← Back to jobs

RulesIQ Logo
Cyber Command Application Security Vulnerability

RulesIQ

 

Brooklyn, NY, USA

Posted On: Just posted
Experience: 12+ years
Availability: Hybrid
Openings: 1
Category: Cyber Security Analyst
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

You will own the end-to-end lifecycle of application security testing and vulnerability management.

This role is on-site.

Responsibilities

  • Operate and maintain industry-standard SAST/DAST tooling, including AppScan, Veracode, and Burp Suite.
  • Scope application assessments by identifying critical components and APIs to establish security baselines.
  • Validate automated scanner findings through manual testing and exploit reproduction to confirm technical impact.
  • Generate defensible vulnerability reports, providing step-by-step evidence for engineering teams and summaries for management.
  • Partner with development teams to translate security findings into actionable technical requirements and prescribe design-level mitigation.

Required Skills

  • Minimum of 12 years of hands-on experience in Application Security, Vulnerability Assessments, or Penetration Testing.
  • Advanced proficiency in applying OWASP Top 10 and NIST 800-53 standards.
  • Practical experience operating and configuring SAST/DAST tools (e.g., AppScan, Veracode, Burp Suite).
  • Proficiency in using CVSS (Common Vulnerability Scoring System) to correlate technical severity with business impact.
  • Proven ability to explain technical vulnerabilities to developers and provide specific remediation guidance.
  • Experience with Application Security and Vulnerability Assessments methodologies.
  • Familiarity with SDLC and Agile workflows.
  • Experience testing APIs.

Preferred Skills

  • Experience testing cloud-native apps on AWS, Azure, or GCP.
  • Proficiency in manual, deep-dive testing to validate automated findings and identify business logic flaws.
Education

Any Gradute

Related Jobs

No related jobs found

← Back to jobs