Security Architect

Procession Systems
Virginia, Estados Unidos
Teletrabajo

Job Description

OVERVIEW :

You would be responsible for helping to create, evolve, document, and implement security development and deployment practices for a product that’s delivered both on-premises as well as to the cloud.

This work would include evaluating and disseminating information and recommendations from resources such as NIST, OWASP, MITRE, and other sources of security information and best practices.

This work would also include with the assistance of the rest of the development team implementing these security controls and practices as part of the software development process, supplying guidance and requirements for deploying our product on-premises, and creating a secure environment for our upcoming cloud offering.

Our product is a .NET Core application (with some TypeScript and Python components) backed primarily by PostgreSQL, that serves both a web frontend and REST API.

The application source is hosted in GitLab, and we use merge requests and GitLab CI to manage our code contribution workflows.

Required Skills

REQUIRED QUALIFICATIONS :

  • Experience maintaining a secure software supply chain (monitoring for CVEs, creating SBOMs, etc.)
  • Experience evaluating security best practices and applying them to processes and assets
  • Experience reviewing code and architecture to identify potential security issues
  • Experience writing internal documentation around security evaluations and decisions
  • Experience with security monitoring infrastructure (log analysis, web application firewalls)
  • 8+ years of experience
  • Familiarity with writing infrastructural code in support of security goals (abstractions, constraints, etc.)
  • Familiarity with working with developers to help them learn and self-apply secure development principals
  • Familiarity with government / industry security auditing processes
  • Specific familiarity with web security concepts and best practices (TLS / HTTPS, common web vulnerabilities, federated authentication, etc.)

CLEARANCE :

US Citizenship minimum

Desired Skills

DESIRED QUALIFICATIONS :

  • Specific familiarity with government programs pertaining to secure application development (STIGs, APL, NIAP)
  • Specific experience with the Microsoft web application development stack (C#, .NET, ASP.NET)
  • Specific experience with AWS security tooling
  • Experience with static application security analysis tools

About Procession Systems

About us

Hace más de 30 días