Key Responsibilities :
- Identify web application security vulnerabilities (e.g., OWASP Top 10) and offer resolution advice
- Integrate security touch points into existing SDLC processes
- Conduct risk assessments, threat modeling, and information security reviews on Morningstar systems, applications, and platforms
- Work directly with internal business units to communicate risk and help resolve open vulnerabilities
- Understand and help execute information security program goals
- Assist in maintaining and updating information security policies and standards
- Provide security remediation advice and training to technical personnel and security champions
- Develop and enhance internal security processes, programs, and procedures
- Document secure coding guidelines and run training programs to assist internal development personnel
- Collect application vulnerability metrics and introduce automated security checks into the application build process
Ideal Candidate Profile :
Enjoys breaking code, solving puzzles, and diagnosing problemsExcellent communication skillsStrong understanding of software development and application security fundamentalsInterested in keeping up with the latest security trendsEnjoys performing code / architecture reviews and penetration test activitiesPreferred Skills & Tools :
Experience with common static and dynamic analysis tools (e.g., Fortify, Web Inspect, AppScan, Burp, etc.)Strong understanding of security best practices in the following programming languages :JavaJavaScript.NETPHPRubySkills Required
Application Security, Web Application Security, Owasp Top 10, Risk Assessment, threat modeling