Home

Sr. Security Engineer - Atlanta, GA (Hybrid) at Atlanta, Georgia, USA
Email: [email protected]
http://bit.ly/4ey8w48
https://jobs.nvoids.com/job_details.jsp?id=688944&uid=

Title Sr. Security Engineer

Location: Atlanta, GA (Hybrid)

Duration: 12+ months Contract

Visa: Noh1

Note: 
We are currently seeking a Sr. Security Engineer with our

Job Description:

Experience 8 or above

This person
will work with the Application Security Team that works solely with in-house
developed Apps (no COTS). 

Daily tasks
include scanning an working with developers to find any vulnerabilities in the
Applications and identify with static, dynamic, open-source and orchestration
application testing tools.

This team
is also in the process of automating a lot of functions for Dynamic/API testing
and integration work.

Top 3
skills needed:

1 - static
and dynamic application testing experience

2 - Well
versed in Dev/Ops with Gitlab, Jenkins and other DevOps orchestration tools

3 - AWS
experience.  They are 50% through with their migration to the cloud and
someone who has worked with AWS that can provide insight is key.

Also some
development experience.

Schedule is
3-2, so MTW remote then work RF and MTW the following week and so on.

They have
another 300+ Apps to migrate

Description:

Our client is on a journey to becoming the best IT organization in the airline
industry, a journey of transformation. They are changing the way we do business
from top to bottom as we strive to create meaningful and innovative solutions
and are looking for team members to help us realize our vision.

Responsibilities:

Conduct Static Application Security Test (SAST), Dynamic
Application Security Test (DAST) and Source Code Analysis (SCA) using
VeraCode

Correlate findings from tools such as VeraCode Source Code Agent to
identify presence of vulnerable methods in code

Research open-source community contributors and NIST NVD to
understand residual risk and recommend course of action

Determine how frequently and quickly fixes should be delivered for
open-source findings

Review SCA reports to track new and changes to SCA components in
the environment

Experience working with tools such as Sonatype nexus firewall and
lifecycle to track and block risk 3rd- party components

Work within the DevSecOps model to secure Containers, withing ROSA,
Tekton and OpenShift pipelines

Design, develop, plan, implement, and maintain Cloud DevSecOps
processes across multiple technical organizations, instantiating security
testing for internally developed systems, applications, and infrastructure
against business requirements

Guide development teams in integrating new services and
applications into the CI/CD pipeline, troubleshoot installations and build
automated deployments of products into a high-security architecture

Possess a knowledge of CI/CD orchestration tools such as Jenkins,
Tekton, GitLab, or Bamboo.

Provide operational support for container security tools (Palo Alto
Prisma, Aqua, Wiz or equivalent)

Perform Baseline Image validation of new container template images

Evaluate scans results for container runtime environments to reduce
security risk

Troubleshoot any connectivity or operational issues for clusters
being evaluated in the Prisma tool

Apply software development skills (e.g., Java, C#.NET, JavaScript)
to recommend and apply secure coding practices

Validate and address vulnerability / threat findings from static
and dynamic analysis tools

Characterize threats and provide recommendations for remediation;
manage remediation efforts to completion

Develop and present finding and remediation reports to audiences
including team members from all department areas and levels of the company

Perform security reviews of software designs and assist developers
to ensure quality and robustness of our internal products

Conduct security assessments against web applications and APIs
across a variety of technology stacks

Ensure adequate security requirements and privacy by design are
built into all architecture/infrastructure/projects

Integrating threat modeling practices into the application testing
lifecycle

Impart application security and ethical hacking subject matter
expertise into team processes

Drive improvements in the security testing practice to include
execution methodology and metrics

Drive awareness and knowledge of security in the developer
community

Continually improve proficiency in application and API
exploitation, tools, techniques, and countermeasures

Requirements:

B.S. degree in Computer Science, Computer Engineering, Information
Assurance, or related field

Minimum 5+ years of professional experience in application
security, penetration testing, security assessment, secure software
development or related field

Hands-on experience working with Cloud and/or DevSecOps related
technologies

Excellent understanding of DevSecOps techniques and processes,
guide integration of various tools in DevSecOps processes (GitLab/GitHub,
SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and
containerization)

Should be well versed with the AWS well architected framework or
TOGAF and able to apply those principles while designing a solution

Experience building and supporting applications in the Cloud (AWS,
Azure, GCP)

Experience engineering software within an Amazon Web Services (AWS)
cloud infrastructure

Troubleshoot and resolve problems with existing cloud controls

Extensive knowledge of the OWASP Top 10

Experience with vulnerability risk and impact assessment

Experience integrating security capabilities in cloud and
application lifecycle management platforms especially in a DevOps model

Extensive knowledge with static analysis tools and flaw triage such
as Client Fortify, IBM Rational, Veracode or Coverity, FindBugs,
FindSecurityBugs, Brakeman and Open-Source scanning tools such as Sonatype
CLM

Excellent written and verbal communication skills

Strong sense of urgency and ownership

Desired skills:

Extensive experience in application security and ethical hacking

Extensive experience exploiting web, mobile and application
security vulnerabilities

Extensive experience in software development

Extensive experience integrating secure coding techniques with
product teams

Professional certifications such AWS practitioner, cloud security
certification for AWS, and CISSP

Thanks/Regards

Ankush Vikal

Sr. Recruitment |
DNext Consulting

Direct: 630-485-4842

Email 
[email protected]

Hangouts: Ankushvikal18

Disclaimer: This is not meant to be an unsolicited email, so if you
dont want to receive any emails from me and Dnext Consulting, You can
any questions.

--

Keywords: csharp continuous integration continuous deployment information technology Georgia
http://bit.ly/4ey8w48
https://jobs.nvoids.com/job_details.jsp?id=688944&uid=
[email protected]
View All
10:05 PM 27-Sep-23


To remove this job post send "job_kill 688944" as subject from [email protected] to [email protected]. Do not write anything extra in the subject line as this is a automatic system which will not work otherwise.


Your reply to [email protected] -
To       

Subject   
Message -

Your email id:

Captcha Image:
Captcha Code:


Pages not loading, taking too much time to load, server timeout or unavailable, or any other issues please contact admin at [email protected]


Time Taken: 8

Location: Atlanta, Georgia