Job Title: Application Security Architect & Engineer
Location: Richmond VA
Complete Description
ABOUT THE ROLE
Application Security Engineer (ASE) with 5 years of experience to join the Office of Technology under Joint Security this role the ASE serves as a dedicated security partner to application teams providing guidance on secure design vulnerability management and secure development practices. The ASE works collaboratively across the SDLC to ensure
security is embedded into application design development testing and
deployment. This includes supporting compliance requirements delivering
training and education and assisting teams with vulnerability remediation
efforts.
- The successful candidate will identify and
recommend improvements to improve the security of all Virginia Tax
applications promote secure coding and development practices and
contribute to ongoing initiatives that reduce risk and strengthen the
agencys overall security posture.
Responsibilities include but not limited to:
- Provide security guidance training and best practices for development and operations teams.
- Support secure software development by applying knowledge of SDLC Agile and Scrum methodologies.
- Evaluate software architecture and design for security risks and alignment with DevSecOps principles.
- Promote and enforce secure coding standards and guidelines.
- Review source code to identify vulnerabilities and recommend remediation strategies.
- Assess security risks across multiple programming languages (e.g. JavaScript C# Java Ruby SQL).
- Analyze and secure modern web application architectures including cloud APIs microservices and client-server models.
- Identify and address common vulnerabilities including those outlined in the OWASP Top 10.
- Support vulnerability remediation patch management and continuous improvement efforts.
- Utilize application security testing tools such as SAST DAST IAST and platforms like Accunetix Veracode Jenkins Splunk Rapid7 and Tenable.
- Interpret and act on findings from SIEM systems including Splunk.
- Apply knowledge of common security controls and frameworks.
- Ensure compliance with relevant security regulations and standards (e.g. NIST 80053 IRS Pub 1075 PCIDSS).
- Implement and evaluate AWS cloud security controls and best practices.
- Create maintain and review System Security Plans (SSPs).
- Troubleshoot and resolve complex technical and security-related issues.
- Stay current with evolving threats technologies and industry trends.
- Develop detailed plans and communicate risks impacts and recommendations effectively.
- Collaborate with application teams QA engineers and operations teams to integrate security into workflows.
- Provide constructive actionable feedback to application teams.
- Communicate technical concepts clearly to both technical and nontechnical audiences.
- Work closely with other security analysts and technology teams to support agency and enterprise security initiatives.
- Manage multiple tasks prioritize effectively and meet deadlines.
- Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.
- Required Skills/Experience:
- Five or more years experience in application security.
- Two or more years network or firewall/AWS Security Groups.
- Experience with log collection vulnerability scans and remediation or privileged access management.
- Strong understanding of security concepts network protocols and threat vectors.
- Proficiency in SIEMIDS/IPS EDRand other relevant security tools.
- Excellent analytical and problem-solving skills.
- Strong communication collaboration and documentation skills.
- Ability to work independently and as part of a team in a fast-paced environment.
Have experience and a strong knowledge of the following:
- Splunk Insigh tVM Rapid7 Tenable CyberArk Jenkins Veracode
- Linux and Windows Operating Systems Baseline hardening of operating systems
- IIS and Apache Scripting Languages and SQL PowerShell Firewall
At least one of these certs below is REQUIRED:
- CompTIA Security
- ISC2 CC(Certified in Cybersecurity)
- OffensiveSecurity Certified Professional (OSCP)
- CCSP(Certified Cloud Security Professional)
- CSSLP(Certified Secure Software Lifecycle Professional)
At least one of these certs below is highly DESIRED (Independently and or with one of the above)
- AWS Solutions Architect (Associate/Professional)
- AWSSecurity Specialty
At least one of the any is DESIRED
- CompTIA PenTest
- CertifiedEthical Hacker (CEH) GIAC Certified
Intrusion Analyst (GCIA
Required/Desired Skills
| Skill | Required/Desired | Amount | of Experience |
| Application Security | Required | 5.0 | Years |
| Network or Firewall/AWS security Groups | Required | 2.0 | Years |
| Infrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated provisioning. | Required | 2.0 | Years |
| Experience with log collection vulnerability scans and remediation or privileged access management | Required | 4.0 | Years |
