About The Position

Enforces application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms.

Requirements

  • Bachelor’s Degree in Computer Science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience. Master’s Degree preferred.
  • 8-15 years of experience as an Application Security Developer, Application Security Analyst, or equivalent.
  • In-depth knowledge of and experience with security technologies, single-sign-on and identity management technologies.
  • Expertise with web system security concepts, including authentication, authorization (RBAC), encryption/hashing, SAML, and LDAP.
  • Advanced knowledge of web application vulnerabilities such as cross-site scripting (XSS), sessions hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors.
  • Hands-on experience with encryption, hashing, secure random number generation, key derivation, digital signatures, etc.
  • Advanced knowledge of network based, system level and application layer attacks and mitigation methods, and TCP/IP, HTTP/S, and related protocols.
  • Experience with static code analysis tools.
  • Familiarity with JavaScript, NodeJS, or other scripting languages and BurpSuite or other intercepting proxy tools.
  • Experience working with GIT source code management.

Nice To Haves

  • Understanding of Agile/Scrum methodologies is preferred.

Responsibilities

  • UMS/EIE/CA setup, config, user management.
  • Automate workflow utilizing Python scripts to improve speed of migrating 65K users to Keyfactor backup, which decreased error rate 95% and increased batch account processing.
  • Ping Federate/DataSync SSO system configuration, update and troubleshooting.
  • User driven with day-to-day knowledge of PKI system, unlock shared mailboxes, and assist with projects and support team with PKI related incidents and Department wide initiatives while maintaining federal standards and procedures.
  • Act as Subject Matter Export with Tenable with identifying and resolving critical PKI vulnerabilities and ensuring robust security and patches.
  • Spear heading the SSL 47 day life cycle automation with researching solutions to automate and improve efficiency with SSL issuance.
  • Identifies additional application security related tools, conducts tool analysis, and provides recommendations on what tools will enhance security protocols.
  • Performs and conducts penetration tests and manual/automated code reviews.
  • Creates and delivers training developers and other relevant team members on Secure Code Development as well as other security protocols.
  • Designs, develops or recommends integrated system solutions ensuring proprietary/confidential data and systems are protected.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service