Security Engineer/Tester
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
As a Security Engineer/Tester, you will perform authorized security testing on complex, massive scale, and highly critical applications. This role involves working within the development team to proactively identify security vulnerabilities (OWASP Top 10, SANS Top 25, CWE) early in the development cycle. You will act as a liaison between the InfoSec and development teams, helping to understand and remediate security issues.
Responsibilities:
- Perform authorized security testing on complex and highly critical applications
- Work in a team-oriented and fast-paced environment
- Maintain awareness of varied application security domains like authentication, authorization, identity management, and cryptography
- Present findings to Leadership, Management, and Development teams to help them understand risks and make informed decisions on mitigations and controls
Requirements
- 3+ years of experience in software development/testing with large-scale enterprise applications
- Primary skill in manual and automated software testing
- Deep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), and browser technologies
- In-depth domain understanding of application security in terms of Identity and Access Management (IAM) and different authentication technologies
- Proven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools)
- Deep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, and attack patterns (CAPEC)
- Bachelor’s Degree in Computer Science or equivalent experience
- Must be self-directed, able to work independently, as well as work in a team-oriented and fast-paced environment
Desired skills:
- Working experience on different security technologies and standards like Single Sign On (SSO) using SAML/OpenID, OAuth protocols, etc
- Good understanding of Cryptographic algorithms and standards like Symmetric/Asymmetric crypto techniques, digital signatures, JWS/JWE tokens, Hardware Security Modules (HSMs), etc
- Understanding of security vulnerabilities related to Cloud environments is an added advantage
- Well-known security certifications is an added advantage
- Understanding of Threat Modeling concepts and Secure Development Life Cycle processes
- Mobile Application Security familiarity is desirable
About the company
Genesis10 is currently seeking a Security Engineer / Tester - Hybrid for a contract to hire position with a Global Financial Institution located in Seattle, WA or Addison, TX., Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals.
For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10:
- Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years.
- The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years.
- Access to an experienced, caring recruiting team (more than 7 years of experience, on average.)
- Behavioral Health Platform
- Medical, Dental, Vision
- Health Savings Account
- Voluntary Hospital Indemnity (Critical Illness & Accident), For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?