Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Application Security Engineer image - Rise Careers
Job details

Senior Application Security Engineer

Overview:   

Responsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration.  Provides advanced working guidance to technology teams and leadership in the areas of secure coding, application authentication, encryption, and quickly research and become competent in other areas as needed.

Primary Responsibilities:

  • Develop and implement engineering’s technical security policies and procedures, and performance of security measures,
  • Scan and test applications for potential vulnerabilities and non-compliance with security standards,
  • Partner with engineering teams during code reviews to identify potential security vulnerabilities and advise strategies to develop more secure code,
  • Integrate security tools and processes into the software development and operations (DevOps) pipeline, including automation of security checks and scans to identify and fix vulnerabilities early in the development process.
  • Lead training sessions for technology teams in one-on-one coaching and large team training sessions on secure coding practices and information system security best practices.
  • Configure and manage automated tools and solutions to address security weaknesses in applications, systems, and infrastructure.
  • Partner closely with incident response teams to mitigate the impact of incidents from application security vulnerabilities and identify necessary steps to remediate findings.
  • Proactively recommend process enhancements and implement prioritized improvements within Cybersecurity team to enhance application security capabilities.
  • Track current events, technological advancements, and changes in the secure application development landscape to anticipate how attackers may change their tactics, and implement adjustments to internal technologies, policies, and procedures.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports belonging and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Scope of Responsibilities:

  • Partners primarily with individual contributors and leaders within Cybersecurity and Technology, and occasionally senior leaders within Cybersecurity.
  • Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met.
  • Proficient ability to use multiple Cybersecurity tools, specific to function.
  • This role is used within Cybersecurity, typically in one of the following ways:
    • Application Security – partners with engineers and developers to secure first-party and third-party code by reviewing the application, data, and systems it interacts with.
    • Product Security – secures products by ensuring they are designed, developed, and delivered in a secure manner".

                       

Manager Responsibilities:

No supervisory responsibilities

Education and Experience Required:

  • Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience, including a minimum of 5 years software development or application security
  • Prior experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
  • Intermediate understanding of the Software Development Life Cycle (SDLC)
  • Ability to train technologist and people leaders at various levels on secure application development, both in person and virtually
  • Excellent communication and interpersonal skills

Education and Experience Preferred:

  • Intermediate experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
  • Understanding of common software weaknesses that impact cloud and web applications, beyond the Open Worldwide Application Security Project (OWASP) Top 10
  • Demonstrable experience developing and maintaining automation for application security tasks and defect identification
  • Experience developing enterprise applications
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments
  • Certifications in the area of Application Security
  • Proficient persuasive communication skills to gain buy-in of others in cybersecurity and technology teams
  • Ability to create an effective learning environment that allows for maximum learner results
  • Must be comfortable with providing 1-1 coaching for all levels of individual contributors and up to SVP management
  • Ability to build and maintain effective relationships within and across multiple technical teams
  • Prior experience utilizing continuous integration and continuous deployment (CI/CD) pipeline instrumentation
  • Highly proficient at coding with one or two programming languages
  • Highly proficient with Agile development methodologies and version control systems
  • Experience defining and reviewing software security features and capabilities

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $93,581.10 - $155,968.51 (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation. The range listed above corresponds to our national pay range for this role. The specific pay range applicable to you may vary based on your location.

Location

Clanton, Alabama, United States of America

Average salary estimate

$124774.80500000001 / YEARLY (est.)
min
max
$93581.1K
$155968.51K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Posted 11 hours ago

M&T Bank is hiring a Commercial Payment Sales Consultant I to grow and service treasury management relationships and deliver tailored commercial payments solutions to sophisticated business clients.

Early-career technologists will join M&T Bank’s two-year Technology Development Program to develop infrastructure automation skills supporting Terraform, Ansible, Kubernetes and developer experience tooling.

Posted 18 hours ago

FurtherAI seeks an experienced Forward Deployed Engineer to build and deploy enterprise-grade AI agents in production while working on-site from our San Francisco HQ.

Photo of the Rise User
Posted 14 hours ago

Lead a remote engineering team to drive API architecture, DevOps best practices, and cloud-native delivery for federal customers supporting the Department of Veterans Affairs.

Posted 10 hours ago

Lead technical design and delivery for Cengage Work platforms, driving scalable, resilient, customer-centric education technology as an Advanced Software Engineer.

Posted 22 hours ago

Experienced geospatial developer needed to build and customize ArcGIS-based web applications and dashboards for mission-driven government projects.

Photo of the Rise User
Posted 5 hours ago

Contribute to Litera’s lawtech platform as a Clojure-focused Software Engineer, building AI-forward features that impact millions of legal professionals.

Photo of the Rise User
Posted 4 hours ago

A Summer 2026 undergraduate software engineer intern role at enGen offering hands-on Java development experience on a scrum team supporting healthcare case and disease management applications.

Photo of the Rise User
Posted 22 hours ago

FleetWorks seeks a Senior Software Engineer to own end-to-end TypeScript product development for voice AI agents that streamline freight booking from our SOMA office.

Photo of the Rise User

Build scalable, React-based internal tools and integrate ML/AI features as an Enterprise Front-End Engineer on a fully remote, enterprise-focused engineering team.

Photo of the Rise User
Mythic Hybrid Austin, TX or Palo Alto, CA or Remote
Posted 3 hours ago

Design and extend compiler IRs and lowering strategies to enable control-flow and iterative algorithmic workloads on Mythic's analog-digital AI accelerator, working cross-functionally with hardware teams.

Photo of the Rise User
Chabez Tech Hybrid 1906 Reston Metro Plaza, Reston, VA 20190, USA
Posted 4 hours ago

Work with ChabezTech’s engineering team in Reston to build and maintain Spring Boot microservices and React/TypeScript front-ends for enterprise data and analytics applications in a hybrid role.

Photo of the Rise User
Flow Hybrid New York, NY
Posted 15 hours ago

Lead and grow Flow's engineering teams as a hands-on Engineering Manager responsible for architecture, delivery, and talent development across full-stack systems.

Photo of the Rise User
Posted 4 hours ago

A fast-growing product company is looking for a Staff Frontend Engineer to define frontend architecture and build performant, intuitive web interfaces while guiding cross-functional teams and mentoring engineers.

Photo of the Rise User
Posted 4 hours ago

Experienced application development leader needed to manage remote development teams and drive delivery of high-quality marketing solutions for Vericast's financial institution clients.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
October 8, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!