| Proficiency in SIEM IDS/IPS EDR and other relevant security tools. | Required | 4.0 | Years |
| Networking & Hybrid Connectivity: Solid understanding of routing firewalls AWS Direct Connect and VPNs in a hybrid cloud environment. | Required | 4.0 | Years |
| One REQUIRED: CompTIA Security ISC2 CC (Certified in Cybersecurity) Offensive Security Certified Professional (OSCP) CCSP or CCLP. UPLOAD COPY!! | Required | | |
| CI/CD & DevOps: Experience with GitLab CI/CD Jenkins or AWS CodePipeline for automated secure deployments. | Highly desired | 5.0 | Years |
| Splunk InsightVM Rapid7 Tenable CyberArk Jenkins Veracode | Highly desired | 2.0 | Years |
| Linux and Windows Operating Systems Baseline hardening of operating systems | Highly desired | 2.0 | Years |
| IIS and Apache Scripting Languages and SQL PowerShell Firewall | Highly desired | 2.0 | Years |
| One highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security Specialty | Highly desired | | |
| One of these is DESIRED: CompTIA PenTest Certified Ethical Hacker (CEH) or GIAC Certified Intrusion Analyst (GCIA) | Highly desired | | |
Required Skills:
Application SecurityNetwork or Firewall/AWS security GroupsInfrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated with log collectionvulnerability scans and remediationor privileged access managementProficiency in SIEMIDS/IPSEDRand other relevant security & Hybrid Connectivity: Solid understanding of routingfirewallsAWS Direct Connectand VPNs in a hybrid cloud REQUIRED: CompTIA SecurityISC2 CC (Certified in Cybersecurity)Offensive Security Certified Professional (OSCP)CCSPor CCLP. UPLOAD COPY!!CI/CD & DevOps: Experience with GitLab CI/CDJenkinsor AWS CodePipeline for automatedsecure Rapid7TenableCyberArkJenkinsVeracodeLinux and Windows Operating SystemsBaseline hardening of operating systemsIIS and ApacheScripting Languages and SQLPowerShellFirewallOne highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security SpecialtyOne of these is DESIRED: CompTIA PenTestCertified Ethical Hacker (CEH)or GIAC Certified Intrusion Analyst (GCIA)
Job Title: Application Security Architect & Engineer Location: Richmond VA Complete DescriptionABOUT THE ROLEApplication Security Engineer (ASE) with 5 years of experience to join the Office of Technology under Joint Security this role the ASE serves as a dedicated security partner to application t...
Job Title: Application Security Architect & Engineer
Location: Richmond VA
Complete Description
ABOUT THE ROLE
Application Security Engineer (ASE) with 5 years of experience to join the Office of Technology under Joint Security this role the ASE serves as a dedicated security partner to application teams providing guidance on secure design vulnerability management and secure development practices. The ASE works collaboratively across the SDLC to ensure
security is embedded into application design development testing and
deployment. This includes supporting compliance requirements delivering
training and education and assisting teams with vulnerability remediation
efforts.
- The successful candidate will identify and
recommend improvements to improve the security of all Virginia Tax
applications promote secure coding and development practices and
contribute to ongoing initiatives that reduce risk and strengthen the
agencys overall security posture.
Responsibilities include but not limited to:
- Provide security guidance training and best practices for development and operations teams.
- Support secure software development by applying knowledge of SDLC Agile and Scrum methodologies.
- Evaluate software architecture and design for security risks and alignment with DevSecOps principles.
- Promote and enforce secure coding standards and guidelines.
- Review source code to identify vulnerabilities and recommend remediation strategies.
- Assess security risks across multiple programming languages (e.g. JavaScript C# Java Ruby SQL).
- Analyze and secure modern web application architectures including cloud APIs microservices and client-server models.
- Identify and address common vulnerabilities including those outlined in the OWASP Top 10.
- Support vulnerability remediation patch management and continuous improvement efforts.
- Utilize application security testing tools such as SAST DAST IAST and platforms like Accunetix Veracode Jenkins Splunk Rapid7 and Tenable.
- Interpret and act on findings from SIEM systems including Splunk.
- Apply knowledge of common security controls and frameworks.
- Ensure compliance with relevant security regulations and standards (e.g. NIST 80053 IRS Pub 1075 PCIDSS).
- Implement and evaluate AWS cloud security controls and best practices.
- Create maintain and review System Security Plans (SSPs).
- Troubleshoot and resolve complex technical and security-related issues.
- Stay current with evolving threats technologies and industry trends.
- Develop detailed plans and communicate risks impacts and recommendations effectively.
