Lead Application Security - DevSecOps & AI-Driven Software Assurance

East West Bank

Dallas, USonsite$120k-$180k/yrPosted Jul 21, 2026
Posting intelligenceActively listedReposted 18×, possible evergreen/ghost posting

Skills

githubcicd

About the role

Introduction:

Since 1973, East West Bank has served as a pathway to success. With over 110 locations across the U.S. and Asia, we are the premier financial bridge between the East and West. Our teams of experienced, multi-cultural professionals help guide businesses and community members on both sides of the Pacific looking to explore new markets and create new opportunities, and our sustained growth and expertise in industries like real estate, entertainment and media, private equity and venture capital, and high-tech help build sustainable businesses and our associates’ potential for career advancement.

Headquartered in California, East West Bank (Nasdaq: EWBC) is a top-performing commercial bank with a strong foundation, an enterprising spirit and a commitment to absolute integrity. East West Bank gives people the confidence to reach further.

Overview:

The Senior Cyber Security Engineer will lead and execute security initiatives across the application lifecycle, integrating security into DevOps pipelines, managing vulnerability assessments, and coordinating penetration testing efforts. This role also extends into advanced software assurance, including third-party software analysis, binary-level inspection, and application trust validation, ensuring that both internally developed and externally sourced applications meet the bank’s security standards prior to execution within the enterprise environment.

Responsibilities:

Application Security & DevSecOps Integration

Embed security controls into CI/CD pipelines using GitHub workflows and automation tools.

Collaborate with development teams to implement secure coding practices and threat modeling during design and development phases.

Manage GitHub Advanced Security configurations, including secret scanning, push protection, and impact analysis.

Security Testing & Vulnerability Management

Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using approved tools (e.g., CodeQL, Dependabot,, OWASP ZAP).

Perform manual and automated code reviews to identify vulnerabilities and ensure remediation through code fixes or configuration changes.

Maintain accurate mapping of applications to GitHub repositories to support vulnerability tracking and reporting.

Advanced Software Analysis & Trust Establishment

Perform security analysis of third-party software, including both source code review and compiled binary analysis where source is not available.

Conduct binary decomposition and reverse engineering techniques, as appropriate, to evaluate software behavior and identify embedded risks.

Support the establishment and execution of a software trust and reputation framework, enabling secure decision-making for application onboarding and whitelisting within the enterprise environment.

Analyze open-source and GitHub-hosted code, including dependencies and contribution risk.

Partner with AppSec leadership to support application security activities and formalize secure software approval processes.

API & Web Application Security

Conduct API security assessments and integrate monitoring tools to protect application endpoints.

Support WAF policy management and application-layer threat monitoring.

Threat Intelligence Integration

Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software.

Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications.

Penetration Testing & Third-Party Risk

Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software.

Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications.

Qualifications:

Proven experience in application security, DevSecOps, or software security analysis.

Strong hands-on expertise in:

SAST/DAST tools and secure SDLC practices

GitHub and open-source ecosystems

GitHub Advanced Security

Experience with third-party software risk analysis, software composition analysis (SCA), or reverse engineering / binary analysis

Familiarity with software supply chain security and trust validation frameworks

Experience integrating threat intelligence into security decision-making

Strong understanding of secure SDLC, threat modeling (e.g., STRIDE), and vulnerability management.

Experience coordinating penetration tests and working with third-party vendors.

Strong communication and stakeholder engagement skills.

Applicants must have legal authorization to work in the United States. We do not offer visa sponsorship at this time.

Compensation: The base pay range for this position is USD $120,000.00/Yr. - USD $180,000.00/Yr. Exact offers will be determined based on job-related knowledge, skills, experience, and location.

Compensation

This Security Engineer role pays $120k-$180k/yr. Within typical range for security engineer roles in United States.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.