Senior Application Security Engineer in Washington

Energy Jobline
Washington, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Washington, United States of America

Tech stack

Java
Amazon Web Services (AWS)
Software System Penetration Testing
Azure
C Sharp (Programming Language)
Network Analysis
Computer Security
Computer Programming
Continuous Integration
Digital Forensics
Information Security Management
Python
Open Web Application Security
Systems Development Life Cycle
Secure Coding
Software Engineering
Software Vulnerability Management
Cloud Platform System
Software Security
Malware
SC Clearance
Information Technology
Cyber Warfare
Devsecops
Static Application Security Testing
Vulnerability Analysis
Dynamic Application Security Testing

Job description

· Support development teams with secure code (DAST, SAST, Dependency, Secret Detection, Container scans, etc.) reviews and other assessments to identify security weaknesses and vulnerabilities

· Establish and maintain secure coding standards and best practices to provide guidance and training to development teams on security best practices

· Recommend cyber defense and vulnerability assessment tools

· Review and research monthly continuous monitoring controls documentation tasks that is required by OIS

· Continuous Process Improvement, actively contribute to the development of standardized operating procedures (SOPs) for API security testing

· Collaborate closely with cross-functional teams, including system administrators and Information System Security Officers (ISSOs)

Security Clearance Requirement:

· Active Public Trust and eligible to obtain a Secret clearance

Requirements

  • Strong written and verbal communication skills

· Must have GitLab CI/CD pipeline experience

· Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching framework and methodologies

· Assist customers with implementing a secure CI/CD pipeline utilizing DevSecOps principles and practices to increase automation and reduce human involvement in the process

· Reviewing source code for potential security vulnerabilities

· Strong analytical skills to assess risks and vulnerabilities in complex systems

· Writing security test cases to check for vulnerabilities or broken/missing security controls.

· Implement automated security controls as part of CI/CD pipelines, * At least Ten (10) years of experience working in cybersecurity or information technology with a bachelor's degree. Minimum of 5 years' experience in vulnerability management, application and software security team, Malware analysis, digital forensics, data/network analysis, penetration testing, information assurance, leading incident handling

  • Solid experience in application security and software development in one or more programming such as C#, Java, Python, etc
  • Experience with security tools such as SAST, DAST, IAST, SCA and other security tools

· Familiarity with industry-standard security frameworks such as OWASP, NIST, BSIMM etc

· Experience with CICD pipeline, security tools integration and secure SDLC

  • Knowledge of current and emerging threats and techniques for exploiting security vulnerabilities
  • CISSP, OSCP, any DevSecOps or other related Information Security certification
  • Experience with cloud-based infrastructure (AWS, Azure, or GCP)

About the company

Energy Jobline is the largest and fastest growing global Energy Job Board and Energy Hub. We have an audience reach of over 7 million energy professionals, 400,000+ monthly advertised global energy and engineering jobs, and work with the leading energy companies worldwide. We focus on the Oil & Gas, Renewables, Engineering, Power, and Nuclear markets as well as emerging technologies in EV, Battery, and Fusion. We are committed to ensuring that we offer the most exciting career opportunities from around the world for our jobseekers., Company DescriptionGSC is a leading cyber security and information technology company based in Washington, DC. We are looking to hire a Senior Security Application Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background and security clearance.Company DescriptionGSC is a leading cyber security and information technology company based in Washington, DC. We are looking to hire a Senior Security Application Engineer to support a full range of cyber security services on a long-term contract in Washington DC. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background and security

Apply for this position