← Back to jobs

Sspearhead Inc Logo
Windows Application Security Developer

Sspearhead Inc

 

Atlanta, GA, USA

Posted On: 30+ days ago
Experience: 9+ years
Availability: Onsite
Openings: 1
Category: Windows Application Security Developer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

You own the security lifecycle for Windows desktop applications.

Responsibilities

  • Interpret Veracode SAST reports, analyzing CWE classifications and severity scores to triage High and Critical findings.
  • Identify and fix OS command injection and SQL injection vulnerabilities across VB6 and .NET components.
  • Map Veracode findings to specific source code modules (VB6, C#, VB.NET, SQL, Python, Fortran) and prioritize remediation backlog.
  • Rebuild applications post-patching, managing dependencies, resolving build errors, and conducting full regression testing.
  • Maintain technical documentation covering root cause analysis, code changes, and residual risk per finding.

Required Skills

  • 9+ years of professional experience in Windows desktop application development (VB6 / .NET).
  • Strong hands-on experience with Visual Basic 6 (VB6), including ADO, Windows API, and ActiveX.
  • Proficiency in C# and/or VB.NET on the .NET Framework for Windows Forms development.
  • Deep understanding of SQL injection remediation (parameterized queries, stored procedures).
  • Proven experience fixing command injection via input sanitization and allowlisting.
  • Hands-on experience with Veracode SAST, interpreting findings and driving flaw closure.
  • Knowledge of OWASP Top 10 and secure coding standards for desktop applications.
  • Proficiency with Git or SVN for version control and patch management.
  • Bachelor's or Master's degree in Computer Science, Software Engineering, or Cybersecurity.

Education

Bachelor's or Master's degrees

Related Jobs

No related jobs found

← Back to jobs