drjobs Applications Security Engineer DevSecOpsCyber Security - REMOTE العربية

Applications Security Engineer DevSecOpsCyber Security - REMOTE

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Jobs by Experience drjobs

15years

Job Location drjobs

Las Vegas, NM - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Job Title: Applications Security Engineer DevSecops/Cyber Security

Location: Remote (Remote conditions With Expectation to travel to office 23 times a year Candidates local to Las Vegas expected to be in office minimum twice a month.)

Duration: 6 Months CTH

Important Information to Note:

Client is using a variety of tools. For cybersecurity they are using software composition analysis (SCA) Docker container scanners infrastructureascode scanners Git Leaks and Git Custodian. In terms of application security they are using Checkmarx AppScan Fortify SonarQube AppScan Standard HP WebInspector Burp Suite for manual penetration testing and Veracode and Tenable for vulnerability management. They also use some less modern tools like Pascal for managing products on the gaming floor

Position Overview

The primary responsibility of the Application Security Engineer Cyber Security is to support technologies that enable the companies cyber security goals and objectives securing the confidentiality integrity and availability of software and computer information systems. The role will serve as a security engineer for software development supporting technologies that facilitate security of the software products and services. Additional key responsibilities of role include review of vulnerabilities identified by application security technologies and processes and provide the true positive results to the appropriate software development teams and coordination with those teams to support their triage and remediation efforts for identified valid vulnerabilities. All duties are to be performed in accordance with departmental and Clients policies practices and procedures.

Essential Duties & Responsibilities

  • Act as a primary technical resource in development of a comprehensive security program to support various Software Development Lifecycles (SDLCs) and ensure that software developed in this SDLC is free of security vulnerabilities.
  • Manage application security program across multiple SDLCs.
  • Ensure cybersecurity requirements are met prior to production release.
  • Triage potential vulnerabilities identified by application security program with context of application and related business knowledge.
  • Maintain understanding of core functionality of supported software and firstparty applications.
  • Collaborate with software development and quality assurance teams to ensure code is free from security defects.
  • Review performance of controls such as threat modeling SCA SAST DAST IAST RASP Secrets Scanning Container Scanning Misconfiguration Identification Secure Code Review CI/CD Pipeline Security Deployment Environment Security.
  • Actively seek ways to improve secure software development processes.

Nice to have

  • Professional certification in multiple programming languages (C# .NET Java etc.) recommended.
  • Professional certifications in cyber security (CISSP OSCP etc.) recommended.
  • Experience with CI/CD and pipeline tools such as Jenkins Docker Kubernetes and others.
  • Knowledge of cloud platforms and services with experience in cloud security.
  • Experience with automated software and security testing tools and techniques.
  • Experience integrating security testing into an SDLC.




The primary responsibility of the Application Security Engineer Cyber Security is to support technologies that enable the companies cyber security goals and objectives, securing the confidentiality, integrity and availability of software and computer information systems. The role will serve as a security engineer for software development, supporting technologies that facilitate security of the software products and services. Additional key responsibilities of role include review of vulnerabilities identified by application security technologies and processes and provide the true positive results to the appropriate software development teams, and coordination with those teams to support their triage and remediation efforts for identified, valid vulnerabilities. All duties are to be performed in accordance with departmental and Client's policies, practices, and procedures. Essential Duties & Responsibilities Act as a primary technical resource in development of a comprehensive security program to support various Software Development Lifecycles (SDLCs) and ensure that software developed in this SDLC is free of security vulnerabilities. Manage application security program across multiple SDLCs. Ensure cybersecurity requirements are met prior to production release. Triage potential vulnerabilities identified by application security program with context of application and related business knowledge. Maintain understanding of core functionality of supported software and first-party applications. Collaborate with software development and quality assurance teams to ensure code is free from security defects. Review performance of controls such as threat modeling, SCA, SAST, DAST, IAST, RASP, Secrets Scanning, Container Scanning, Misconfiguration Identification, Secure Code Review, CI/CD Pipeline Security, Deployment Environment Security. Actively seek ways to improve secure software development processes. Nice to have Professional certification in multiple programming languages (C#, .NET, Java, etc.) recommended. Professional certifications in cyber security (CISSP, OSCP, etc.) recommended. Experience with CI/CD and pipeline tools such as Jenkins, Docker, Kubernetes, and others. Knowledge of cloud platforms and services, with experience in cloud security. Experience with automated software and security testing tools and techniques. Experience integrating security testing into an SDLC.

Employment Type

Full Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.