About the role
What will you do at ADP?
ADP is hiring a Senior Application Security Engineer in our Alpharetta, GA office. This is a hybrid role. Overview: We are seeking a Senior Application Security Engineer to secure our software supply chain by assessing, governing, and mitigating risks associated with open-source software.
This role partners closely with engineering, DevOps, and security teams to drive secure OSS adoption at scale.
What You’ll Do
- * Generate and analyze SBOMs and conduct OSS security assessments using tools like Snyk and Syft.
- * Evaluate and onboard security tools through POCs.
- * Build and operate cloud-based data pipelines to identify vulnerabilities, license risks, and supply chain threats.
- * Develop dashboards and reports to communicate security risk to engineering teams and leadership.
- * Design and integrate OSS security tooling, including JFrog Artifactory/Xray or Sonatype Nexus/Lifecycle.
- * Partner with engineering teams to guide secure open-source usage and remediation.
- * Support incident response efforts, including zero-day vulnerability management.
- * Create OSS security standards, documentation, and training materials.
- Experience You’ll Need * 7+ years of experience in cybersecurity, application security, or software supply chain security.
- * Hands-on experience with SBOMs, OSS scanning tools, and vulnerability management.
- * Experience with JFrog or Sonatype artifact repository platforms.
- * Strong background in cloud-native security and automation.
- Skills & Technologies * Programming: Python; npm / Node.js ecosystems * Cloud & Platforms: AWS, Kubernetes, SQL * OSS & Supply Chain: JFrog Artifactory/Xray, Sonatype Nexus/Lifecycle * Reporting & Monitoring: Amazon QuickSight, Prometheus Qualifications * Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- * Knowledge of OWASP, NIST, and secure SDLC practices.
- * Strong communication and cross-functional collaboration skills.
- * Security certifications (CISSP, CSSLP, etc.) are a plus.
- Primary qualification : Python, AWS + Kubernetes + SQL + Security certifications (CISSP, CSSLP, etc.) are a plus Qualifications #LI-MS2
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Security Engineer
Brightspot · Reston, Virginia, United States
Application & AI Security Engineer
MissionSquare · District of Columbia, United States
Cloud Security Engineer
Morgan & Morgan, P.A. · Tampa, Florida, United States
Senior Security Engineer
Credit Sesame · Mountain View, California, United States
Cybersecurity Assessment Data Analyst
CACI International Inc · United States
Security Engineer - Directory Services
Truist · Atlanta, Georgia, United States
Role information can change. Confirm current details on the original application page.