Skip to content

ComputerWork: Jobs for Technical People

 

Tempe Arizona - 90-120k Full Time Posted: Wednesday, 18 September 2019
 
 
Applicants must be eligible to work in the specified location

Application Security Engineer

The Application Security Engineer will be responsible for integrating security into the development of applications. The Application Security Engineer will work closely with the product and software development team to threat model, vulnerability scan, and pen test the early software, system, and network architecture and identify required control points in the application stack. The Application Security Engineer will also work closely with developers to diagnose, document, and remediate application security vulnerabilities. The Application Security Engineer will also be responsible for evaluating, recommending, and implementing application security related software in an automated continuous integration/deployment environment.

Responsibilities

  • Continuously evaluate the organization's existing application security practices, define and measure security-related activities, and demonstrating concrete improvements to the application assurance program within the organization.
  • Provide secure application development training to developers and provide guidance on the development of web-based training for ongoing awareness.
  • Conduct code reviews and penetration testing.
  • Develop and maintain unit and integration tests designed to ensure security controls are tested on every build.
  • Work closely with application development and platform teams to help formulate and implement a strategy for software security that is tailored to the specific risks facing the organization, including threat modelling and applications security advisement services.
  • Develop and maintain a balanced application security program based on a well-defined application security framework.
  • Conduct application security assessments/penetration tests and implement tools for dynamic/automated code reviews.
  • Ensure application design and implementation best-practice with role-based and appropriate access standards, as well as integration with Identity and Access Management environments.
  • Ensure compliance with society, regulatory, and industry standards for application security.

Qualifications

  • College degree in a technical field or equivalent work experience.
  • Understanding and Passion for Agile/XP/Scrum/Kanban
  • Understanding of Test Driven Development built on User Stories
  • Understanding of Continuous Integration/Testing/Delivery
  • Familiarity with Metasploit, Burp Suite, Fuzzing, Gaunlt, and Jenkins is preferred
  • 3+ years' experience in a software development field such as Software Developer, Architect, Software Quality Assurance, or Application Security Engineer
  • Highly proficient in at least one of the following development languages: Java, .NET, Node.js, or Python
  • Possess a strong understanding of application architectural patterns, such as MVC, Microservices, Event-driven etc.
  • Possess strong business acumen with ability to work with application development, QA and security teams
  • Knowledge of the OWASP Top 10
  • Strong self-starter who has the ability to operate independently
  • Has solid understanding and experience with establishing software development policies across an organization
  • Familiarity with code reviews and penetration testing preferred
  • OSCP, OSCE, or OSWE Certifications are a major plus

If this is an opportunity that you're interested in please email your resume to:

(see below)


Tempe Arizona, United States of America
IT
90-120k
Request Technology - Kyle Honn
Kyle Honn
JSSB
9/18/2019 9:33:12 AM

We strongly recommend that you should never provide your bank account details to an advertiser during the job application process. Should you receive a request of this nature please contact support giving the advertiser's name and job reference.