What you will be doing:
Identifying solutions for difficult security problems while participating in a broader agile Application
Security team.
Building comprehensive solutions to conduct consolidation aggregation and notification of security
findings to respective stakeholders.
Conduct threat modeling secure design reviews and provide direct guidance to development
teams.
Promoting designing and evaluating application security in all phases of the SDLC and constantly
looking for innovative ways to improve processes.
Influencing building and assisting with information security challenges within applications.
What we'll want you to have:
You are either a security-minded software engineer who has been building modern services using a
microservice architecture in an agile development environment or a development-interested security
practitioner who understands security best practices but wants to get closer to development and
engineering.
5 plus years of experience with application security and relevant testing tools for:
DAST: Burp Suite OWASP Zap Invicti AppScan
SAST/SCA: Fortify Checkmarx Coverity Semgrep OWASP Dependency
Check Mend Blackduck
Attack Surface Management: OWASP Amass Spiderfoot CyCognito
3 years of experience with Python Bash and/or PowerShell.
3 years of experience in DevSecOps integrating security solutions into CI-CD pipelines and
automated tooling orchestration.
Sensitivity:
Internal
Relevant certifications include CompTIA Security or CASP EC Council CEH ISC2
CSSLP are a plus.
Experience partnering with development and systems engineers on impactful
security initiatives.
Understanding of software development; how applications and systems are designed built
and break is critical.
Understand DevSecOps cultural mindsets and an engineering-focused approach to
solving complex security problems.
Strong verbal and written communication skills to translate security objectives and
requirements to specific engineering outcomes.
Ability to deliver work that meets all minimum standards of security quality and operability.
What you will be doing: Identifying solutions for difficult security problems while participating in a broader agile Application Security team. Building comprehensive solutions to conduct consolidation aggregation and notification of security findings to respective stakeholders. Conduc...
What you will be doing:
Identifying solutions for difficult security problems while participating in a broader agile Application
Security team.
Building comprehensive solutions to conduct consolidation aggregation and notification of security
findings to respective stakeholders.
Conduct threat modeling secure design reviews and provide direct guidance to development
teams.
Promoting designing and evaluating application security in all phases of the SDLC and constantly
looking for innovative ways to improve processes.
Influencing building and assisting with information security challenges within applications.
What we'll want you to have:
You are either a security-minded software engineer who has been building modern services using a
microservice architecture in an agile development environment or a development-interested security
practitioner who understands security best practices but wants to get closer to development and
engineering.
5 plus years of experience with application security and relevant testing tools for:
DAST: Burp Suite OWASP Zap Invicti AppScan
SAST/SCA: Fortify Checkmarx Coverity Semgrep OWASP Dependency
Check Mend Blackduck
Attack Surface Management: OWASP Amass Spiderfoot CyCognito
3 years of experience with Python Bash and/or PowerShell.
3 years of experience in DevSecOps integrating security solutions into CI-CD pipelines and
automated tooling orchestration.
Sensitivity:
Internal
Relevant certifications include CompTIA Security or CASP EC Council CEH ISC2
CSSLP are a plus.
Experience partnering with development and systems engineers on impactful
security initiatives.
Understanding of software development; how applications and systems are designed built
and break is critical.
Understand DevSecOps cultural mindsets and an engineering-focused approach to
solving complex security problems.
Strong verbal and written communication skills to translate security objectives and
requirements to specific engineering outcomes.
Ability to deliver work that meets all minimum standards of security quality and operability.
View more
View less