Application Security Engineer
Magnum Hunt
United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English
Job source
Tech stack
ASP.NET
Java (Programming Language)
Microsoft Windows
Application Programming Interfaces (APIs)
Agile Methodology
Ajax (Programming Language)
Big Data
C Sharp (Programming Language)
C++ (Programming Language)
Cloud Computing
Code Review
Encodings
+27 more
Databases
Cross-Site Request Forgery
Software Debugging
Linux
Perl (Programming Language)
Fiddler (Software)
JSON
Python (Programming Language)
Microsoft Office
Microsoft SQL Server
Model View Controller (MVC)
Object-Oriented Software Development
Systems Development Life Cycle
Reverse Engineering
Secure Coding
Web Application Security
Service-Oriented Architecture
Software Engineering
SQL Injection
Web Applications
Web Testing
Extensible Markup Language (XML)
Scripting
Transport Layer Security
Software Security
Cross-Site Scripting (XSS)
Mitmproxy
Job description
- Identify risks and areas of exposure in applications developed and/or used by BlackLine.
- Perform security reviews of source code, stored procedures, and server/service configurations.
- Define and document application security requirements for BlackLine applications.
- Oversee development of security components throughout all stages of the SDLC.
- Perform manual and automated security testing of BlackLine applications.
- Monitor application logs and audit trails.
- Monitor industry trends and threat landscape and recommend necessary controls or countermeasures.
- Educate developers on secure coding techniques and security best practices.
- Participate in development of security policies, standards, and processes.
- Participate in incident handling and perform application-related forensics activities.
- Perform other duties as assigned
Requirements
- 5+ years of hands-on application security experience.
- Hands-on development experience and thorough understanding of object-oriented programming, preferably Java, C#, ASP.NET
- Advanced knowledge of web application technologies, MVC, Ajax, XML, JSON, SOA, SSL, web-related protocols and services.
- Intermediate knowledge of MS SQL. Basic knowledge of other commonly-used DBMS.
- Experience with cloud and “big data” storage, databases, and APIs
- Ability to identify security vulnerabilities from source code reviews and testing.
- Knowledge of encryption technologies, secure communications, and secure credentials management.
- Advanced experience with at least one scripting language (e.g.: Perl, Python)
- Intermediate proficiency with C/C++ or Java. Experience with lower-level languages (Assembly), debug and reverse-engineering tools (IDA, etc.) is a plus.
- Advanced knowledge of common application vulnerabilities, (e.g.: XSS, CSRF, SQL injection, cookie/header/encoding manipulation, input/output validation, session replay).
- Intimate familiarity with web application testing tools (eg: Burp, Parox, Fiddler, mitmproxy, Havij, netcat). Ability to write proof-of-concept exploits is a big plus.
- Ability to define application security requirements and build secure web application solutions.
- Advanced written and verbal communication skills including ability to present technical subjects to non-technical audiences.
- Strong work ethic, attention to detail, and organizational skills.
- Ability to multi-task and manage priorities in a fast-paced environment.
- Ability to collaborate in a team and work independently.
- Conceptual understanding of software development principles and SDLC models, Agile experience is a plus.
- Intermediate proficiency with the Microsoft Office suite.
- Windows and Linux operating systems knowledge at advanced user level.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on magnumhunt.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
AF
Ava Faulkner
7 Important Tips That Every Software Developer Should Know
about 4 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago