Application Security Engineer- REMOTE (PST)
Security assessment and remediation
o Review current vulnerability results and triage based on severity and potential impact. This will allow us to prioritize and make the team s work more efficient.
o Put together a remediation plan that includes the current team approach.
o Define security assessment for remediation advance review points.
Implementing security best practices
o Work with upper management to define application security posture.
o Define security coding practices and standards based on OWASP Secure Coding Guidelines.
o Include the review of security flaws during manual code reviews.
o Define a threat modeling framework to identify threats and vulnerabilities from design.
o Define a standard remediation plan when vulnerability arises.
o Implement penetration testing.
Automating security process
o Include guardrails in the SDLC, like SAST and DAST tools, within the automatic CI/CD pipelines (as proposed by the team).
Training and awareness:
o Define training and workshops to teach about secure coding.
o Generate internal documentation.
Security assessment and remediation
o Review current vulnerability results and triage based on severity and potential impact. This will allow us to prioritize and make the team s work more efficient.
o Put together a remediation plan that includes the current team approach.
o Define security assessment for remediation advance review points.
Implementing security best practices
o Work with upper management to define application security posture.
o Define security coding practices and standards based on OWASP Secure Coding Guidelines.
o Include the review of security flaws during manual code reviews.
o Define a threat modeling framework to identify threats and vulnerabilities from design.
o Define a standard remediation plan when vulnerability arises.
o Implement penetration testing.
Automating security process
o Include guardrails in the SDLC, like SAST and DAST tools, within the automatic CI/CD pipelines (as proposed by the team).
Training and awareness:
o Define training and workshops to teach about secure coding.
o Generate internal documentation.