FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Application Security Engineer – ADR, AVP
State StreetApplication Security Engineer at State Street focusing on application security, threat detection, and DevSecOps. Collaborating with engineering teams to implement security measures and improving detection capabilities.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Application Detection and Response (ADR) strategies, application security practices, and cloud technologies. Proficient in leading technical projects, developing security documentation, and collaborating with cross-functional teams to enhance security processes and incident response.
Highest-signal resume keywords
Application Detection And Response (ADR)Application Security (AppSec)Cloud Technologies (Azure, AWS)Information Security Certifications (CISSP, GCIH, GWAPT)Software Development (Java, .NET, Python, Node.js)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application Security Disciplines (SAST, DAST, SCA)Threat DetectionAutomation And Orchestration (Ansible, Terraform, Kubernetes)Secure Software Development Life Cycle (SDLC)Incident ResponseCybersecurityAgile DevelopmentDevOpsApplication Telemetry AnalysisSecurity Event Investigation
Soft Skills
Technical LeadershipCollaborationCommunication
Tools & Technologies
Application Detection And Response PlatformsRuntime Application Self-Protection (RASP)Web Application And API Protection (WAAP)Infrastructure As Code (IaC)
Certifications & Qualifications
CISSPGCIHGWAPT
Industry Keywords
OWASP Top 10API Security RisksCloud SecuritySecurity ReportingSecurity Metrics
Tech Stack
Tools & technologiesAnsibleAWSAzureCloudCyber SecurityJavaJavaScriptKubernetes.NETNode.jsPythonSDLCTerraform
About the role
Key responsibilities & impact- Help define and build the organization's Application Detection and Response (ADR) strategy.
- Partner with Engineering, Security Operations, Cloud Security, and Application Development teams to implement and operationalize ADR technologies and processes.
- Lead the deployment, onboarding, and operational support of ADR platforms.
- Monitor, analyze, and investigate application-layer security events, attack patterns, and anomalous behaviors.
- Collaborate with application teams to triage, prioritize, and remediate security findings.
- Develop use cases, detection logic, alerting mechanisms, and response workflows.
- Integrate ADR platforms with incident response processes.
- Deliver and communicate security reporting, dashboards, metrics, and executive-level summaries.
- Develop and maintain ADR, AppSec, and DevSecOps documentation, standards, and operational procedures.
- Support internal and external audits by providing evidence, documentation, and process adherence.
- Work with stakeholders to continuously improve application monitoring, detection accuracy, response effectiveness, and security processes.
- Provide technical leadership and support for strategic projects through planning, implementation, and operationalization.
Requirements
What you’ll need- Strong software development background with technologies such as Java, .NET, Python, Node.js, or similar platforms.
- Experience with cloud technologies including Azure and AWS.
- Experience in Application Security disciplines, including SAST, DAST, SCA, API Security, Container Security, and Secure SDLC practices.
- Experience implementing or supporting Application Detection and Response (ADR), Runtime Application Self-Protection (RASP), Web Application and API Protection (WAAP), API Security, Threat Detection, or related application security technologies.
- Strong understanding of attack techniques targeting web, mobile, cloud-native, and API-based applications, including OWASP Top 10, API security risks, and advanced threat scenarios.
- Experience analyzing application telemetry, logs, traces, and security events to identify malicious activity and investigate incidents.
- Current information security certifications such as CISSP, GCIH, GWAPT, or equivalent is highly desirable.
- Experience with automation and orchestration technologies such as Ansible, Terraform, Kubernetes, and Infrastructure as Code (IaC) practices.
- Proven technical solutioning experience with current and emerging technologies including Agile Development, DevOps, Cloud Engineering, Cloud Security, Application Security, Threat Detection, Incident Response, and Cybersecurity.
- Bachelor’s degree in Computer Science, Information Technology, Information Security, Engineering, or a related discipline.
- 11+ of years of relevant combined experience across development, CI/CD, software supply chain security and application security.
Benefits
Comp & perks- Inclusive development opportunities
- Flexible work-life support
- Paid volunteer days
- Vibrant employee networks