- Collaborate with application teams QA engineers and operations teams to integrate security into workflows.
- Provide constructive actionable feedback to application teams.
- Communicate technical concepts clearly to both technical and nontechnical audiences.
- Work closely with other security analysts and technology teams to support agency and enterprise security initiatives.
- Manage multiple tasks prioritize effectively and meet deadlines.
- Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.
- Required Skills/Experience:
- Five or more years experience in application security.
- Two or more years network or firewall/AWS Security Groups.
- Experience with log collection vulnerability scans and remediation or privileged access management.
- Strong understanding of security concepts network protocols and threat vectors.
- Proficiency in SIEMIDS/IPS EDRand other relevant security tools.
- Excellent analytical and problem-solving skills.
- Strong communication collaboration and documentation skills.
- Ability to work independently and as part of a team in a fast-paced environment.
Have experience and a strong knowledge of the following:
- Splunk Insigh tVM Rapid7 Tenable CyberArk Jenkins Veracode
- Linux and Windows Operating Systems Baseline hardening of operating systems
- IIS and Apache Scripting Languages and SQL PowerShell Firewall
At least one of these certs below is REQUIRED:
- CompTIA Security
- ISC2 CC(Certified in Cybersecurity)
- OffensiveSecurity Certified Professional (OSCP)
- CCSP(Certified Cloud Security Professional)
- CSSLP(Certified Secure Software Lifecycle Professional)
At least one of these certs below is highly DESIRED (Independently and or with one of the above)
- AWS Solutions Architect (Associate/Professional)
- AWSSecurity Specialty
At least one of the any is DESIRED
- CompTIA PenTest
- CertifiedEthical Hacker (CEH) GIAC Certified
Intrusion Analyst (GCIA
Required/Desired Skills
| Skill | Required/Desired | Amount | of Experience |
| Application Security | Required | 5.0 | Years |
| Network or Firewall/AWS security Groups | Required | 2.0 | Years |
| Infrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated provisioning. | Required | 2.0 | Years |
| Experience with log collection vulnerability scans and remediation or privileged access management | Required | 4.0 | Years |
| Proficiency in SIEM IDS/IPS EDR and other relevant security tools. | Required | 4.0 | Years |
| Networking & Hybrid Connectivity: Solid understanding of routing firewalls AWS Direct Connect and VPNs in a hybrid cloud environment. | Required | 4.0 | Years |
| One REQUIRED: CompTIA Security ISC2 CC (Certified in Cybersecurity) Offensive Security Certified Professional (OSCP) CCSP or CCLP. UPLOAD COPY!! | Required | | |
| CI/CD & DevOps: Experience with GitLab CI/CD Jenkins or AWS CodePipeline for automated secure deployments. | Highly desired | 5.0 | Years |
| Splunk InsightVM Rapid7 Tenable CyberArk Jenkins Veracode | Highly desired | 2.0 | Years |
| Linux and Windows Operating Systems Baseline hardening of operating systems | Highly desired | 2.0 | Years |
| IIS and Apache Scripting Languages and SQL PowerShell Firewall | Highly desired | 2.0 | Years |
| One highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security Specialty | Highly desired | | |
| One of these is DESIRED: CompTIA PenTest Certified Ethical Hacker (CEH) or GIAC Certified Intrusion Analyst (GCIA) | Highly desired | | |
Required Skills:
Application SecurityNetwork or Firewall/AWS security GroupsInfrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated with log collectionvulnerability scans and remediationor privileged access managementProficiency in SIEMIDS/IPSEDRand other relevant security & Hybrid Connectivity: Solid understanding of routingfirewallsAWS Direct Connectand VPNs in a hybrid cloud REQUIRED: CompTIA SecurityISC2 CC (Certified in Cybersecurity)Offensive Security Certified Professional (OSCP)CCSPor CCLP. UPLOAD COPY!!CI/CD & DevOps: Experience with GitLab CI/CDJenkinsor AWS CodePipeline for automatedsecure Rapid7TenableCyberArkJenkinsVeracodeLinux and Windows Operating SystemsBaseline hardening of operating systemsIIS and ApacheScripting Languages and SQLPowerShellFirewallOne highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security SpecialtyOne of these is DESIRED: CompTIA PenTestCertified Ethical Hacker (CEH)or GIAC Certified Intrusion Analyst (GCIA)
View more
View less