Sr Application Security Engineer - Cyber Security
Las Vegas Sands
- Location
- Las Vegas
- Work model
- On-Site
- Level
- Senior
- Posted
- 6h ago
Skills
About this role
Job Description
Position Overview The primary responsibility of the Sr Engineer – Cyber Security is to design, implement, and support application security capabilities that integrate into the company’s Software Development Lifecycles (SDLCs). This role partners with development, quality assurance, and cyber security teams to evaluate application risk, operate AppSec technologies, support secure coding practices, and guide remediation of software vulnerabilities. All duties are to be performed in accordance with departmental and Las Vegas Sands Corp.’s policies, practices, and procedures. All Las Vegas Sands Corp.
Team
Members are expected to conduct and carry themselves in a professional manner at all times.
Team
Members are required to observe the Company’s standards, work requirements and rules of conduct. Essential Duties & Responsibilities Develop, implement, and support application security programs across Software Development Lifecycles (SDLCs), including technology integration, workflow design, documentation, training, and stakeholder enablement. Evaluate SDLCs and advise on application security technologies, integration points, and process improvements to reduce software security risk. Perform code, vulnerability, and configuration analysis using manual review and automated application security testing solutions, including SAST and DAST tools. Partner with development teams to prioritize product vulnerabilities, validate mitigation urgency, and provide remediation guidance and recommendations. Configure, implement, maintain, troubleshoot, and support capacity planning for cyber security tools, devices, infrastructure, and application security technologies. Monitor tool health, respond to security outputs, and tune solutions to support reliable performance, business-focused monitoring, and program objectives. Respond to cyber security events and incidents with professionalism and support practice exercises for use case driven alerts and incidents. Identify security requirements and support cyber security architecture, secure configuration, and product security reviews across heterogeneous computing environments. Create and maintain cyber security documentation, including design materials, standard operating procedures, protocols, diagrams, metrics, reports, and presentations. Collaborate with cyber security, IT, business, development, quality assurance, and administrative teams to troubleshoot issues, support operational needs, and promote secure software development practices. Manage operational requests by submitting and responding to tickets, preparing change management items, and participating in Change Approval Board (CAB) meetings. Stay current on malware, infiltration and investigative techniques, forensics, application security practices, and the evolving threat environment. Mentor junior engineers to develop job competency, technical skills, and cyber security expertise. Perform job duties in a safe manner. Attend work as scheduled on a consistent and regular basis. Perform other related duties as assigned.
Minimum Qualifications
At least 21 years of age. Proof of authorization to work in the United States. Bachelor’s degree in Computer Science or related field. Must be able to obtain and maintain any certification or license, as required by law or policy. 5 - 7 years of experience in cyber security or information technology. Experience in at least 5 of the following: Secure SDLC, DevSecOps, or application security program support. Implementing application security testing tools, including SAST, DAST, SCA, secrets scanning, or container scanning. CI/CD pipeline security, release gating, and developer workflow integration. Cloud architecture security, including secure configuration, identity, network, and workload protection. Application vulnerability assessment, triage, and remediation validation. Software composition analysis, open-source risk management, and dependency vulnerability management.