Experience with one or more programming or scripting languages such as Java, JavaScript, Python with focus on secure coding practices and vulnerability management.
Deep understanding of operating systems (Linux/Windows), networking protocols, and scripting /programming languages like python.
Experience with container security, Kubernetes, Helm, Docker, and cloud native workload protection.
Familiarity with application security testing tools such as Checkmarx, Contrast Security, TideLift, Burp Suite, OWASP Dependency Check, Fortinet or similar platforms.
Experience with vulnerability identification, triage, remediation validation, and risk-based prioritization.
Experience working with CI/CD and source code management platforms such as Bitbucket, GitLab, GitHub, Jenkins, or similar tools.
Experience supporting security automation, metrics reporting, and vulnerability management integrations with tools such as Jira, ServiceNow, or risk management platforms
Professional certifications such as the Offensive Security Certified professional (OSCP) or Certified Ethical Hacker (CEH) preferred.
The incumbent is required to immediately disclose any debarment, exclusion, or other event that makes them ineligible to perform work directly or indirectly on Federal health care programs.
Must be able to effectively work in a fast-paced environment with frequently changing priorities, deadlines, and workloads that can be variable for long periods of time.
Must be able to meet established deadlines and handle multiple customer service demands from internal and external customers, within set expectations for service excellence.
Must be able to effectively communicate and provide positive customer service to every internal and external customer, including customers who may be demanding or otherwise challenging.
Licenses/Certifications:
CISSP Certified Information Systems Security Professional Upon Hire Req or
CISM - Certified Information Security Manager Upon Hire Req or
Certified Ethical Hacker (CEH) Upon Hire Req or
Certified Information Systems Auditor (CISA) Upon Hire Req