Achieving our goals starts with supporting yours. Grow your career, access top-tier health and wellness benefits, build lasting connections with your team and our customers, and travel the world using our extensive route network.
Come join us to create what’s next. Let’s define tomorrow, together.
DescriptionWe’re on a path to becoming the best airline in aviation history. Join our Cybersecurity and Digital Risk (CDR) team to help lead the industry in cyber safety, security and resilience. United's CDR team plays a critical role in protecting our operations by enabling secure and resilient systems, managing threats and vulnerabilities, and ensuring swift response and recovery. Our mission is to seamlessly embed cybersecurity and digital risk management into every aspect of our business. We help drive progress and growth through trusted digital solutions, safeguarding assets and empowering our team, all while promoting a cyber-safe and secure environment that supports resilient airline operations.
Job overview and responsibilities
The Engineer- Application Cybersecurity helps validate that our services, applications, and websites are designed and implemented in accordance with United’s secure development standards. The engineer works closely with development teams, product teams, and other teams across the organization to integrate security into the product lifecycle from design through deployment.
The engineer will support the enforcement of security requirements, perform application security assessments, and provide developers with remediation guidance and advice.
Perform code analysis of applications, manually and using application security testing solutions including mobile application security tests as well as conducting manual vulnerability analysis, and assisting product teams with vulnerability remediationImprove the accessibility of security through automation, continuous integration pipelines, and other means including but not limited to developing and maintaining CI/CD templatesResearch, define and communicate security best practices and standards and ensure products development teams understand themSupport security architecture design reviews and threat modelling of our products
QualificationsWhat’s needed to succeed (Minimum Qualifications):
Bachelor's degreeMinimum of 3 years of experience in a relevant fieldWorking knowledge of OWASP Top 10, CWE 25Working knowledge with application testing (i.e., SAST, DAST, SCA, etc.)Working knowledge of programming languages and scripting (Python preferred)Basic understanding of SDLC processBasic understanding of web and app security stack (e.g., API security)Ability to own projects and learn architecture over timeAbility to work independently and self-motivateExcellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skillsMust be legally authorized to work in the United States for any employer without sponsorshipSuccessful completion of interview required to meet job qualificationReliable, punctual attendance is an essential function of the position
What will help you propel from the pack (Preferred Qualifications):
AWS Certified Solutions Architect – AssociateCertified Application Security EngineerBasic understanding of DevSecOps (e.g., CI/CD)Data analysis capabilityExperience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security, cloud computingExperience with AWS technologiesWorking knowledge of C#, Java, Python, Swift, and JavaScriptBasic understanding of threat modelingBasic understanding of cloud technologies and securityBasic understanding of vulnerability management processes and proficiency in providing remediation guidanceBasic understanding of compliance frameworks (e.g., NIST 800-53) and processesWorking knowledge with technical documentation / Standard Operating Procedures (SOPs) creationBasic understanding of cryptographyBasic technical understanding of authentication and authorization flows in web applicationsBasic understanding of networks and network security (i.e., WAF, Micro-segmentation)
The base pay range for this role is $89,965.00 to $117,212.00.
The base salary range/hourly rate listed is dependent on job-related, factors such as experience, education, and skills. This position is also eligible for bonus and/or long-term incentive compensation awards.
You may be eligible for the following competitive benefits: medical, dental, vision, life, accident & disability, parental leave, employee assistance program, commuter, paid holidays, paid time off, 401(k) and flight privileges.
United Airlines is an equal opportunity employer. United Airlines recruits, employs, trains, compensates and promotes regardless of race, religion, color, national origin, gender identity, sexual orientation, physical ability, age, veteran status and other protected status as required by applicable law. Equal Opportunity Employer - Minorities/Women/Veterans/Disabled/LGBT.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform crucial job functions. Please contact JobAccommodations@united.com to request accommodation.