Tech Stack
Cyber SecurityJavaLinuxPythonSQL
About the role
- Ensure security is injected into the software development lifecycle and products are secure.
- Implement, enforce, and validate secure coding practices across development teams.
- Engage directly in application security reviews, threat modeling, and code review.
- Participate in penetration test engagements and dynamic testing.
- Own and facilitate application security vulnerability management.
- Advise and support development teams on application security matters.
- Suggest and implement improvements to existing processes and tooling.
- Demonstrate application of information security, compliance, and assurance practices.
- Assess risk using a given risk assessment framework and stay up to date on evolving threats.
- Organize and coordinate projects or resolution of security issues; lead solutions to completion.
- Assist in definition, documentation, and evolution of best practices for the application security program.
Requirements
- Prior experience working in Application Security.
- Understanding of vulnerability analysis, penetration testing, encryption technologies, intrusion detection, incident response.
- Proven hands-on experience with security tools such as Burp Suite, OWASP ZAP, and Kali Linux.
- Working knowledge of the OWASP Top 10 and how to apply the standard to minimize security risk.
- Understanding of security best practices and how to implement them at an enterprise level.
- Basic coding skills – SQL, Python, other scripting languages.
- Knowledge of secure coding principles and experience with code review processes.
- Understanding of common Information Security concepts, practices, and procedures.
- Strong written and oral communication skills and the ability to prioritize work.
- Strong aptitude for problem solving, math, and communication.
- Strong organizational and interpersonal skill.
- Desired: Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related area of study.
- Desired: Five years of information security experience.
- Desired: Experience in at least one programming language.
- Desired: Proficiency with SQL, Python, and/or Java.
- Desired: Industry certifications in cyber security incident management (e.g., SANS GIAC, CEH, CompTIA Security+).
- Desired: Application Development experience.