Talent.com
TEKsystems
Sr. Application Security Engineer - Work from homeTEKsystems • Raleigh, NC, US
Sr. Application Security Engineer - Work from home

Sr. Application Security Engineer - Work from home

TEKsystems • Raleigh, NC, US
30+ days ago
Job type
  • Full-time
  • Remote
Job description
  • Description : * What will this person do? This individual is accountable for identifying weaknesses in our security posture within the application or web space while defining methods to achieve security control requirements via automation or highly efficient means that further support timely delivery and minimal overhead. They work in a team of infrastructure specialists and engineers making sure services are delivered and used securely as required. Works with and supports third parties to provide security services. The Sr. Application Security Engineer will advise and enable development and technical teams to make security decisions and provide advice and guidance, ensuring the effective use of common tools and patterns *Best fit candidate will have a strong understanding of S-SDLC (Secure Software Development Life Cycle) process and implementation. Have a strong understanding of the OWASP top 10 Framework with Excellent communication skills to help guide / educate developers on creating code with security in mind in each phase of the SDLC. Responsibilities : Act as the point of contact for Application engineering and security. Participate in security code reviews, and automate penetration testing against products prior to move to production. Support engineering with implementing security fixes, ensuring security scanners are utilized correctly, and develop strategies to proactively secure their architecture. Review development frameworks for security functionality, consistency, and uplift opportunities. Create threat models and leverage them to prioritize time based on risk impact. Educate and train product teams. Evaluate client needs, coordinate design for a solution, and clearly communicate the value proposition of complex and highly technical subjects Implement and / or assess existing security controls Translates logical designs into physical designs. Produces detailed designs and documents all work using required standards, methods and tools, including prototyping tools where appropriate. Designs systems characterized by managed levels of risk, manageable business and technical complexity and meaningful impact. Works with well-understood technology and identifies appropriate patterns. Client Job Description : The Application Engineer, Cyber Security is responsible for building, managing and supporting information security that underpins all internal and external user technology services, according to security policies and best practices. The Application Engineer, Cyber Security has strong development experience in numerous programming languages and is the subject matter expert (SME) for concepts behind security controls and how they apply to application development, web presence and API services. This individual is accountable for identifying weaknesses in our security posture within the application or web space while defining methods to achieve security control requirements via automation or highly efficient means that further support timely delivery with minimal overhead. They work across internal and external teams of infrastructure specialists and software engineers making sure services are delivered and used securely as required, offering advice and guidance on security decisions and ensuring the effective use of common tools and patterns. The incumbent must have a service-oriented mentality, a high sense of ownership of the problems and requests assigned, a focus on managing and resolving issues in alignment with the SLAs, establishing and maintaining communication with technology customers to keep them updated with status of their requests, initiating and performing changes on production systems and proactively escalating any issues that cannot be resolved within the established timeframes. Additional insights, experience or background in any of the following are also of great value : NIST, ISO27001, Data Protection, Python Development, Static Code Analysis, Dynamic Code Analysis, Penetration Testing, Containers, MicroServices, CI / CD Pipeline, Agile, Git, Jira, Docker, Kubernetes, cloud security (AWS, Azure, GCP) and design, process maturity, and other related focuses. Primary Accountabilities : Technical (80%) - Be the security representative for multiple product lines and act as the point of contact for software engineering and security. - Perform architecture reviews to steer projects in the right direction, participate in security code reviews, and automate penetration testing against products prior to move to production. - Support software engineering with implementing security fixes, ensuring security scanners are utilized correctly, and develop