Vertisystem, a MOURI Tech Company, is seeking an Application Security Engineer to join their security team. This role involves validating security analysis results, collaborating with developers to address security risks, and ensuring security practices are integrated within the software development lifecycle.
Responsibilities:
- Work with engineers to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC)
- Analyze output of application security scanners, such as SAST and SCA, to proactively discover risks and identify security vulnerabilities
- Validate and investigate applicability of identified vulnerabilities and provide risk analysis as needed
- Configure and fine-tune security scanners to ensure scanner output is applicable to the application’s context
- Collaborate with developers and report vulnerabilities to application owners, supervising issues from report to resolution
- Engage with other application security engineers to align tasks with development timelines, completing tasks according to application release timing
Requirements:
- 2+ years of experience working within software development
- Bachelor's degree in Computer Science, Information Security, Cyber Security or equivalent experience (> 7 years)
- Excellent written and oral communication skills, as well as social skills including the ability to articulate to both technical and non-technical audiences
- High level of personal integrity, with the ability to professionally handle confidential matters, and reflect appropriate level of judgment as it pertains to security
- Able to work both independently and with development teams, and multi-task effectively
- Firm understanding of enterprise class application architectures that are highly scalable and reliable, and the expertise to secure them
- Experience with security architecture and feature design reviews
- Experience with multiple languages such as Java, Go, Python and Perl etc, and understand how to detect and remedy related security issues such as OWASP top 10
- Excellent analytical, evaluative, and problem-solving abilities
- Experience with securing host, database, and application solutions for multi-tier systems
- Experience with penetration testing
- Knowledge of automated attack tools and developing mitigation techniques
- Ability to think like an attacker
- Experience with AWS and Akamai technologies
- Technical certifications within information security are a plus (GWAPT, OSCP or equivalents)