Epicareer Might not Working Properly
Learn More
F

Senior Source Code Auditor

Salary undisclosed

Apply on


Original
Simplified

Job Description

Job Description
Job Summary:
We are seeking five Senior Source Code Auditors to strengthen our cybersecurity team. In this critical role, you will be tasked with assessing and reviewing source code to identify vulnerabilities and ensure compliance with coding standards. Your work will play a pivotal role in improving the security and quality of our applications. The position involves close collaboration with software developers, security experts, and other stakeholders to provide actionable feedback and strategies to enhance secure coding practices.

Key Responsibilities:
  1. Conduct comprehensive reviews of source code to pinpoint vulnerabilities, security risks, and areas for improvement.
  2. Audit code written in various programming languages, including Python, Java, C++, JavaScript, Swift, and Kotlin.
  3. Develop and refine code auditing tools and standards to ensure consistency and quality.
  4. Partner with development teams to offer guidance on secure coding and vulnerability remediation.
  5. Produce detailed audit reports that present findings, risks, and suggestions for enhancing code security and quality.
  6. Stay informed on the latest security threats, standards, and practices to continuously refine auditing procedures.
  7. Provide mentorship to junior team members on code auditing methods and security best practices.
  8. Work alongside cross-functional teams to embed security practices into the software development lifecycle (SDLC).
  9. Assist with security training and awareness initiatives for the development team.
Qualifications:
  1. Bachelor s degree in computer science, Information Security, or related field, or equivalent professional experience.
  2. Minimum 5 years of experience in source code auditing, software development, or application security.
  3. Strong grasp of secure coding principles, software vulnerabilities, and attack methods such as SQL injection, XSS, and buffer overflows.
  4. Proficiency in multiple programming languages and development frameworks.
  5. Experience with automated code review tools like SonarQube, Checkmarx, or Veracode, alongside manual code auditing techniques.
  6. Excellent analytical skills and attention to detail.
  7. Strong communication abilities to convey complex technical concepts to non-technical team members.
  8. Relevant certifications (CEH, OSCP, CISSP) are an advantage.
Preferred Skills:
  1. Experience with cloud security and reviewing code for cloud-based applications (AWS, Azure, GCP).
  2. Knowledge of DevSecOps practices and integrating security into CI/CD pipelines.
  3. Familiarity with regulatory software security standards like ISO27001, GDPR, or HIPAA.
Benefits:
  1. Complimentary snacks and beverages
  2. Full coverage for medical, dental, and vision insurance (partial coverage for dependents)
  3. 401k contribution plan
  4. Four weeks of PTO annually
  5. Bi-annual salary reviews
  6. Wellness programs, including a free gym membership
  7. Regular team-building events


#STW1
#STW2
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job