Job Title: Software Developer
Location: Arlington VA (Onsite)
Duration: 12 months
What Youll Do:
Collaborate with a team of engineers to implement Brokeragespecific security policies in the CI/CD security tools including but not limited to SAST DAST and SCA applications.
Work with Development DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevOps processes.
Define the security rules that need to be adhered to at a code level in web and mobile applications written in Java React ObjectiveC SWIFT Kotlin etc.
With your development background and security knowledge provide security guidance to developers in the form of secure coding standards and guidelines.
Support security standards create templates and establish patterns to increase the efficiency and adoption of the security program.
These Skills Will Help You Succeed in This Role:
Education: Bachelors degree with a minimum of 8 years of work experience in the IT field.
Experience:
3 years of software development experience using Java and JavaScript.
3 years of experience in:
OWASP Secure Coding Practices.
Common software and web application security vulnerabilities.
Application security scanning tools.
Continuous Integration/Continuous Deployment (CI/CD) processes and concepts using relevant technologies and tools (e.g. Jenkins).
Experience in Python scripting.
Even Better If You Have:
A degree in Cybersecurity or CISSP/CSSLP certification or a keen desire to move into the security field.
Business acumen to support the implementation of SAST DAST or IAST across the enterprise.
Ability to perform code reviews with minimal assistance.
A selfstarter attitude with a strong desire to learn new technologies and apply them to solve problems.
Experience with two or more of the application build environments such as Jenkins Gradle or Maven.
Familiarity with public cloud services.
Experience with two or more Secure SDLC tools such as Burp Suite Fortify Checkmarx AppSec SE Veracode WhiteSource or Sonatype.
Experience with Threat Analysis.
Experience with DevSecOps and Secure SDLC.
Knowledge of DevOps container/orchestration tools (e.g. Kubernetes Docker Puppet) is a plus.
Experience with evaluating integrating and onboarding security tools such as RASP WAF vulnerability scanners container analyzers and opensource scanning is a plus.