Friday, 26 April 2019

Application (Java) Security Engineer (VS# 7-0136)

Hi ,

Hope you are doing great.

As discussed please go through the below position, if you are comfortable share the below required details along with your DL and Visa Copy ASAP.

 

Application (Java) Security Engineer (VS# 7-0136)

Headcount: One (1)

Assignment Duration: Temp-To-Hire

Location: Rensselaer, NY

 

The Application Security Engineer will be responsible for integrating security into the development of NYSoH’s applications. The Application Security Engineer will work closely with the software development team to threat model, vulnerability scan, and pen test the early software, system, and network architecture and identify required control points in the application stack. The Application Security Engineer will also work closely with developers to diagnose, document, and remediate application security vulnerabilities. The Application Security Engineer will also be responsible for evaluating, recommending, and implementing application security related software in an automated continuous integration/deployment environment.

This is a new position and the first application security hire. You will help to establish risk frameworks, identify application vulnerabilities, perform risk assessments, and work cross functionally to remediate, mitigate, or accept the risk(s) of vulnerabilities. Secondarily you will be responsible for implementation and maintenance of security tools with a focus on improving automated testing processes and reporting.

 

You would get an opportunity to work alongside some of the most senior engineers to support the programs comprehensive efforts to identify and remediate software security defects and maintain a high level of software quality for our client.

 

Responsibilities

  • Provide leadership and expertise in application security.
  • Develop remediation plans to target cyber security vulnerabilities.
  • Offer cyber security thought leadership and secure coding standards.
  • Identify appropriate security check points in the systems development life cycle.
  • Perform risk-based, technical assessments of applications, using dynamic and static scanning tools; Produce reports, and meet with development team.
  • Work with appropriate stakeholders in app dev and management to develop a formal Application Security Verification Standard within our SDLC process.
  • Perform application security audits ensuring compliance with industry standards, procedures, etc.
  • Consult with application development and technical operations on security designs of applications, potential vulnerabilities, and remediation.
  • Create documentation and training materials to educate development team and other stakeholders on key security concepts.
  • Research new attack vectors and stay current with cybersecurity news and trends.
  • Develop and maintain a balanced application security program based on a well-defined application security framework.
  • Conduct application security assessments / penetration tests and implement tools for dynamic/automated code reviews.
  • Work with Development Designers and Application Architects on application design and implementation best-practice with role-based and appropriate access standards, as well as integration with Identity and Access Management environments.
  • Continuously evaluate the organization’s existing application security practices, define and measure security-related activities, and demonstrate concrete improvements to the application assurance program within the organization.
  • Consult with the Development leadership on application development training for developers

 

Qualifications

The ideal candidate would have a development background, as well as a strong background in Security principles as it relates to code.

  • Bachelor’s Degree in computer science or other relevant discipline.
  • Eight (8) years of Information Technology experience
  • Must have come up or be a current Java programmer with a strong secure coding background.
  • Three (3) – five (5) years’ experience in a software development field such as Software Developer, Architect, Software Quality Assurance, or Application Security Engineer.
  • 3+ years of experience working in Information Security with a focus on application security
  • Experience with security tools: Experience with Dynamic and static application scanning: Veracode, Appscan, Fortify.
  • Ability to communicate effectively in writing and verbally with an attention to detail
  • Demonstrated collaboration and teaching abilities.
  • Strong analytical problem-solving skills.
  • CISSP, CEH, CISA, OSCP, OSCE, or OSWE Certifications are a major plus

 

 

Consultant Details:

 

 Full Name as per Passport

 

Current Location (City, State & Zip Code)

 

Relocation (Y/N)

 

Phone Number

 

Email Id

 

LinkedIn Id

 

Date of Birth (MM/DD)

 

SSN last 4 Digits

 

Highest Education & Year of Passing

 

Visa Status (Attach Visa Copy)

 

Validity

 

Interview - Slots for next 2 days

 

W2 or C2C

 

Total Years of Experience

 

Skype ID

 

Currently on Project (Yes / No)

 

Availability

 

Rate

 

 

 

Arun Reddy

IT Recruiter

(W) 312-985-0412

22260 Haggerty Rd, Suite # 285,Northville, MI 48167.

www.rsrit.com

 
 
 
 

To unsubscribe from future emails or to update your email preferences click here .

1 comment:

  1. Cyber threats are numerous and it may get worse in the near future. Many countries already have programs to monitor and collect data about cyber sabotage. Governments which don’t have such active programs are more or less likely to implement them in the near future, so even if you trust your own government with your data, you need to be careful about other governments who have not yet taken cyber crime seriously. As a software developer the onus lies on you to create applications that are highly secure and not easily prone to cyber attacks.Thanks for sharing such an important topic. ~ Charlotte W. from software security testing

    ReplyDelete