ASX

Application Security Engineer

ASX

Sydney, New South Wales, Australia · Full Time

Be the first to apply

Experience
Any
Salary
Openings
1
Posted
1 hour ago
Work mode
In office
Eligibility
Applicants must be legally eligible to work in Australia permanently with no restrictions.
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About ASX

ASX is a pivotal institution in Australia's financial markets, driving a more robust economic future through a fair and dynamic trading platform. Joining ASX means becoming part of a globally recognized securities exchange known for its reliability and as a significant data hub.

ASX is proud of its diverse and inclusive work culture, fostering a sense of belonging across various communities and promoting equality, accessibility, and wellbeing. The team is comprised of professionals spanning operations, program delivery, financial products, risk, compliance, and primarily technology, which makes up a third of the workforce.

Role Overview

The Application Security Engineer role is located within the Security Operations and Engineering division of ASX Cyber Security. This team is responsible for defending ASX’s technology infrastructure by managing detection, response, vulnerability management, and secure technology enablement.

This position involves collaborating with numerous applications and delivery teams to tailor application security improvements suitable for each team's maturity. You will conduct focused security assessments and use AI-enhanced code analysis to detect vulnerabilities and weaknesses in critical applications.

Key Responsibilities

  • Identify, prioritize, and lead remediation efforts for critical and high-severity code vulnerabilities alongside engineering teams.
  • Assist with threat modeling, secure design reviews, and security evaluations of priority applications and automation workflows.
  • Customize application security guidelines to accommodate various engineering team maturity levels, balancing risk mitigation, standardization, and delivery speed.
  • Provide hands-on secure coding advice, remediation patterns, and detailed recommendations to expedite effective vulnerability fixes.
  • Support remediation by reviewing or contributing to pull requests where needed for knowledge transfer and timely fixes.
  • Help develop and embed security checkpoints, guardrails, and automation within the software development lifecycle and continuous integration/delivery pipelines.
  • Enhance the effectiveness of application security tooling such as SAST, DAST, SCA, and other related controls without hindering delivery velocity.
  • Promote or establish Security Champion programs within delivery teams to maintain secure coding standards after engagements.
  • Create documentation, reusable security patterns, and team enablement resources to ensure sustainable ownership of security practices.

Required Qualifications & Experience

  • Proven hands-on experience in application security, secure software engineering, or direct vulnerability remediation.
  • Deep knowledge of secure coding principles, typical vulnerability types including OWASP Top 10, and remediation strategies.
  • Experience reviewing application code and collaborating with engineering teams to fix vulnerabilities in modern development contexts.
  • Understanding of secure software development lifecycle controls, DevSecOps methodologies, CI/CD security integration, and automated application security tools.
  • Practical usage experience with application security tools such as static (SAST), dynamic (DAST), software composition analysis (SCA), secret scanning, and container or cloud security assessment tools.
  • Capability to work across diverse applications, platforms, or teams with varying application security maturity.
  • Adeptness at adjusting security approaches based on risk, complexity, and business needs while maintaining strong engagement with stakeholders.
  • Ability to communicate technical vulnerability risks and remediation priorities clearly to technical and non-technical audiences.

Preferred Skills

  • Possession of recognized security certifications like CSSLP, GWAPT, GWEB, OSWE, CISSP, or equivalent practical security knowledge.
  • Experience in financial services, critical infrastructure, or highly regulated environments.
  • Exposure to AI-powered security analysis, threat modeling, or secure-by-design initiatives.
  • Familiarity with DevOps pipelines and enterprise Java or similar development environments.
  • Experience establishing Security Champion initiatives, mentoring developers, or enhancing secure coding skills across teams.

Additional Information

ASX values skills, potential, and alignment with its values and encourages candidates to apply even if all criteria are not met. Accommodations during recruitment are available upon request to support all applicants.

The organization offers flexible and hybrid working arrangements despite the full-time employment notice. Successful applicants will undergo background verification, including police and reference checks.

Applicants must have lawful and unrestricted work rights in Australia on a permanent basis.

How they work

Communication Adaptability Relationship Building

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer