
Application Security Engineer
ASX
Application Security Engineer
ASX is seeking an Application Security Engineer to join its Security Operations and Engineering team in Sydney. The role involves conducting application security reviews, supporting threat modelling, and driving remediation of vulnerabilities across critical market infrastructure. Candidates should have strong knowledge of secure coding practices and experience with AppSec tooling.
Application Security Engineer
ASX is seeking an Application Security Engineer to join its Security Operations and Engineering team in Sydney. The role involves conducting application security reviews, supporting threat modelling, and driving remediation of vulnerabilities across critical market infrastructure. Candidates should have strong knowledge of secure coding practices and experience with AppSec tooling.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Conduct targeted application security reviews and AI-assisted code analysis to identify exploitable vulnerabilities and structural weaknesses across priority applications.
- Prioritise, articulate and drive remediation of critical and high-severity code-level vulnerabilities in partnership with engineering teams.
- Support threat modelling, secure design reviews and application security assessments for priority applications and automation workflows.
- Adapt AppSec guidance to suit different engineering team maturity levels, balancing risk reduction, standardisation and delivery velocity.
- Provide practical secure coding guidance, remediation patterns and code-level recommendations to accelerate effective fixes.
- Raise, review or contribute to pull requests where appropriate to support timely remediation and knowledge transfer.
- Help define, refine and embed security checkpoints, guardrails and automation within the SDLC and CI/CD pipelines.
- Support optimisation of AppSec tooling, including SAST, DAST, SCA and related controls, so security testing is effective without unnecessarily impacting delivery velocity.
- Help establish or uplift Security Champion practices across delivery teams to sustain secure coding capability after the engagement.
- Produce handover documentation, reusable AppSec patterns and team enablement materials to support sustainable BAU ownership after the engagement.