> Markdown version of [/jobs/ext/2717396-it-security-auditor](https://www.wearedevelopers.com/jobs/ext/2717396-it-security-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Auditor - **Company:** HCL GLOBAL - **Location:** United States - **Contract:** Permanent contract - **Skills:** Advanced Linux Sound Architecture, Cloud Computing, Cyber Security, Cross-Site Request Forgery, Cryptographic Protocols, Open Web Application Security, Secure Coding, Software Engineering, Extensible Markup Language (XML), Software Security, Tenable Nessus, Restful APIs, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/db9a13a0-11f4-4044-99c3-bee4f7f94912 ## About the Role This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices. Candidates must have a strong development background., * Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud) * Knowledge of HTTP Request/Response headers for web and Restful API calls * Ability to explain in detail any of the OWASP top 10 vulnerabilities * Familiarity with Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc. Preferred Skills: * Experience in a Security Operations Center * Industry certifications such as CISSP, CISA, or CEH * Knowledge of network security protocols and technologies * Strong communication and collaboration skills ## Description * Work closely with software development teams to ensure secure coding practices * Utilize Application Security scanning tools such as SAST, DAST, SCA, ASOC, Container/Cloud * Analyze HTTP Request/Response headers for web and Restful API calls * Explain in detail any of the OWASP top 10 vulnerabilities * Identify and address Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security)