A bachelor's degree and 5 years experience in a development or software security / penetration testing roleIdentify web application security vulnerabilities (e.g., OWASP Top 10) and offer resolution adviceIntegrate security touch points into existing SDLC processesConduct risk assessments, threat modeling and information security reviews on Morningstar systems, applications and platformsWork directly with internal business units to communicate risk and help resolve open vulnerabilitiesUnderstand and help execute information security program goalsAssist in maintaining and updating information security policies and standardsProvide security remediation advice and training to technical personnel and security championsDevelop and enhance internal security processes, programs and proceduresDocument secure coding guidelines and run training programs to assist internal development personnelCollect application vulnerability metrics and introduce automated security checks into application build processWe're looking for someone who enjoys breaking code, solving puzzles, and diagnosing problemsExcellent communication skills and a strong understanding of software development and application security fundamentalsCandidates should be interested in keeping up with the latest security trends, as well as enjoy performing code / architecture reviews and penetration test activitiesExperience with common static and dynamic analysis tools (Fortify, Web Inspect, AppScan, Burp, etc.)A strong understanding of security best practices in Java, JavaScript, .NET, PHP and Ruby programming languageSkills Required
Java, secure coding , Application Security, Owasp, Penetration Testing