strategies to proactively secure their architecture. - Review development frameworks for security functionality, consistency, and uplift opportunities. - Create threat models and leverage them to prioritize time based on risk impact. - Evaluate client needs, coordinate design for a solution, and clearly communicate the value proposition of complex and highly technical subjects. - Implement and / or assess existing security controls. - Translate logical designs into physical designs; produce detailed designs and document all work using required standards, methods and tools, including prototyping tools where appropriate. - Design systems characterized by managed levels of risk, manageable business and technical complexity and meaningful impact; works with well-understood technology and identifies appropriate patterns. Project Management (20%) - Work with application development teams to ensure secure software development lifecycle (S-SDLC) implementation and validation. - Educate and train product teams. - Evaluate client needs, coordinate design for a solution, and clearly communicate the value proposition of complex and highly technical cyber security subjects. Specific Technical Skills Needed : Security and Risk Assessment : - Aware of Security governance principles and able to apply them to the enterprise - Understands the legal and regulatory Issues relevant to the enterprise and does not place the enterprise at risk. Security Engineering : - Working knowledge of secure design principles - Working knowledge of database security - Working knowledge of cloud computing - Working knowledge of Cryptography Identity and Access Management : - Physical and logical access - LDAP - Multi-factor authentication - Session management - Credential management Software Development Security : - Working knowledge of software development lifecycles - Working knowledge of what software development methodologies are used in the enterprise and can explain what it means - Familiar with DevOps concepts - Working knowledge of security vulnerabilities and understands how the following work : Bounds checking, Input / output validation, Buffer overflow, Privilege escalation - Working knowledge of secure coding practices - Working knowledge of code repositories Individual Competencies : - Integrity : Gains the trust of others by taking responsibility for own actions and telling the truth. - Teamwork : Builds relationships and works cooperatively with others, inside and outside the organization, to accomplish objectives to build and maintain mutually-beneficial partnerships, leverage information and achieve results. - Adaptable : Responds to change with a willingness to learn new ways to accomplish work objectives with a positive attitude. Innovative : Ability to develop, sponsor, or support the introduction of new and improved methods, products, procedures or technologies. - Curious : A desire to inquire and learn, to seek new knowledge and wisdom, and to listen to the contributions of others with a genuine interest to better self, the team, and the organization. - Analytical and Critical Thinking : Ability to tackle a problem by using a logical, systematic, sequential approach. - Problem Solving : Gathers and analyzes information to generate and evaluate potential solutions to problems, issues and challenges while weighing the accuracy and relevance of the facts, data and information. *Skills : * Applications Security, S-SDLC, SDLC, OWASP Top 10, Developer, Cloud, Information security, Code Review, Threat Modeling, owasp, Application security, Security architecture, Vulnerability, code deployment *Top Skills Details : * Applications Security,S-SDLC,SDLC,OWASP Top 10,Developer,Cloud,Information security,Code Review,Threat Modeling *Additional Skills & Qualifications : * Required Qualifications : Bachelor’s degree in Computer Science, Information Technology or related field 8-10 years of related work experience with application security, e.g. DAST, SAST, SCA, cloud security Or any equivalent combination of experience and training / certification that provides the required knowledge, skills, and abilities needed to complete the major responsibilities / essential functions of the position Certifications preferred. OSCP, CISSP, GCIH, GXPN, GPEN Working experience in web and mobile application security Working experience in distributed platform development security and design In-depth knowledge of web and mobile security standards and best practices (OWASP, etc.) Strong foundation in core information security principles and concepts (HTTPS, TLS, OAuth, etc.) Working experience with industry tools and technologies such as Burp, Metasploit, etc. Working knowledge of common languages *Experience Level : * Expert Level About TEKsystems : We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company. The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
Create a job alert for this search

