Cyber Security - IT Security Auditor
- Minimum of 5+ years of total IT related experience.
- 3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)
- 3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks
- 3+ years with networking, infrastructure, secure application development and security automation (DevSecOps).
- 3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications.
Job Description:
- Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition Analysis assessments.
- This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices.
- The ideal candidate will feel comfortable working with both front-end, back-end and cloud-based application developers.
- Partnering with distributed teams to help transform the way systems are built, secured, authorized and securely operated for continuous compliance and risk mitigation.
- Specifically, this candidate will help lead efforts to implement security patterns and practices with orchestration and automation tools that automate the secure configuration, verification, compliance, and authorization of systems and their development.
- They will be a key member of a team tasked with maturing the organization's secure software development practices.
Functional Knowledge:
- Chrome/Firefox/Edge Development tools to see the request/response headers
- Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud) a must.
- Experience with Coverity, BlackDuck, STRM, Fortify a plus
- Request/Response headers for web and Restful API calls
- Ability to explain in detail any of the OWASP top 10 vulnerabilities
- Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc.
- API Security
- JWT
- OAUTH/OIDC/PKCE
- Web, API replay attacks
- High-level understanding of containers
- Cloud development experience (Azure, AWS, GCP).
Recommended Jobs
Runner/Server Assistant
Job Description Job Description Marcus Samuelsson Restaurant Group is seeking a Server Assistants and Food Runner to join the opening team of our newest restaurant concept in East Rutherford, New…
Night Audit-Hilton Garden Inn Mt Laurel, NJ
Night Auditor/Guest Services Agent – Hilton Garden Inn Mt. Laurel, NJ Full-time & Part-time Opportunities Available Join Our Team! At Hilton Garden Inn Mt. Laurel, we are committed to providi…
Onsite Customer Service Manager, Omnichannel
Job Description Job Description About Flexport: At Flexport, we believe global trade can move the human race forward. That's why it's our mission to make global commerce so easy there will be mo…
Social Worker LCSW, Mental Health-Adult OP
Job Title: Social Worker LCSW Location: NPC PLAZA BLDG Department Name: Mental Health Adult OP Req #: 0000213570 Status: Salaried Shift: Day Pay Range: $75,211.00 - $93,444.00 per ye…
Class A CDL Driver
Job Description Job Description . We partner with some of the country's largest and most respected carriers to connect experienced drivers with high-quality opportunities. Whether you're looki…
Virtual Primary Therapist, NY
*Seeking therapists with full independent clinical licensure in New York. Position is 100% remote, PRN/ As Needed, Evenings required, along with day time hours (Mon-Fri). We’re thrilled to level up…
Line Service Technician - Full Time
Job Description Job Description Why You’ll Love This Line Service Technician JobDid you ever want to work in aviation but didn’t know how to break into the industry? Would you like working in a f…
Pharmacy Technician
Job Description Job Description Company Description International Health and Medical Services delivers customized medical and security risk management and wellbeing solutions to enable our c…
Training Lead
Job Description Job Description JCFPL JOB TITLE : Training Lead DEPARTMENT : The Learning Center LOCATION : Learning Center offices and various branch locations REPORTS TO : Learning…
Supply Chain Coordinator
POSITION SUMMARY: The Supply Chain Coordinator is the one who helps support the planning and turns it into action by aligning product priorities with operation capacity to ensure supply plans are cle…