Responsibilities
- Work with engineers to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC)
- Analyze output of application security scanners, such as SAST and SCA, to proactively discover risks and identify security vulnerabilities
- Validate and investigate applicability of identified vulnerabilities and provide risk analysis as needed
- Configure and fine-tune security scanners to ensure scanner output is applicable to the application s context
- Collaborate with developers and report vulnerabilities to application owners, supervising issues from report to resolution
- Engage with other application security engineers to align tasks with development timelines, completing tasks according to application release timing
Qualifications
- 5+ years of experience working within software development
- Bachelor s degree in Computer Science, Information Security, Cyber Security, or equivalent experience (> 7 years)
- Excellent written and oral communication skills, as well as social skills including the ability to articulate to both technical and non-technical audiences
- High level of personal integrity, with the ability to professionally handle confidential matters, and reflect appropriate level of judgment as it pertains to security
- Able to work both independently and with development teams, and multi-task effectively
- Firm understanding of enterprise class application architectures that are highly scalable and reliable, and the expertise to secure them
- Experience with security architecture and feature design reviews
- Experience with multiple languages such as Java, Go, Python and Perl etc, and understand how to detect and remedy related security issues such as OWASP top 10