Application Security Engineer
Bain & Company
- Location
- Mexico City
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 27 approvals (FY2023)
Skills
About this role
Please submit your resume in English to be considered. What Makes Us a Great Place to Work We are proud to be consistently recognized as one of the world's best places to work. We are currently the top-ranked consulting firm on Glassdoor's Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don't happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally. Where You'll Fit Within the Team As an Application Security Engineer, you'll help scale our shift-left security program by leading our code scanning capabilities and supporting the adoption of AI-enabled static code analysis technologies across our global development teams. This is a highly collaborative, technical role where you'll work alongside engineering teams to integrate security seamlessly into the software development lifecycle. You'll help reduce vulnerabilities at the point of code creation, translate security risks into practical guidance for developers, and communicate security progress effectively to both technical and non-technical stakeholders.
What You'll Do
As an Application Security Engineer, you will: Own and operate application security scanning capabilities, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), secret detection, and Infrastructure-as-Code (IaC) scanning. Lead the deployment and adoption of Wiz Code across development teams and CI/CD pipelines. Define and maintain secure coding standards and policy-as-code practices. Integrate security scanning into developer IDEs, pull request workflows, and CI/CD pipelines. Configure and optimize scanning rules to improve detection quality while minimizing false positives. Develop dashboards and reporting to measure application security posture, remediation progress, and key performance indicators. Build automation that streamlines vulnerability triage, ticket creation, and remediation workflows. Serve as a trusted security partner for development teams, supporting security issues through resolution. Evaluate emerging application security technologies and recommend improvements to the security tooling ecosystem. Develop documentation, developer guidance, and onboarding materials that enable teams to adopt secure development practices. Monitor, triage, and prioritize security findings, partnering with engineering teams to drive timely remediation of critical vulnerabilities. Identify recurring security patterns and implement long-term improvements that reduce organizational risk. Support application security investigations, root cause analysis, and compliance activities. Provide clear communication on application security risks, remediation progress, and program maturity. Advocate for security-by-design principles and help foster a culture of shared responsibility for secure software development.
About You
Required Qualifications Undergraduate degree or equivalent relevant work experience. 2–4 years of experience in Application Security, DevSecOps, or a related security or software engineering role. Experience with application security concepts including SAST, SCA, secret scanning, and Infrastructure-as-Code scanning. Understanding of common software vulnerabilities, including the OWASP Top 10, CVEs, and software dependency risks. Experience supporting CI/CD pipelines such as GitHub Actions, GitLab CI, or Jenkins. Ability to