Application Security Engineer
Acuity Inc. (NYSE: AYI) is a market-leading industrial technology company. We use technology to solve problems in spaces, light and more things to come. Through our two business segments, Acuity Brands Lighting (ABL) and Acuity Intelligent Spaces (AIS), we design, manufacture, and bring to market products and services that make a valuable difference in people’s lives.
We achieve growth through the development of innovative new products and services, including lighting, lighting controls, building management solutions, and an audio, video and control platform. We focus on customer outcomes and drive growth and productivity to increase market share and deliver superior returns. We look to aggressively deploy capital to grow the business and to enter attractive new verticals.
Acuity Inc. is based in Atlanta, Georgia, with operations across North America, Europe and Asia. The Company is powered by approximately 13,000 dedicated and talented associates. Visit us at www.acuityinc.com.
Job Summary
We're seeking a talented and enthusiastic Application Security Engineer who will work with the development teams to ensure security is embedded in the overall Software Development Life Cycle (SDLC) process and technology risk are addressed at each phase. You will serve as highest level technical architecture expert for software development / infrastructure teams at the program level and are expected to conduct security assessments and penetration testing. You will research and evaluate vulnerabilities, attack vectors, and associated risks to determine the impact to our application systems.
Key Tasks & Responsibilities (Essential Functions)
- Conduct security assessments of web and mobile applications, APIs, and microservices.
- Proactively identify and mitigate against application security risks or incidents
- Perform application and source-code reviews, threat modeling and penetration tests to build application visibility
- Participate in the architecture of mobile and web applications including interface and database design, process and API flows, networking, cloud infrastructure, protocol communication, security and appropriate technology use.
- Provide guidance and oversight into secure application coding practices conducted by other teams by acting as a mentor to software developers
- Provide security training to internal engineering, DevOps and infrastructure teams.
- Develop and implement the application security program in-line with industry best practices and compliance across all of Acuity Brands engineering teams.
- Raise awareness of application security requirements through development and review of application security standards, policies and secure SDLC processes
- Continuous learning and researching security related trends and best practices.
Preferred Skills and Experience
- Bachelor's Degree in Computer Science (CS) or equivalent
- 8+ years of experience in the security domain with working knowledge of Software Development and required knowledge of application testing
- Experience with static analysis tools (e.g., SNYK, BlackDuck, Checkmarx) and knowledge of OWASP tools and methodologies.
- Experience with vulnerability and application scanning tools (e.g., Qualys, Nessus, AppScan, BurpSuite)
- Application security experience with high level programming languages (e.g., Java, C, C++, C#, VB, .NET, ASP.NET, ASP, PHP, J2EE, JSP)
- Programing background and working experience in SDLC and software development tools such as Eclipse, Jenkins or similar
- Experience with Cloud Service Providers (Azure and/or AWS)
- Security certifications, such as CISSP, CEH, OSCP, CISA, are desirable
- Communication skills to create documentation, videos and conduct training classes
We value diversity and are an equal opportunity employer. All qualified applicants will be considered for employment without regards to race, color, age, gender, sexual orientation, gender identity and expression, ethnicity or national origin, disability, pregnancy, religion, covered veteran status, protected genetic information, or any other characteristic protected by law.
Accommodation for Applicants with Disabilities: As an equal opportunity employer, Acuity Inc. is committed to providing reasonable accommodations in its application process for qualified individuals with disabilities and disabled veterans. If you have difficulty using our online system due to a disability and need an accommodation, you may contact us at (770) 922-9000. Please clearly indicate what type of accommodation you are requesting and for what requisition.
Any unsolicited resumes sent to Acuity Inc. from a third party, such as an Agency recruiter, including unsolicited resumes sent to an Acuity Inc. mailing address, fax machine or email address, directly to Acuity Inc. employees, or to Acuity Inc. resume database will be considered Acuity Inc. property. Acuity Inc. will NOT pay a fee for any placement resulting from the receipt of an unsolicited resume.
Acuity Inc. will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees. This includes any Agency that is an approved/engaged vendor, but does not have the appropriate approvals to be engaged on a search.
Job Segment:
Cloud, Testing, Application Engineering, Embedded, Developer, Technology, Engineering