OneStream Software Logo

OneStream Software

Senior Application Security Engineer

Posted 4 Days Ago
Remote
Hiring Remotely in United States
158K-198K Annually
Senior level
Remote
Hiring Remotely in United States
158K-198K Annually
Senior level
The Senior AppSec Engineer secures the OneStream platform, performs application security testing, conducts code analysis, and collaborates with engineering teams to enhance security throughout the software development lifecycle.
The summary above was generated by AI

Senior Application Security Engineer


Location:                     Remote, USA
Employment Type:    Full-Time
Compensation:          $158,000.00 - $198,250.00 (Range applies to US candidates only) + Benefits/Variable Comp/Equity - Range may vary based on experience. 
Benefits Offered:       Vision, Medical, Life, Dental, 401K

 

Summary

The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for defining and enforcing secure coding and development practices, performing application security testing to identify risks and vulnerabilities before release and in production, and reviewing the output of application security tools to provide clear remediation guidance across the organization.

In addition, the Senior Application Security Engineer partners with engineering teams on the planning and architecture of new features, contributes to platform security design, and leads or supports the development of custom security tools and scanning capabilities. The ideal candidate brings a strong foundation in secure development and programming practices, hands-on experience with C# and .NET, and a passion for protecting customers. This role requires effective communication across technical and non-technical audiences and may involve developing proof-of-concept exploits to validate vulnerabilities and assess real-world risk.

 

Primary Duties and Responsibilities

  • Perform manual and automated application security testing to identify vulnerabilities across the OneStream platform.
  • Conduct code analysis to assess and ensure the security of application code.
  • Evaluate the software development lifecycle (SDLC) to identify opportunities to strengthen application and supply chain security.
  • Partner with Development and Engineering teams to embed security into OneStream services and workflows.
  • Collaborate with members of the Security team to identify attack patterns and indicators of compromise.
  • Design, develop, and maintain custom security testing tools to support internal testing efforts.
  • Define, document, and enforce secure development policies, standards, and procedures.
  • Provide mentorship and technical guidance to junior members of the Security team to support growth and knowledge sharing.
  • Document, communicate, and report security findings and risks identified during testing activities.
  • Perform penetration testing against OneStream assets to validate application and infrastructure security.
  • Conduct security architecture and design reviews to ensure secure-by-design implementations.
  • Provide secure design and secure coding guidance to engineering teams throughout the development lifecycle.

 

Required Education and Experience

  • One of the following combinations of education and experience:
    • Bachelor’s degree in Computer Science, Engineering, or a related field with 8+ years of experience in application security testing, penetration testing, or software development; or
    • Master’s degree in Computer Science, Engineering, or a related field with 3+ years of experience in application security testing, penetration testing, or software development; or
    • Associate degree in Computer Science, Engineering, or a related field with 12+ years of experience in application security testing, penetration testing, or software development.
  • 3+ years of hands-on experience conducting threat modeling for applications and systems and translating findings into actionable remediation guidance.

Preferred Education and Experience

  • Experience writing and reviewing C# and .NET code, including secure coding and code review practices.
  • Hands-on experience performing penetration testing of web applications.
  • Experience decompiling and reverse engineering .NET libraries.
  • Broad experience across IT security and infrastructure, security risk management, and compliance frameworks such as SOC 2 and FedRAMP, including security policies, procedures, testing, auditing, and internal audit.
  • Industry-recognized offensive security or penetration testing certifications, such as:
    • Offensive Security Certified Professional (OSCP)
    • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
    • GIAC Penetration Tester (GPEN)
    • Other relevant offensive security or penetration testing certifications
  • Outstanding written and verbal communication skills, with the ability to clearly explain complex technical concepts to both technical and non-technical audiences.

 

Knowledge, Skills, and Abilities

  • Highly organized with strong analytical and reasoning skills.
  • Self-motivated self-starter who works effectively both independently and with minimal direction.
  • Independent thinker with sound judgment and the ability to make well-reasoned decisions.
  • Ability to think quickly, evaluate trade-offs, and make decisions in fast-paced environments.
  • Strong prioritization and multitasking skills, with the ability to manage multiple initiatives simultaneously.
  • Comfortable communicating and collaborating with stakeholders at all levels of the organization, including senior leadership.
  • Experience with OneStream Software is not required; experience with financial consolidation or enterprise performance management platforms is a plus.

 

Who We Are

OneStream is how today’s Finance teams can go beyond just reporting on the past and Take Finance Further™ by steering the business to the future. It’s the only enterprise finance platform that unifies financial and operational data, embeds AI for better decisions and productivity, and empowers the CFO to become a critical driver of business strategy and execution. Our vision is to be the operating system for modern finance, digitizing core financial functions and empowering the CFO to become a critical driver of business strategy. To learn more visit www.onestream.com.


Why Join The OneStream Team

  • Transparency around corporate structure, salary, and benefits
  • Core value of customer success
  • Variety of project work (not industry-specific) 
  • Strong culture and camaraderie
  • Multiple training opportunities

 

Benefits at OneStream  
OneStream employees are passionate, hardworking individuals who go above and beyond to keep our customers happy and follow through on our mission statement. They consistently deliver the best and in turn, we make every effort to keep them cared for and happy. A sample of the benefits we provide are:

  • Excellent Medical Plan
  • Dental & Vision Insurance
  • Life Insurance
  • Short & Long Term Disability
  • Vacation Time
  • Paid Holidays
  • Professional Development
  • Retirement Plan

All candidates must be legally authorized to work for any company in the country where this position is located without sponsorship.

OneStream is an Equal Opportunity Employer.

#LI-CB1
#LI-Remote

Top Skills

.Net
C#

Similar Jobs

9 Days Ago
Easy Apply
Remote or Hybrid
36 Locations
Easy Apply
118K-231K Annually
Senior level
118K-231K Annually
Senior level
Big Data • Cloud • Software • Database
The Senior Application Security Engineer will advance MongoDB's security program by securing applications, conducting assessments, and collaborating with cross-functional teams to improve security practices.
Top Skills: AWSGCPGoGoogle WorkspaceJavaScriptPythonTypescript
10 Days Ago
Remote or Hybrid
Mountain View, CA, USA
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
As a Senior Application Security Engineer, you'll secure AI infrastructure and collaborate on secure app development, conduct penetration testing, and enhance the AppSec program.
Top Skills: AWSAzureBurp SuiteDastGCPGithub DependabotGoPythonSastSnyk
11 Days Ago
Easy Apply
Remote
USA
Easy Apply
123K-185K Annually
Senior level
123K-185K Annually
Senior level
Fintech • Social Impact • Financial Services
The Senior Application Security Engineer will protect company systems and data, conduct security reviews, and educate developers on secure practices.
Top Skills: ApexClojurePythonRubySast Tooling

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account