Avatar for TeradataAster
TeradataAster
Actively Hiring
Teradata Aster works to help companies meet their big analytics and discovery needs

Application Security Engineer

Posted: 3 days ago• Recruiter recently active
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Python
Java
Azure
Ansible
AWS
Terraform
Go
Google Cloud
FEDRAMP
PCI-DSS
Cloudformation
helm
IaC
C/C++
DAST
SAST
CI/CD Pipelines
JavaScript/TypeScript
SCA
OWASP ASVS
Prompt Injection
Container Scanning
Insecure Output Handling
Open-Source Dependencies
Unsafe Tool Use
OWASP Top Ten (2025)
AISVS
SVPS
Excessive Permissions
OWASP AI Security Standards

About the job

Our Company

At Teradata, we believe that people thrive when empowered with better information. Teradata Autonomous Knowledge Platform activates enterprise intelligence by unifying data, knowledge and business context to achieve tangible outcomes. With Teradata, organizations can provide agents with full context for impact when it matters. Our solution lets businesses connect and scale on premises, in the cloud, or through a hybrid approach. Teradata delivers real business value with AI.

What You’ll Do

  • The Application Security integrates and support security at every phase of the software development lifecycle (SDLC) and work closely with developers to ensure applications are secure from inception through release. Given Teradata’s large portfolio of analytic applications, we are pushing the boundaries of security by automating source code analysis, and analytic security. Our expertise lies in deep technical understanding of security and our application security engineers within Teradata. The Application Security team is tasked with enabling software developers to build secure application and products through automating security (Shifting Left).
  • Analyze and triage findings from SAST, SCA, DAST, IaC, and container scanning tools to identify true positives and eliminate noise.
  • Deliver clear, actionable remediation guidance to development teams for AppSec findings across the application portfolio.
  • Perform code reviews and reason about vulnerabilities across Java, C/C++, Go, Python, and JavaScript/TypeScript codebases.
  • Integrate and tune AppSec scanning tools within CI/CD pipelines to shift security left in the SDLC.
  • Assess web applications and APIs for common vulnerability classes including the OWASP Top Ten (2025).
  • Apply OWASP ASVS, AISVS, and SVPS standards to application security assessments and security requirement definitions.
  • Review AI-assisted development workflows and evaluate agentic systems for risks such as prompt injection, excessive permissions, unsafe tool use, and insecure output handling.
  • Investigate software supply chain risks by analyzing open-source dependencies for known vulnerabilities, suspicious packages, and dependency confusion exposures.
  • Write and maintain automation scripts in Go to streamline security processes and tool integrations.
  • Review and assess Infrastructure as Code configurations in Terraform, CloudFormation, Helm, and Ansible for security misconfigurations.
  • Evaluate cloud environments across AWS, Azure, and/or Google Cloud for AppSec risk and misconfigurations.
  • Communicate security findings and risk clearly to both technical and non-technical stakeholders.
  • Support compliance activities related to PCI-DSS and FedRAMP as they intersect with application security.

Who You’ll Work With

  • The Application Security team is an integral part of Teradata Information Security and closely partners and guides Product Engineering. Application Security team works with several teams such as CloudOps, DevOps and our Engineering teams.

What Makes You a Qualified Candidate

Proficient in 1 or more of any of the following areas:

  • Read and reason about code in Java, C/C++, Go, Python, or JavaScript/TypeScript to identify and address security issues.
  • Integrate SAST, SCA, DAST, IaC, and Container scanning into CI/CD pipelines.
  • Spot manual security processes and build automation to replace them.
  • Write and maintain security automation scripts in Go.
  • Identify and remediate software supply chain risks including malicious or compromised third-party packages, typosquatting, and dependency confusion attacks.
  • Evaluate internal software and third-party products against security requirements.
  • Evaluate new technologies and development practices for AppSec impact.
  • Apply OWASP AI security standards to assess and reduce risk in AI-generated code and agentic workflows outlined in OWASP AI Top Tens.
  • Familiarity with the OWASP AISVS and OWASP Top 10 for LLMs, Agentic Apps, or NHIs as emerging standards for AI security.
  • Translate SAST, SCA, DAST, IaC, container scan, and pentest findings into plain-language summaries for non-security audiences.
  • Work directly with Product Engineering to improve security practices across the Secure SDLC.
  • Deliver developer training on secure coding, security requirements, and AppSec tooling.
  • Guide and mentor software engineers on vulnerability remediation.
  • Serve as the go-to SME for AppSec topics, processes, and tooling.
  • Make sound, well-reasoned security decisions and explain the tradeoffs clearly.

Education Background:

  • Knowledge of core application security principles, common security vulnerability classes, their root causes, and mitigations
  • MS/BS degree in Electrical Engineering, Computer Science, Information Technology, or related field. Advanced degree highly preferred

Why We Think You'll Love Teradata

We prioritize a people-first culture because we know our people are at the very heart of our success. We embrace a flexible work model because we trust our people to make decisions about how, when, and where they work. We focus on well-being because we care about our people and their ability to thrive both personally and professionally. We are committed to actively working to foster an inclusive environment that celebrates people for all of who they are.

Why We Think You’ll Love Teradata

We prioritize a people-first culture because we know our people are at the very heart of our success. We embrace a flexible work model because we trust our people to make decisions about how, when, and where they work. We focus on well-being because we care about our people and their ability to thrive both personally and professionally. We are an anti-racist company because our dedication to Diversity, Equity, and Inclusion is more than a statement. It is a deep commitment to doing the work to foster an equitable environment that celebrates people for all of who they are.

Teradata invites all identities and backgrounds in the workplace. We work with deliberation and intent to ensure we are cultivating collaboration and inclusivity across our global organization. ​ We are proud to be an equal opportunity and affirmative action employer. We do not discriminate based upon race, color, ancestry, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related conditions), national origin, sexual orientation, age, citizenship, marital status, disability, medical condition, genetic information, gender identity or expression, military and veteran status, or any other legally protected status.

About the company

TeradataAster company logo

TeradataAster

Actively Hiring
Teradata Aster works to help companies meet their big analytics and discovery needs5000+ Employees
Learn more about TeradataAster image

Founders

Art Gallardo
Founder
Los Angeles
image
View the team image

Similar Jobs

Astranis company logo
Astranis
Building next-generation internet satellites to get the world online
Scale AI company logo
Scale AI
Accelerate the development of AI applications
Assured company logo
Assured
Automated claims are now a reality
Orchard Robotics company logo
Orchard Robotics
Securing America's food supply by building the AI farmer that automates our nation's farms
EliseAI company logo
EliseAI
Building AI agents that transform complex healthcare and housing systems
NumeralHQ company logo
NumeralHQ
Sales tax on autopilot for Ecommerce & SaaS ✨ Spend 5 mins or less per month on compliance
C3 AI company logo
C3 AI
C3 AI is a leading enterprise AI software provider for accelerating digital transformation