Ascendion logo

Information Security Specialist

Ascendion

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

About the job:

We are seeking an experienced Secure by Design Engineer / Security Consultant who will support end‑to‑end security activities across the product development lifecycle. This role combines hands‑on security testing, architecture and design review, and advisory responsibilities. The resource is expected to work closely with product development teams to execute technical tasks on the ground while also providing expert consulting across security domains.

Responsibilities:

· Work directly with product development and engineering teams to embed security into DevOps/DevSecOps workflows.

· Perform solution outline reviews to validate architectural and security patterns early in the design phase.

· Facilitate and document threat modeling sessions to identify potential attack vectors and mitigation strategies.

· Review migration plans to ensure secure transition of services, data, and workloads.

· Assess access model implementations to confirm compliance with least‑privilege, RBAC, and segregation‑of‑duty principles.

· Perform security impact analyses for new features, changes, or technology integrations.

· Provide continuous security consulting to product and engineering teams.

· Conduct manual penetration testing across applications, APIs, infrastructure, and cloud components.

· Execute static application security testing (SAST), dynamic application security testing (DAST), and software dependency scanning.

· Perform container and image security scanning using industry-standard tools and methodologies.

· Conduct manual configuration reviews to validate secure configuration baselines.

· Execute system integration reviews to ensure security in multi‑component environments.

· Perform Infrastructure-as-Code (IaC) scanning to ensure compliance with security controls.

· Conduct ITPF conformance assessments to ensure solutions adhere to security and governance requirements.

· Support remediation activities by providing practical, actionable guidance.

· Communicate findings, risks, and mitigation strategies effectively to both technical and non‑technical stakeholders.

· Prepare detailed documentation, reports, and validation evidence.

Required Skills & Qualifications:

· 10+ years of experience in application security, cloud security, secure SDLC, or penetration testing.

· Strong knowledge of security testing methodologies, OWASP Top 10, SANS 25, MITRE ATT&CK, and threat modeling frameworks.

· Hands‑on experience with SAST, DAST, dependency scanning, container security tools, and IaC scanning.

· Practical penetration testing experience (web apps, APIs, cloud, infrastructure).

· Strong understanding of secure architecture, authentication/authorization models, and cloud-native security principles.

· Familiarity with DevSecOps practices, CI/CD pipelines, and modern development technologies.

· Excellent communication skills and the ability to work closely with cross-functional team

About Us:

Ascendion is a global, leading provider of AI firstsoftware engineering services, delivering transformative solutions across North America, APAC, and Europe. We are headquartered in New Jersey. We combine technology and talent to deliver tech debt relief, improveengineering productivity solutions, and accelerate time to value, driving our clients’ digital journeys with efficiency and velocity. Guided by our “Engineering to the power of AI” [EngineeringAI] methodology, we integrate AI into software engineering, enterprise operations, and talent orchestration, to address critical challenges of trust, speed, and capital. For more information, please go to www.ascendion.com

With Ascendion (www.ascendion.com), you:

  • Will get to work on numerous challenging and exciting projects on our various offerings including Salesforce, AI/Data Science, Generative AI/ML, Automation, Cloud Enterprise and Product/Platform Engineering.
  • At Ascendion you have high chances of project extension or redeployment to other clients.
  • Additionally, you can also share CV of anyone you know. We have a referral policy in place.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Ascendion was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.