02 Nov
Application Security Engineer
Application Security EngineerRequirements:- Bachelor's degree in information technology, computer science, or comparable technical field.
- Four (4) years of experience focused on application security, or a combination of education and experience.
- CISSP, CISM, CISA, GCIH, CCSP, or other related security and risk certification.
- Experience with DevOps/DevSecOps methodologies and processes.
- Experience with scripting languages, software development, and Web development practices and languages.
- Ability to perform network and Web application penetration testing using both automated tools and manual techniques. Capable of managing third party penetration testing engagements.
- Ability to configure and maintain Web application firewalls and WAF security policies.
- Experience with common cloud platforms and cloud security controls.
- Able to conduct security reviews and risk assessments for on premise, SaaS, and cloud technologies. Able to research and evaluate security controls and make recommendations for remediation or improvement.
- Knowledge and experience with network protocols, network technologies, and identity management principles.
- Experience with logging, monitoring, and log analysis tools.
- Understanding of common security frameworks and implementing best practices, such as NIST, ISO, and MITRE ATT&CK.
- Able to configure and manage Web application scanning and static code analysis tools.
- Thorough understanding of Web application security concepts, principles and guidelines, such as OWASP.
- Knowledge of PKI and current cryptographic concepts, principles, algorithms, and technologies
- Excellent analytical, decision making and problem solving skills.
- Excellent customer service, interpersonal, and verbal and written communication skills, with the ability to build and maintain effective relationships with all levels of management, team members and customers.
- Strong organizational and time management skills and detail orientation, with the ability to prioritize and multi-task under tight time frames and competing priorities
- Ability to work independently, as well as collaboratively in a team environment.
- High degree of personal integrity and trustworthiness.
- Ability to provide off-hour, on-call production support.
- Availability for occasional travel.