Epicareer Might not Working Properly
Learn More
e

Application Security Engineer - Remote EST

Salary undisclosed

Apply on

Availability Status

This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.


Original
Simplified

Job Title: Application Security Engineer

Job Location: EST Remote (Client is based out in Newark, NJ)

Project Duration: C2H

Job Overview

The Application Security Analyst will partner with developers and other technical teams to conduct application security assessments. The individual will work closely with technical teams to analyze potential security impacts and pitfalls associated with threats and vulnerabilities to applications and systems. Candidate will advise developers and technical teams on options to mitigate the risk. The candidate must have excellent verbal, written and interpersonal communication skills.

Major Responsibilities

  1. Perform application code review and security testing (SAST/DAST/SCA).
  2. Provide root cause analysis, security summary analysis and recommendations to the developers on how to fix the identified vulnerabilities.
  3. Strong knowledge of script languages (Python, BASH, PowerShell, etc.) and build automation tools on an ad-hoc basis
  4. Lead projects related to security portfolio to strengthen the overall Cybersecurity posture
  5. Write and optimize custom rules on automated source code scanning tools
  6. Experience of building security into continuous integration and delivery (CI/CD) pipeline
  7. Review business requirements and provide risk based security recommendations during the initial phases of SDLC
  8. Work with security architects to perform architecture reviews and Threat Modeling and create assessment reports with recommendations to bridge the security gaps
  9. Design and assess SaaS and IaaS cloud services and virtualization technologies, e.g. Amazon Web Services (AWS) and VMWare
  10. Learn on the job and explore new technologies with little supervision to identify new and emerging security threats
  11. Create and deliver knowledge sharing presentations and documentation to security, developers and operations teams

Education/Experience:

  • Prefers BA/BS degree from an accredited college or university in Information Security, Computer Science, Information Management Systems, or in related field.
  • Requires a Bachelor's degree or 10 years of relevant experience in technology or engineering, in lieu of degree.
  • 5+ years of professional experience in Information Security or a Master's degree in Information Security, Computer Science, Information Management Systems, or in related field with 4 years of professional work experience in IT and/or Information Security that have significant work in or related to application security.
  • Prefers security certifications, such as: CISSP, SANS/GIAC Certifications, AWS Certifications.

Knowledge of:

  • Common vulnerabilities and defense against them in software, including web and mobile applications.
  • Common web application architectures such as three-tier, microservices, single-page app, etc.
  • Protocols/technologies such as SOA, HTTP, SSL, LDAP, JDBC, Servlet/JSP, SQL, HTML, XMLJava Application and Java Application Server administration/tuning
  • Amazon Web Services (AWS) and/or VMware vCloud, container and microservices and how to secure them

Skills and Abilities:

  • Requires strong verbal and written communication skills and business acumen
  • Must have experience creating reusable documentation
  • Ability to understand software design algorithms, secure code and security testing
  • Strong knowledge of one or more of the following programming languages: HTML5, Java, Python, Objective-C , C#, C++, SQL is preferred
  • Ability to write scripts in languages such as Python, BASH, PowerShell, etc., for automation preferred
  • Ability to read and debug code
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job