“I can succeed as an Application Security Engineer at Capital Group”
As the Application Security (“AppSec”) Engineer you are an individual contributor in the Capital Group (CG) AppSec team. The CG AppSec team is part of Information Security in CG’s Information Technology Group. In the role you will be reviewing the architectures and performing threat models, code reviews, validating cloud configurations, and validating the DAST, SAST, and SCA findings for web applications. You will be doing code reviews (Java, TypeScript/JavaScript, Python, Terraform) and creating POCs for DAST tooling where required or collaborating with the penetration testers, as appropriate. The team members are geographically dispersed with varying experience levels. You will help the teams understand how to fix issues and provide best practices or appropriate compensating controls. In this role, you will be using threat modeling tools, static analysis tools, cloud configuration tools. If you are good at software security, this role is for you.
A typical day in the life of the AppSec engineer may look like the following:
You will be performing AppSec reviews including threat modeling, and code reviews
You will be meeting with the software development teams to understand a new application they are building and providing them with feedback on their architecture
You leverage SAST, DAST, SCA tools to create findings and translating them to severity of risks to perform this in Capital Group’s technology environment
You will write clear, succinct and effective technical documentation summarizing your findings, risks, and recommendations
You will write automated proof-of-concepts, and automated security tests by authoring security testing tools where needed
You will collaborate with technology stakeholders and advise on risks for technology solutions such as SaaS services and how they integrate with CG’s environment
You will communicate effectively and have an empathetic outlook towards development teams by authoring clear, actionable guidance on writing secure code
You will effectively present to development teams educating them on secure development.
“I am the person Capital Group is looking for.”
You have a bachelor's degree in computer science, a related field, or equivalent experience (preferably 7+ years of experience)
You understand threat modeling, code reviews, network security, TCP/IP, DNS, TLS, HTTP, etc.
You have experience with technologies such as Threat modeler/Threat Dragon, Scoutsuite, Veracode, Checkmarx, Netsparker, DAST scanners like Burpsuite
You have the ability to automate tasks in Python, bash, Java, C/C#/C++, Rust, etc.
You have a strong understanding of attacks in AWS, Azure, OAuth
You have excellent communication skills (written, oral), with the ability to simplify and document complex technical details to both technical and non-technical audiences
You can learn quickly and have a track record of developing a deep understanding of systems and risks to the business
You can work independently and take the initiative to drive security initiatives forward
You can juggle multiple tasks and coordinate/delegate to achieve speedy resolutions to application security-related security incidents working with Security operations.
Los Angeles, CA
Company Overview:
Founded in 1931, Capital Group is one of the world’s largest and most trusted investment management companies and home to the American Funds. We manage more than US$1.7 trillion in assets, and our 7,500 associates make our clients their first priority every day. When we do our job right, millions of investors around the world fulfill their dreams and financial goals, from home ownership and higher education, to a comfortable retirement. Our long-term investment results and outstanding service set us apart from our competitors, while our workplace sets us apart from other employers.
OUR CORE BELIEFS
We believe a financial goal is more than a number to your clients. It may represent a new home, a small business, a comfortable retirement or a college education. To help your clients go from dreaming to doing, we have four core beliefs that are central to their investing success.