Salary
💰 $115,000 - $145,000 per year
Tech Stack
AWSCloudCyber SecuritySaltStackSDLCSpring
About the role
- Conduct security reviews and static code analysis to identify application vulnerabilities
- Integrate SAST, DAST, and SCA tools into CI/CD pipelines
- Collaborate with developers to remediate vulnerabilities and promote secure coding practices
- Generate and present risk-based security reports to engineering and management teams
- Maintain security tooling configurations and ensure up-to-date signatures and policies
- Support secure development and implementation of applications
Requirements
- Must have an active NOAA Public Trust clearance or active Secret security clearance
- US Citizenship Required
- 5+ years of experience in application security or a related field
- Identify, analyze, and mitigate application security vulnerabilities using tools like Checkmarx, Invicti, Black Duck, etc.
- Collaborate with development teams to integrate secure coding practices and prioritize vulnerability remediation throughout the SDLC
- Maintain container images supporting different automated CI/CD security scanning phases
- Hands-on experience with static and dynamic application security testing (SAST/DAST)
- Familiarity with tools such as Invicti, Checkmarx, Black Duck, and similar platforms
- Strong understanding of secure coding practices and application vulnerabilities (e.g., OWASP Top 10)
- Experience working within a Cloud Environment required (AWS experience preferred)
- Experience with CI/CD tools and pipelines, integrating security throughout the SDLC
- Ability to interpret and explain security findings to developers and provide remediation guidance
- Excellent communication skills and strong documentation ability
- Possess at least ONE (1) of the following professional certifications: CompTIA Security+; CEH; CISSP