GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk.
By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
Requirements
Proficiency with the implementation, operationalization, and troubleshooting of Static Application Security Testing (SAST) tools such as Semgrep, Snyk, CodeQL, Checkmarx, Veracode, etc.
Experience in software engineering, ideally full stack software development, including modern technologies and application architectures
Strong scripting and automation experience using one or more programming languages
Solid working knowledge of application security fundamentals including the OWASP Top 10, threat modeling, and implementing secure coding practices throughout the Software Development Lifecycle (SDLC)
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Excellent written and verbal communication skills.
Experience writing or adapting custom SAST rules (Semgrep or CodeQL)
Familiarity with additional Application Security tools (e.g. Interactive (IAST), Dynamic (DAST) and API security, SCA, etc.)
Familiarity with API Security tools (e.g., NoName, Traceable, Salt, Cequence)
Practical hands-on experience validating vulnerabilities and proficiency with Burp Suite
Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities identified by web application scanning tools
Understanding of automated security testing approaches and tools
Experience in building and operating security tools within CI/CD pipelines
Experience with proactive integration of security into the development process
Past experience as an application security practitioner or software engineer
Bachelor’s degree in a relevant discipline or equivalent experience
5-7 years of security engineering experience in the Information Security industry
Tech Stack
Azure
Cyber Security
Jenkins
SaltStack
SDLC
Benefits
Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
12 corporate holidays and a Flexible Time Off (FTO) program
Healthy mobile phone and home internet allowance
Eligibility for retirement plan after 2 months at open enrollment