Make an impact by working for sectors where technology is the enabler everything is groundbreaking and theres a constant need to be innovative.
Be part of the team that combines business knowledge technological edge and a design experience. Our different backgrounds and knowhow are key in developing solutions and experiences for digital clients.
Face challenges and learn other ways of thinking and seeing the world theres always room for your energy and creativity.
About the role
Celfocus is looking to add an Application Security Analyst to join our team.
As a part of your job you will:
- Conducting analysis and threat modeling for new and existing Celfocus products/projects.
- Analyzing and discussing requirements; interacting with all participants in the software development process.
- Penetration testing web applications.
- Conducting both manual and automated testing.
- Participating in the creation and development of the companys products at all stages of their life cycle.
What are we looking for
- Previous experience as a DevSecOps Security Analyst
- Profound security assurance tool knowledge
- Profound CI/CD knowledge
- Profound vulnerability knowledge
- Basic understanding of security compliance requirements
- Capability to align with teams from Analysts Designers Architects Developers to DevOps.
- Knowledge of HTTP.
- Working knowledge of programming languages
- Knowledge of the Top 10 OWASP vulnerabilities: how to find exploit and fix them.
- Knowledge of Burp Suite or other popular web scanners like ZAP Acunetix Netsparker etc.
- The desire and ability to work in a team.
- The desire to develop yourself in the field of application security.
- A lively and flexible mind clear logic a detailoriented approach
- Knowledge of English at least at the level of reading technical documentation.
Nice to have:
- Good knowledge of Linux or Windows operating systems.
- Skills in scripting and automating your work using Powershell Python Bash etc.
- Knowledge of the OWASP Application Security Verification Standard (ASVS) OWASP Testing Guide and experience in whole product or feature planning.
- An understanding of browser security mechanisms (SOP cookies CSP HSTS etc.
- Familiarity with various protocols and attacks against them (OAuth JWT websockets etc.
- Experience with public clouds (Azure AWS GCP)
- Experience with pipeline Orchestrators (Jenkins Azure DevOps GitLab CI/CD)
- Penetration testing experience
Personal traits:
Ability to adapt to different contexts teams and Clients
Teamwork skills but also sense of autonomy
Motivation for international projects and ok if travel is included
Willingness to collaborate with other players
Strong communication skills
Believe this is you Come join the Team! At Celfocus we are committed to cultivate a diverse and inclusive workplace. As an equalopportunity employer we welcome applicants of all backgrounds gender identities and abilities. We are dedicated to providing reasonable accommodations for candidates with specific needs. If you require any adjustments during the selection process please inform our Talent Acquisition Team.
Come join the Team!