Application Security Engineer
US Tech Solutions, Inc.
Arlington, VA, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Java (Programming Language)
JavaScript (Programming Language)
Burp Suite
Code Review
Cyber Security
Continuous Delivery
Continuous Integration
DevOps
Gradle
Mobile Application Software
Apache Maven
Objective-C (Programming Language)
+26 more
Open Source Technology
Open Web Application Security
Systems Development Life Cycle
Cloud Services
Fortify (Software)
Secure Coding
Web Application Security
Security Software
Software Engineering
Scripting
ReactJS
Sonatype
Software Security
Swift (Programming Language)
Veracode
Kotlin
Kubernetes
Tenable Nessus
Checkmarx
Puppet
Devsecops
Docker
Jenkins
Static Application Security Testing
Vulnerability Analysis
Dynamic Application Security Testing
Job description
- Collaborate with a team of engineers to implement *** specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications.
- Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevOps processes.
- Define the security rules that needs to be adhered to at a code level in web and mobile applications written in Java, React, Objective C, SWIFT, Kotlin etc.
- With your development background and security knowledge, provide security guidance to developers in the form secure coding standards and guidelines.
- Support security standards, create templates and patterns to increase the efficiency and adoption of security program.
Requirements
- Bachelor’s degree with minimum 8 years of work experience in the IT field
- 3+ years software development experience using Java, JavaScript
- 3+ years of experience in the following:
- OWASP Secure Coding Practices
- Common software and web application security vulnerabilities
- Application security scanning tools
- Continuous Integration/Continuous Deployment (CI/CD) processes and concepts using relevant technologies and tools (e.g., Jenkins)
- Experience in Python scripting
Even Better If You Have
- A degree in Cybersecurity or CISSP/CSSLP certification or keen desire to move to security field
- Business acumen to support the implementation of SAST or DAST or IAST across the enterprise
- Ability to perform code reviews with minimal assistance
- A self-starter, with a strong desire for learning new technologies and applying them to solve problems
- Experience with two or more of the application build environments like Jenkins, Gradle, Maven.
- Familiarity with public cloud services a plus
- Experience with two or more of the Secure SDLC tools like Burp Suite, Fortify, Checkmarx, AppSec SE, Veracode, WhiteSource, Sonatype
- Experience with Threat Analysis.
- Experience with DevSecOps, Secure SDLC.
- DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc) is a plus
- Experience with evaluation, integration and onboard of security tools such as RASP, WAF, vulnerability scanner results, container analyzers, open source scanning etc is a plus
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dejobs.orgGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
AF
Ava Faulkner
7 Important Tips That Every Software Developer Should Know
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
KD
Krissy Davis
Best Countries for Software Engineers
about 3 years ago