drjobs Application Offensive Security Consultant العربية

Application Offensive Security Consultant

Employer Active

1 Vacancy
The job posting is outdated and position may be filled
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Jobs by Experience drjobs

5years

Job Location drjobs

Jersey - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Centurion Analytics, LLC is seeking an experienced Application Offensive Security Consultant to support our client in a hybrid role located in Jersey City, NJ.

The Application Offensive Security Consultant-Secure Code Reviewer is responsible for providing technical direction and performing secure code review on applications. The person in this role should possess good understanding of application security vulnerabilities, secure coding, software development life cycle (SDLC), offensive security methodology and SAST/DAST.

General Duties Include But Are Not Limited To:
  • Perform Manual Secure Code Review against applications
  • Analyze and identify vulnerabilities in source code using manual analysis techniques
  • Coordinate with application development teams to collect the application details
  • Provide the vulnerability information in the predefined report format after performing the testing using manual methodology
  • Assist the developers and business teams in detailing the vulnerabilities reported along with the recommendations for remediation
  • Align risk and control processes into day-to-day responsibilities to monitor and mitigate risk; escalates appropriately
  • Generate reports on assessment findings and summarizes to facilitate remediation, document technical issues identified during security assessments
  • Perform threat modeling, design, and code views to assess security implications and requirements
  • Be a subject matter expert and respond to any security engineering questions/ requests related to Application Defense enhancements
  • Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality product


Requirements

  • Minimum of 3+ years of experience in secure code review
  • Minimum of 5+ years in application security
  • Experience in performing manual secure code review
  • Bachelor s Degree and/or equivalent experience
  • Minimum of 5 years of experience in application security
  • Minimum of 3 years of detecting and analyzing vulnerabilities in at least two of the following languages: Java, C#, C/C++, Python, PHP
  • Ability to explain vulnerabilities and weaknesses in OWASP Top 10 and SANS Top 25 to any audience and discuss effective defensive techniques
  • Proficiency with application security best practices with focus on secure coding
  • Ability to work under pressure, multitask and be flexible
  • Experience in conducting analysis using commercial tools such as Fortify, Veracode, SonarQube or related tool



Benefits

Centurion Analytics, LLC is an equal opportunity employer and does not discriminate against any employee or applicant for employment because of race, religion, color, sex, national origin, age, disability, or any other basis prohibited by state law relating to discrimination in employment.




Minimum of 3+ years of experience in secure code review Minimum of 5+ years in application security Experience in performing manual secure code review Bachelor s Degree and/or equivalent experience Minimum of 5 years of experience in application security Minimum of 3 years of detecting and analyzing vulnerabilities in at least two of the following languages: Java, C#, C/C++, Python, PHP Ability to explain vulnerabilities and weaknesses in OWASP Top 10 and SANS Top 25 to any audience and discuss effective defensive techniques Proficiency with application security best practices with focus on secure coding Ability to work under pressure, multitask and be flexible Experience in conducting analysis using commercial tools such as Fortify, Veracode, SonarQube or related tool

Employment Type

Full Time

Company Industry

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.