Work with engineers to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC)
Analyze output of application security scanners, such as SAST and SCA, to proactively Client risks and identify security vulnerabilities
Validate and investigate applicability of identified vulnerabilities and provide risk analysis as needed
Configure and fine-tune security scanners to ensure scanner output is applicable to the application's context
Collaborate with developers and report vulnerabilities to application owners, supervising issues from report to resolution
Engage with other application security engineers to align tasks with development timelines, completing tasks according to application release timing
Qualifications
2+ years of experience working within software development
Bachelor's degree in Computer Science, Information Security, Cyber Security or equivalent experience (> 7 years)
Excellent written and oral communication skills, as well as social skills including the ability to articulate to both technical and non-technical audiences
High level of personal integrity, with the ability to professionally handle confidential matters, and reflect appropriate level of judgment as it pertains to security
Able to work both independently and with development teams, and multi-task effectively
Firm understanding of enterprise class application architectures that are highly scalable and reliable, and the expertise to secure them
Experience with security architecture and feature design reviews
Experience with multiple languages such as Java, Go, Python and Perl etc, and understand how to detect and remedy related security issues such as OWASP top 10
Desired Experience
Excellent analytical, evaluative, and problem-solving abilities
Experience with securing host, database, and application solutions for multi-tier systems
Experience with penetration testing
Knowledge of automated attack tools and developing mitigation techniques
Ability to think like an attacker
Experience with AWS and Akamai technologies
Technical certifications within information security are a plus (GWAPT, OSCP or equivalents)