Similar available jobs
in Mclean, VA
Title: Information Security Analyst
Location: 100% Remote role
Duration: 12 months Contract to hire role with possibility of getting converted after 3 months
Only open for non-sponsered profiles
Position Summary
We are seeking an Information Security Senior to assist our Application Security Testing area. The candidate will provide subject matter expertise in AppSec Analysis of our internally developed applications. In this role, you will work closely with development teams to assist them with the analysis and remediation of software security vulnerabilities in their code.
Responsibilities
Priorities can often change in a fast-paced environment like ours, so this role includes, but is not limited to, the following responsibilities:
- Communicating with stakeholders at every stage of the appsec testing activity to understand applications in context, existing security controls and providing guidance on remediation of the vulnerabilities discovered.
- Be a self-motivated individual who can manage your time and deliver reports in a tight timeline to the business.
- Assist with and make improvements to the process that drives the secure development lifecycle
- Develop technical solutions, new security tools/scripts to automate repeatable tasks
- Introduce and integrate security testing tools to existing SDLC to drive higher levels of assurance
- Identify and define application security requirements
- Prepare and document standard operating procedures and protocols
- Write comprehensive reports including assessment-based findings, outcomes, and propositions for further application security enhancement
Requirements
- Proven work experience as an application security engineer or information security engineer
- Working knowledge of Java w/ preference for Python
- Proven ability to identify code level weaknesses
- Working knowledge of best practices for securing code repositories
- Strong familiarity with various build technologies, code repositories, and CI/CD pipeline processes
- Serve as the technical SME on project work
- Mentor other team members through technical challenges
- Thorough understanding of security testing techniques
- Ability to problem solve independently and collaborate as a team to solve complex problems in support of the teams mission
- Proven experience in finding vulnerabilities and weaknesses in code and systems
- Knowledge of industry best practices for foundational security elements and application security best practices
- Experience leading technical projects
- Working knowledge of fuzzing, DAST, SAST, SCA and/or IAST
- 3-5 Years dedicated AppSec experience
- Bachelor degree or equivalent work experience
Preferred Skills:
- CISSP, CSSLP certification
- Strong written, verbal and presentation skills required.
Information Security,Fortify/checkmarx,Java,Application Security