Responsibilities
Essential Functions / Responsibilities
- Configure and fine tune Application Security tests and vulnerability scans .
- Partner with Development teams to integrate security testing into their CI / CD pipelines and development processes.
- Partner with Senior Application Security engineers on Penetration tests set up and validation
- Ensure the processes and procedures of the area are documented and updated
- Do research and regularly consult with colleagues
- Deliver secure software development training ( e.g. OWASP Top10)
- Co-work with Security Analysts and other colleagues on software vulnerabilities and security issues : determine scope, severity and potential impact, recommend next steps, follow through with risk treatment and mitigation.
- Escalate issues, appropriately, to various teams and levels of authority inside the organization .
Minimum Qualifications
Bachelor s degree in a relevant business or technical discipline is required .3 + years of relevant work experienceDemonstrated knowledge of application security concepts, best practices and methodsExperience with various application security tools including SAST, SCA, DASTExperience with Web Application security testing like Web Pentesting , Fuzzing, Automated testEven Better If You Have
Experience securing cloud infrastructure and cloud applications .Working knowledge of web, mobile, API, Microservices, network and security architectures and design patterns.Demonstrated ability to code in at least one programming language (python, javascript , typescript, go)Working knowledge of AWS native security tools.Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities.Experience with methodologies and tools, for threat analysis of systems, such as threat modelling and software fuzzing.Experience with developer tools and environments, project management and bug tracking systems.Experience in implementing and integrating security tools into CI / CD.EEO CommitmentEEO Commitment#LI-NB1Skills Required
Static Analysis, dynamic testing , Vulnerability Assessment, threat modeling , secure coding , Penetration Testing, Web Security, Network Security, Risk Management, Incident Response