Security Engineer/Tester

Genesis10
Seattle, WA, United States
about 2 months ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$104,874.0 - $121,514.0
Working hours
Regular working hours
Job source

Tech stack

Static Program Analysis Cyber Security Digital Signature Fiddler (Software) Hardware Security Module Identity and Access Management Mobile Application Software OAuth OpenID Open Web Application Security Security Assertion Markup Language (SAML) Secure Coding
+7 more
Single Sign-On Software Engineering Web Applications Enterprise Software Applications Cloud Platform System Software Security Information Technology

Job description

As a Security Engineer/Tester, you will perform authorized security testing on complex, massive scale, and highly critical applications. This role involves working within the development team to proactively identify security vulnerabilities (OWASP Top 10, SANS Top 25, CWE) early in the development cycle. You will act as a liaison between the InfoSec and development teams, helping to understand and remediate security issues.

Responsibilities:

  • Perform authorized security testing on complex and highly critical applications
  • Work in a team-oriented and fast-paced environment
  • Maintain awareness of varied application security domains like authentication, authorization, identity management, and cryptography
  • Present findings to Leadership, Management, and Development teams to help them understand risks and make informed decisions on mitigations and controls

Requirements

  • 3+ years of experience in software development/testing with large-scale enterprise applications
  • Primary skill in manual and automated software testing
  • Deep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), and browser technologies
  • In-depth domain understanding of application security in terms of Identity and Access Management (IAM) and different authentication technologies
  • Proven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools)
  • Deep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, and attack patterns (CAPEC)
  • Bachelor’s Degree in Computer Science or equivalent experience
  • Must be self-directed, able to work independently, as well as work in a team-oriented and fast-paced environment

Desired skills:

  • Working experience on different security technologies and standards like Single Sign On (SSO) using SAML/OpenID, OAuth protocols, etc
  • Good understanding of Cryptographic algorithms and standards like Symmetric/Asymmetric crypto techniques, digital signatures, JWS/JWE tokens, Hardware Security Modules (HSMs), etc
  • Understanding of security vulnerabilities related to Cloud environments is an added advantage
  • Well-known security certifications is an added advantage
  • Understanding of Threat Modeling concepts and Secure Development Life Cycle processes
  • Mobile Application Security familiarity is desirable

About the company

Genesis10 is currently seeking a Security Engineer / Tester - Hybrid for a contract to hire position with a Global Financial Institution located in Seattle, WA or Addison, TX., Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals.

For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10:

  • Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years.
  • The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years.
  • Access to an experienced, caring recruiting team (more than 7 years of experience, on average.)
  • Behavioral Health Platform
  • Medical, Dental, Vision
  • Health Savings Account
  • Voluntary Hospital Indemnity (Critical Illness & Accident), For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all