Technology Engineer, Application Security

PNC

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Pittsburgh, PACleveland, OHBirmingham, ALDallas, TXLakewood, CO
Salary
$86,250–$158,125 / yr
Posted
45 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $180k
This role $122k
$70k most similar roles pay here $236k

This role pays less than 95% of similar roles. Most pay $145,700–$215,178 — the shaded band above. At the midpoint, this role pays about $122k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About PNC

PNC is one of the largest diversified financial services institutions in the U.S., based in Pittsburgh, PA, it provides retail banking, corporate banking, and asset management.

PNC currently has 118 open roles on FindRole.

Listed pay typically runs $86,250–$172,500 across 62 roles with salary data.

Most-posted roles

View all roles at PNC

At a glance

TL;DR · Technology Engineer, Application Security

Technology Engineer - Application Security (JAVA/.NET) As a member of the Technology organization, you will identify, evaluate, and mitigate application security risks throughout the entire software development lifecycle. You will be responsible for triaging and remediating web application security vulnerabilities while providing guidance on mitigation strategies based on your knowledge of the OWASP Top 10. Your daily work involves collaborating with engineering teams to promote secure coding practices, manually validating software vulnerabilities, and distinguishing legitimate attacks from false positives. The role requires a background in software development using Java and/or .NET. You will also utilize Interactive Application Security Testing (IAST) tools and manage incident responses related to application attacks. This position focuses on enhancing the overall security posture of applications by ensuring that technical solutions are built, integrated, and configured according to established security standards and requirements.

What you'll do

  • Identify, evaluate, and mitigate application security risks throughout the entire software development lifecycle.
  • Provide guidance on mitigation strategies for OWASP Top 10 web application risks to relevant teams.
  • Triage and remediate web application security vulnerabilities within the organization.
  • Manually validate compensating controls when direct remediation of identified vulnerabilities is not immediately possible.
  • Analyze and manually validate software vulnerabilities to distinguish legitimate attacks from false positives.
  • Design, build, and maintain technology solutions while selecting appropriate platforms and configuring systems.
  • Develop software components and hardware for new and emerging technology projects aligned with business goals.
  • Provide consultation on common issues and best practices for junior staff members.

What we're looking for

  • Candidates must have a bachelor's degree or an equivalent combination of education, certifications, and experience.
  • Candidates must have 3+ years of relevant or direct industry experience.
  • Must possess good verbal and written communication skills.
  • Must have a software development background, preferably in Java and/or .NET.
  • Must have demonstrated experience in software development with comprehensive knowledge of application security.
  • Must be proficient in triaging and remediating web application security vulnerabilities.
  • Must have a practical understanding of the OWASP Top 10 web application risks.
  • Experience in incident response pertaining to application attacks is an advantage.

More like this

Similar roles

Junior Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Senior Application Security Engineer

LPL Financial

Fort Mill, NC +5 32 days ago $100,631$167,787
Application Security OWASP Top 10 DevSecOps CI/CD IAST Burpsuite Postman Synopsys BlackDuck J-Frog PrismaCloud C# Java HTML CSS React Angular
5+ yrs exp Hybrid

Application Security Engineer

Opendoor

Toronto, Canada 86 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid

Application Security Engineer

Opendoor

Miami, FL 86 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid

Application Security Engineer

Leidos

Ashburn, VA 60 days ago $107,900$195,050
Application Security SAST DAST SCA SDLC Machine Learning Artificial Intelligence Container Security Anchore Kubernetes Rancher Cloudera Salt Ansible CI/CD Elasticsearch GitLab
8+ yrs exp