Epicareer Might not Working Properly
Learn More

Source Code Review Assessor - SCA (Static code review)

Salary undisclosed

Checking job availability...

Original
Simplified

Primary Duties:
Deliver secure code review assessment on programming languages such as Java, C#, JavaScript & SQL
Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques
Train and assist developers in writing secure software and remediating existing vulnerabilities
Develop and review custom vulnerability description, business impact and remediation content
Develop, research and recommend open source tools assisting in secure code review
Contribute to development and delivery of secure coding and remediation training
Mentor and assist team members in effectively delivering assessments and enhancing skillsets
Recommend best practices to integrate and automate application security testing in SDLC

Basic Qualifications:
3+ years of experience in application security including secure code review, web application penetration testing or threat modelling
2+ years of experience in secure code review / static application security testing
Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code
Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience
Bachelor's Degree in Computer Science/ Engineering or equivalent with GPA of 3.0 or higher

Preferred Qualifications:
Experience in detecting, analyzing and providing recommendation guidance on security vulnerabilities in at least two of the following languages: Java, C#, JavaScript & SQL
Hands-on experience conducting security focused static analysis using commercial SAST tools such as Checkmarx
Experience in software development in at least one server-side programming language
Master's degree in Computer Science/ Engineering or equivalent

Expanded notes from the hiring team:
Need 2-3 years of experience at a high level - need to be experts
Need coding experience
Better to have development experience (Secure development is the best option)
Dynamic Analysis- needs to be able to speak to this.
Example: Candidates should be able to identify a SQL Injection within the code
Need to partner with MEH accessor to understand vulnerability, what are the remediations and how it happened.
Needs to be able to communicate with the Dynamic Assessor

--

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job

Primary Duties:
Deliver secure code review assessment on programming languages such as Java, C#, JavaScript & SQL
Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques
Train and assist developers in writing secure software and remediating existing vulnerabilities
Develop and review custom vulnerability description, business impact and remediation content
Develop, research and recommend open source tools assisting in secure code review
Contribute to development and delivery of secure coding and remediation training
Mentor and assist team members in effectively delivering assessments and enhancing skillsets
Recommend best practices to integrate and automate application security testing in SDLC

Basic Qualifications:
3+ years of experience in application security including secure code review, web application penetration testing or threat modelling
2+ years of experience in secure code review / static application security testing
Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code
Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience
Bachelor's Degree in Computer Science/ Engineering or equivalent with GPA of 3.0 or higher

Preferred Qualifications:
Experience in detecting, analyzing and providing recommendation guidance on security vulnerabilities in at least two of the following languages: Java, C#, JavaScript & SQL
Hands-on experience conducting security focused static analysis using commercial SAST tools such as Checkmarx
Experience in software development in at least one server-side programming language
Master's degree in Computer Science/ Engineering or equivalent

Expanded notes from the hiring team:
Need 2-3 years of experience at a high level - need to be experts
Need coding experience
Better to have development experience (Secure development is the best option)
Dynamic Analysis- needs to be able to speak to this.
Example: Candidates should be able to identify a SQL Injection within the code
Need to partner with MEH accessor to understand vulnerability, what are the remediations and how it happened.
Needs to be able to communicate with the Dynamic Assessor

--

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job