Website:
7-elevengsc.com
Job details:
Role Description
Job Description:
Application security engineer will be executing automated application Security tools for security
weaknesses, performing vulnerability scans, managing security tools and providing security guidance to software development teams.
Responsibilities
- Execute automated SAST and SCA scans to identify security vulnerabilities in web, API, and mobile applications.
- Perform manual secure code reviews to validate findings and detect security issues not identified by automated tools.
- Analyze vulnerability scan results, prioritize risks, and provide remediation recommendations to development teams.
- Collaborate with developers to resolve security issues and promote secure coding best practices.
- Integrate application security testing into the Software Development Life Cycle (SDLC) to ensure security is embedded throughout development.
- Manage application security tools, perform re-validation of fixes, and support continuous improvement of the organization's application security posture.
Key Skills Required
- Expertise in automating secure coding tools and processes (SAST, SCA, DAST, Mobile & API Security).
- Review security test results from vulnerability scans, penetration testing for true positives and propose appropriate remediation measures or mitigation control.
- Experience with programming languages such as Java, Python, or Go, and at least one scripting language.
- Knowledge on WAF.
- Knowledge of web, mobile, API, Microservices and network pen testing.
- Knowledge of security best practices, principles, and common security frameworks, such as NIST and OWASP,
etc.
- Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities.
- Knowledge of AWS, Azure, Google cloud or Oracle is preferable.
- Knowledge on securing container platforms such as docker and Kubernetes.
- Ability to interact with a broad cross-section of personnel to explain and enforce security measures.
- Good written and verbal communication skills.
Education & Experience
- Bachelor's degree in Computer science, Information Technology, Cyber Security, or related discipline or equivalent experience.
- 4 to 6 years of Application Security experience with knowledge on security tools and vulnerabilities.
- Certifications:
- CSSLP
- GWAPT
- CEH
- CISSP
- CCSP
Click on Apply to know more.