Application Security Engineer Dallas or Detroit metro
Comerica Incorporated.com
Office
Auburn Hills, MI, United States
Full Time
Application Security Engineer
The Application Security Engineer ensures Comerica’s applications are secure from Cyber threats. Generally working with dynamic and static code analyzers the application security engineer will communicate vulnerabilities to development teams and collaborates as necessary with development teams to remediate these vulnerabilities. The individual will also be responsible for integrating tool output into development pipelines. Creates and shares proof of concept code to demonstrate application attacks. Onboards applications and vulnerability tracking into management system and reports on progress. Hosts threat modeling exercises based on STRIDE or other industry standard methodology to draw out vulnerabilities during design phase. Guides aspiring application security individuals with Static and Dynamic Code Analysis.
Core Responsibilities
Threat Modeling & Design Reviews: Conduct risk assessments and threat modeling to identify potential vulnerabilities during the design phase of new applications. Vulnerability Management: Oversee the vulnerability management program, managing its implementation and remediation efforts. Secure Coding Practices: Promote and guide developers in adopting secure coding principles to build secure applications from the start. Security Testing: Perform and automate application security testing, including static and dynamic analysis (SAST/DAST), code reviews, and penetration testing.
Tool Integration: Implement and maintain various security tools, such as secret scanners, SCA (Software Composition Analysis), SAST, and DAST tools, within development pipelines. Developer Consultation: Act as a security consultant for development and product teams, providing technical security guidance and support. Security Training: Develop and deliver training materials to developers on security best practices and awareness.
Documentation: Create and maintain documentation for application security controls, standards, and guidelines.
Position Responsibilities:
- Performs integration of static and dynamic code scan output into CI/CD pipeline.
- Reviews of code analysis output and translation into findings.
- Utilizes the finding management software and tracking remediations with the development teams.
- Performs development and application team education resolution training.
- Performs emerging threat and threat landscape research.
- Provides forensic cyber event analysis.
- Identifies means to reduce cyber-attack effectiveness. Looks for continuous improvement of detections for operationalization.
- Leads threat modeling workshops to draw out vulnerabilities.
- Champions industry standard Threat Modeling framework (such as STRIDE).
- Updates detection tools as new vulnerabilities emerge.
- Stays aware of new vulnerabilities to articulate their inner workings against Comerica's environment.
- Works closely with partners in Cyber and Technology to solve security problems.
- Serves as the escalation point for cyber incidents, events, and application vulnerability research.
- Identifies and provides guidance to mitigate threat vectors unique to the shared cyber attack surface.
- Proactively communicates with application development teams to illustrate vulnerabilities and solutions.
- Identifies & evaluates projects, products, and solutions to enhance threat detection and other capabilities.
- Provides expert guidance on highly complex, large projects to incorporate cyber and fraud detection capabilities and considerations.
- Participates in industry working and information sharing groups.
- Keeps management informed of status of threats, the threat landscape, and current incidents and events through appropriate reporting.
- Actively participates on committees representing Cybersecurity. Keeps abreast of leading-edge technologies in the application security space.
- Other duties as assigned.
Application Security Engineer Dallas or Detroit metro
Office
Auburn Hills, MI, United States
Full Time
October 6, 2025