About Us:
Recognized among Pittsburgh's 2024 Top Workplaces and Fastest-Growing Companies , Wolfe has been a leader in the Gift Card and FinTech sectors for over 25 years. We power gift card programs for national merchants like KFC. Our flagship consumer brand, PerfectGift.com, enables customers to create customized gift cards. Learn more about our company culture, core values, and industry recognition on our career page ( https://wolfe-llc.breezy.hr/ ) .
Job Summary:
Wolfe is seeking an Application Security Engineer to embed security throughout our development lifecycle and drive secure practices across our technology organization. In this hands-on role, you'll collaborate closely with Developers and DevOps engineers, advising on architecture, maturing security within CI/CD pipelines, and improving quality through the adoption of secure coding standards. You'll help shape how Wolfe builds secure systems while partnering with teams to balance risk, performance, and delivery.
If you are a developer looking to grow into a security role, or a security engineer ready to expand into Application Security and influence how engineers build software, we encourage you to apply!
- This is a five-day onsite role based in Pittsburgh, PA.
- Wolfe does not provide visa sponsorship.
Qualifications:
- Bachelor's Degree in Information Security, Cybersecurity, Computer Science, or a related field OR a minimum of 6 years' equivalent experience in lieu of a degree
- 4+ years of experience in application security and security engineering OR a combination of 2+ years experience as a developer and 2+ years in application security and security engineering
- Hands-on experience with security tools (SAST, DAST, SCA, container security, IaC security), improving automated security solutions within CI/CD pipelines, strong knowledge of secure coding principles (OWASP Top 10, SANS CWE Top 25), and familiarity with AI ML or LLM usage within security tooling.
- Experience with vulnerability management, web app penetration testing tooling, and security certifications like CISSP, OSCP, GCPN, GCSA, AWS Security Specialty, or CSSLP are preferred.
- Proficiency in Bot Management tooling, client-side monitoring tooling, and implementing maturity measurement frameworks such as DSOMM or BSIMM in an enterprise setting.
- Ability to understand and communicate best-practice system architectures, data flows, and security controls within modern web applications and cloud (SaaS/PaaS, IaaS).
- Excellent verbal and written communication skills, with the ability to communicate complex security concepts to technical and non-technical stakeholders.
Key Responsibilities:
Application Security & Code Vulnerabilities:
- Perform code reviews, static/dynamic security testing (SAST/DAST), and secure coding guidance to developers.
- Identify and remediate vulnerabilities in application code, libraries, containers, and infrastructure as code (IaC).
- Develop and enforce secure coding standards in alignment with OWASP, NIST, and other frameworks.
- Conduct threat modeling and security architecture reviews for applications and services. For example, assist application teams with developing accurate data flow diagrams and developing appropriate identity management solutions.
- Manage and mature Bot Management services for all applications. Assist with WAF management and maturity.
- Improve secrets management and API security.
Vulnerability Management & Risk Reduction:
- Manage and mature enterprise-wide Bug Bounty program (e.g. BugCrowd, HackerOne)
- Manage vulnerability scanning tools (e.g., Tenable, Qualys, Sonar, Snyk) and prioritize remediation efforts.
- Track, assess, and coordinate the remediation of vulnerabilities across the application, infrastructure, and cloud environments.
- Develop risk-based vulnerability management workflows and collaborate with engineering teams to drive fixes.
- Monitor security dashboards and metrics, ensuring vulnerabilities are patched in alignment with SLAs.
Security CI/CD Automation & Tooling:
- Implement security automation using APIs, scripts, and cloud-native security controls.
- Work with DevOps engineers to integrate security tooling (like SemGrep, Snyk, Cycode) or within Jenkins, GitHub, GitLab CI/CD, or AWS DevOps.
- Automate security findings triage, reporting, and prioritization processes.
DevSecOps & Maturity Measurement Implementation:
- Assess, report, and assist with improving application security and DevSecOps Maturity, utilizing a measurement framework such as DSOMM or BSIMM, across the organization.
- Define and implement security policies, standards, and best practices for DevOps, CI/CD pipelines, and cloud security.
Security Awareness & Collaboration:
- Train and mentor developers on secure coding, threat modeling, DevSecOps, and vulnerability management best practices.
- Collaborate with security operations, incident response, and compliance teams on security initiatives.
- Participate in security assessments, penetration testing, and security incident investigations.
Compensation & Benefits:
Wolfe is committed to providing a comprehensive benefits package to support your well-being, along with competitive compensation targeting the top 25% (75th percentile) in the local market. Our benefits and perks include but not limited to:
Restricted Stock Units (RSUs)
Profit Share
Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
Short-Term Disability Insurance (Wolfe pays 100% of premium)
Voluntary Long-Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
PTO (vacation)
Corporate Holidays
401(k)
Employee recognition program
Charitable Donation to a charity of your choice yearly
Employee Referral Bonus
Tuition Reimbursement
Internal Training and Information sessions
Family Picnic, Holiday Party, and other outings
Internal Culture Club
Wolfe is an Equal Opportunity Employer.
Wolfe does not sponsor individuals for the purpose of obtaining H-1 Visas. _
_