Title: AppSac Consultant
Location: Richfield MN (Day 1 Onsite)
Job Description
- Excellent understanding of different application security vulnerabilities and their mitigation OWASP SANS etc.
- Scan the source code of Web and mobile applications and manually triage the results. Correlate these results and conduct followon tests as needed.
- Good understanding of common CVEs and exploits.
- Experience with writing custom rules in various tools and good understanding on how these scanners work.
- Perform analysis design and configuration of CI/CD tools and integration with different systems.
- Integrate CI/CD tools with existing security tools like Checkmarx Veracode Fortify Blackduck etc.
- Excellent understanding on how dependencies are handled by applications and how each build tool works.
- Collaborate with application teams and onboard applications to various tools.
- Excellent understanding of different programming languages like Java Groovy Javascript and web frameworks like Spring Node JS React etc.
- Scripting with Shell/Python highly desired.
- Continuously advise development teams on how to remediate issues including coding proofofconcept solutions and advise dev teams on secure coding practices for addressing findings.
- Working knowledge of various dev tools like bitbucket Jira confluence etc.