IT Security Auditor

HCL GLOBAL
United States
5 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Advanced Linux Sound Architecture Cloud Computing Cyber Security Cross-Site Request Forgery Cryptographic Protocols Open Web Application Security Secure Coding Software Engineering Extensible Markup Language (XML) Software Security Tenable Nessus Restful APIs
+2 more
Static Application Security Testing Dynamic Application Security Testing

Job description

  • Work closely with software development teams to ensure secure coding practices
  • Utilize Application Security scanning tools such as SAST, DAST, SCA, ASOC, Container/Cloud
  • Analyze HTTP Request/Response headers for web and Restful API calls
  • Explain in detail any of the OWASP top 10 vulnerabilities
  • Identify and address Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc.

Requirements

This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices. Candidates must have a strong development background., * Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud)

  • Knowledge of HTTP Request/Response headers for web and Restful API calls
  • Ability to explain in detail any of the OWASP top 10 vulnerabilities
  • Familiarity with Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc.

Preferred Skills:

  • Experience in a Security Operations Center
  • Industry certifications such as CISSP, CISA, or CEH
  • Knowledge of network security protocols and technologies
  • Strong communication and collaboration skills

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:59 min

The danger of adopting default REST APIs

Stefan Priebsch · World Congress 2021

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

Videos

See all

Related articles

See all