology changes.
- Respond to incidents: identify, isolate, remediate unauthorized access and perform root cause analysis.
- Implement and maintain cloud security controls to reduce drift, private-cloud gaps, and web-facing vulnerabilities (AWS-focused).
- Integrate security testing and controls into the SDLC and work within agile teams to deliver iterative improvements.
- Collaborate with InfoSec, engineering, and vendors to advance roadmaps and operational initiatives.
- Provide concise risk briefings to management on data compromise or system unavailability; participate in on-call rotation.
Requirements:
- 5–7 years relevant experience securing cloud environments (primarily AWS) or equivalent expertise.
- Degree in a related field or equivalent practical experience.
- Strong background in application security engineering, architecture, and MWAFs.
- Hands-on experience with penetration testing, vulnerability management, and incident response.
- Familiarity with cloud security controls, secure SDLC practices, and integrating security testing tools.
- Proven ability to partner with cross-functional teams and communicate technical risk to non-technical leadership.
- Experience managing security vendors and managed services.
- Strong organizational skills, attention to detail, and a proactive mindset.