Samsung SDS is seeking a detail-oriented Information Security Engineer – Web Application Security to join our Cloud Security Team. This role is responsible for conducting web application security assessments, managing application security assets, identifying and tracking vulnerabilities through remediation, and partnering with development and technical teams to address security risks.
🏢 About Samsung SDS
Samsung SDS is the digital arm of the Samsung group and a global provider of cloud and digital transformation innovations. Samsung SDS delivers enterprise-grade solutions and services in cloud, secure mobility, analytics / AI, digital marketing and digital workspace. We enable our customers in government, financial services, healthcare, and other industries to drive business in a hyper-connected economy helping them to increase productivity, safeguard assets, and make smarter decisions.
🎯 The Role
The engineer will support secure software development practices by providing security guidance and training to developers, analyzing reported vulnerabilities, and assisting with remediation efforts. The role works cross-functionally with application developers, infrastructure and systems teams, information security, business units, and customers to identify risks and drive timely resolution of web application security issues.
✅ Key Responsibilities
Perform periodic security assessments and vulnerability testing of company and customer-facing web applications.
Conduct security assessments for newly developed or newly deployed web applications before production release.
Maintain and manage the inventory of web applications and related assets, ensuring accuracy and consistency of asset information.
Identify, analyze, and document web application vulnerabilities and provide remediation recommendations to development and system teams.
Track identified vulnerabilities through remediation and perform follow-up validation or retesting to confirm successful resolution.
Provide security guidance and technical support to developers for vulnerability remediation.
Develop and deliver secure development training for developers, including common web application vulnerabilities, secure coding practices, and vulnerability prevention.
Investigate reported security concerns or vulnerabilities affecting specific websites and support the responsible teams in analysis, remediation, and validation.
Prepare and maintain vulnerability assessment reports, remediation status, and supporting documentation.
Collaborate with development, infrastructure, security, and customer teams to improve the overall security posture of web applications.
📌 Required Qualifications
Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent practical experience.
2–5 years of experience in information security, web application security, vulnerability management, or a related field.
Understanding of web application security concepts and common vulnerabilities, including the OWASP Top 10.
Experience conducting web application vulnerability assessments or penetration testing.
Knowledge of HTTP/HTTPS, web architecture, authentication, session management, APIs, and common web technologies.
Familiarity with web security testing tools such as Burp Suite, OWASP ZAP, WebInspect, or similar tools.
Ability to analyze vulnerability findings, identify exploitable security risks, and distinguish legitimate findings from false positives.
Understanding of secure coding principles, vulnerability remediation, and validation techniques.
Basic knowledge of operating systems, networking, and infrastructure security.
Strong technical documentation and communication skills, with the ability to clearly communicate security findings and remediation requirements to developers and other stakeholders.
Ability to collaborate effectively with application developers, infrastructure teams, information security teams, business units, and other stakeholders.
⭐ Desirable Experience
Experience working directly with software developers to identify, remediate, and validate web application vulnerabilities.
Experience with web application asset management and vulnerability tracking.
Experience supporting secure software development practices or providing security guidance to development teams.
Security certifications such as Security+, CEH, OSCP, or other relevant industry certifications.
Experience with vulnerability management processes, including remediation tracking and validation.
Strong analytical, problem-solving, and organizational skills.
🎁 Benefits
Samsung SDSA offers a comprehensive suite of programs to support our employees:
Top-notch medical, dental, vision and prescription coverage
Wellness program
Parental leave
401K match and savings plan
Flexible spending accounts
Life insurance
Paid Holidays
Paid Time off
Additional benefits
🛂 Visa & Eligibility
Samsung SDS America, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, status as a protected veteran, marital status, genetic information, medical condition, or any other characteristic protected by law. We are committed to providing reasonable accommodations to participate in the job application.
Please let Samsung Sds America know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.