Application Security Engineer

Company:  Genesis10
Location: Atlanta
Closing Date: 20/10/2024
Hours: Full Time
Type: Permanent
Job Requirements / Description
Genesis10 is currently seeking an Application Security Engineer with our client in the transportation industry in their Atlanta, GA location. This is a 12 + month contract position.

Description:

Seeking an Application Security Engineer

Our client is on a journey to becoming the best IT organization in the airline industry, a journey of transformation. They are changing the way we do business from top to bottom as we strive to create meaningful and innovative solutions and are looking for team members to help us realize our vision.

Responsibilities:

Conduct Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA) using VeraCode

Correlate findings from tools such as VeraCode Source Code Agent to identify presence of vulnerable methods in code

Research open-source community contributors and NIST NVD to understand residual risk and recommend course of action

Determine how frequently and quickly fixes should be delivered for open-source findings

Review SCA reports to track new and changes to SCA components in the environment

Experience working with tools such as Sonatype nexus firewall and lifecycle to track and block risk 3rd- party components

Work within the DevSecOps model to secure Containers, withing ROSA, Tekton and OpenShift pipelines

Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements

Guide development teams in integrating new services and applications into the CI/CD pipeline, troubleshoot installations and build automated deployments of products into a high-security architecture

Possess a knowledge of CI/CD orchestration tools such as Jenkins, Tekton, GitLab, or Bamboo.

Provide operational support for container security tools (Palo Alto Prisma, Aqua, Wiz or equivalent)

Perform Baseline Image validation of new container template images

Evaluate scans results for container runtime environments to reduce security risk

Troubleshoot any connectivity or operational issues for clusters being evaluated in the Prisma tool

Apply software development skills (e.g., Java, C#.NET, JavaScript) to recommend and apply secure coding practices

Validate and address vulnerability / threat findings from static and dynamic analysis tools

Characterize threats and provide recommendations for remediation; manage remediation efforts to completion

Develop and present finding and remediation reports to audiences including team members from all department areas and levels of the company

Perform security reviews of software designs and assist developers to ensure quality and robustness of our internal products

Conduct security assessments against web applications and APIs across a variety of technology stacks

Ensure adequate security requirements and privacy by design are built into all architecture/infrastructure/projects

Integrating threat modeling practices into the application testing lifecycle

Impart application security and ethical hacking subject matter expertise into team processes

Drive improvements in the security testing practice to include execution methodology and metrics

Drive awareness and knowledge of security in the developer community

Continually improve proficiency in application and API exploitation, tools, techniques, and countermeasures

Requirements:

B.S. degree in Computer Science, Computer Engineering, Information Assurance, or related field

Minimum 5+ years of professional experience in application security, penetration testing, security assessment, secure software development or related field

Hands-on experience working with Cloud and/or DevSecOps related technologies

Excellent understanding of DevSecOps techniques and processes, guide integration of various tools in DevSecOps processes (GitLab/GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization)

Should be well versed with the AWS well architected framework or TOGAF and able to apply those principles while designing a solution

Experience building and supporting applications in the Cloud (AWS, Azure, GCP)

Experience engineering software within an Amazon Web Services (AWS) cloud infrastructure

Troubleshoot and resolve problems with existing cloud controls

Extensive knowledge of the OWASP Top 10

Experience with vulnerability risk and impact assessment

Experience integrating security capabilities in cloud and application lifecycle management platforms especially in a DevOps model

Extensive knowledge with static analysis tools and flaw triage such as Client Fortify, IBM Rational, Veracode or Coverity, FindBugs, FindSecurityBugs, Brakeman and Open-Source scanning tools such as Sonatype CLM

Excellent written and verbal communication skills

Strong sense of urgency and ownership

Desired skills:

Extensive experience in application security and ethical hacking

Extensive experience exploiting web, mobile and application security vulnerabilities

Extensive experience in software development

Extensive experience integrating secure coding techniques with product teams

Professional certifications such AWS practitioner, cloud security certification for AWS, and CISSP

If you have the described qualifications and are interested in this exciting opportunity, please apply!

About Genesis10:

Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals.

For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10:

Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years.

The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years.

Access to an experienced, caring recruiting team (more than 7 years of experience, on average.)

Behavioral Health Platform

Medical, Dental, Vision

Health Savings Account

Voluntary Hospital Indemnity (Critical Illness & Accident)

Voluntary Term Life Insurance

401K

Sick Pay (for applicable states/municipalities)

Commuter Benefits (Dallas, NYC, SF)

Remote opportunities available

For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website.

Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Apply Now
Share this job
  • Similar Jobs

  • Network Security Engineer

    Atlanta
    View Job
  • Network Security Engineer

    Atlanta
    View Job
  • Application Support Engineer

    Atlanta
    View Job
  • IVOS Application Support Engineer

    Atlanta
    View Job
  • DOAS IVOS Application Support Engineer

    Atlanta
    View Job
An error has occurred. This application may no longer respond until reloaded. Reload 🗙