Sr. Application Security Engineer - Work from home • Raleigh, NC, US

Similar jobs

Sr Account Executive - Electronic Security/Door hardware

WilsonHCGRaleigh, NC, United States
Full-time

One of the East Coast's premier Security integration organzations is searching for talented Account Executive to drive Sales in the RTP area.This company is a market leader in the Southeast, provid... Show more

 • Promoted

Security Specialist

Arete Technologies IncRaleigh, NC, United States
Full-time

Security SpecialistArete Technologies, Inc.Consulting and Outsourcing services, bridging the gap between requirements and outputs of various dexterous and facile companies worldwide.The thrust of p... Show more

 • Promoted

Earn Side Money at Home Testing Products

Product Review JobsLILLINGTON, NC, United States
Full-time

Compensation: Varies per assignment.Location: Remote (USA) Company: ProductReviewJobs Thank you for your interest in becoming a Paid Product Tester.This opportunity is for completing market res... Show more

 • Promoted

Artificial Intelligence Engineer (Full-Time Remote, North Carolina Based)

Alliance HealthRaleigh, NC, United States
Remote
Full-time

OverviewThe Artificial Intelligence Engineer (AI Engineer) will design, develop, deploy, and integrate machine learning models, AI tools, and other analytics products into Alliance systems and work... Show more

 • Promoted

Sr. Director, AI & Technology Risk Governance

The Mutual GroupRaleigh, NC, United States
Full-time

Enterprise Ai Systems Governance Leader.Lead the enterprise AI Systems Governance Program, with core accountability for governing AI Systems across The Mutual Group and its member insurance carrier... Show more

 • Promoted

SAP Security PM

Omni InclusiveRaleigh, NC, United States
Full-time

Looking for a resource who started as a hands on SAP Security resource who moved their way up into program management. Show more

 • Promoted

Business Information Security Leader - Corporate Systems - Hybrid Bridgewater, NJ or Morrisville, NC

Syneos HealthMorrisville, NC, United States
Full-time

Business Information Security Leader - Corporate Systems.Syneos Health is a leading fully-integrated life sciences services organization built to accelerate customer success.We partner with innovat... Show more

 • Promoted

Remote Amazon Web Services (AWS) Security Specialist

Reef SystemsCary, NC, United States
Remote
Full-time

Remote Amazon Web Services (AWS) Security Specialist Reef Systems is a small business based in Raleigh NC seeking an Amazon Web Services (AWS) Security specialist that can help us hardening our AWS... Show more

 • Promoted

Data Entry Clerk - Remote Work From Home (Part-Time / Full-Time)

Apex Focus GroupWake Forest, NC, US
Remote
Full-time +1

Now accepting applicants for Focus Group studies.Earn up to $750 per week part-time working from home.Must register to see if you qualify.No Data Entry experience needed.Data Entry Clerk Work From ... Show more

 • Promoted

Work From Home

Remote JobsLinden, NC
Remote
Full-time

Remote Jobs are now available in your area.This position is a work from home position.You will not need to come into the office.Benefits: Health Insurance, 401K, Vacation& PTO.Apply now! Work f... Show more

 • Promoted

94E Radio and Communications Security Repairer

Army National GuardDunn, NC
Part-time

It’s extremely important that Army National Guard communications don’t fall into the wrong hands.As the Radio and Communications Security Repairer, you will maintain the equipment and systems that ... Show more

 • Promoted

Armed Security Officer Patrol

Allied UniversalDunn, NC, United States
Part-time

Allied Universal®, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose.While working in a dynamic, welcoming, and collaborat... Show more

 • Promoted

Sr Analyst, Global C2C

TeleflexMorrisville, NC, United States
Full-time

About Teleflex Incorporated: As a global provider of medical technologies, Teleflex is driven by our purpose to improve the health and quality of people's lives.Through our vision to become the mos... Show more

 • Promoted

Remote Sensing AI / ML Engineer

C-star SolutionsFuquay Varina, NC, United States
Remote
Full-time

Spectral ScientistC-Star supports our customers with advanced intelligence analysis to aid analysts, the warfighters and decision makers.You will be supporting a team in Springfield, VA located at ... Show more

 • Promoted

Flexible remote AI work. Your schedule. Paid weekly, straight to your bank account.

Meridian.aiWake Forest, NC, US
Remote
Full-time

Review and label digital content including text, images, and documents.Every task you complete helps improve how technology interprets information and performs in practical settings.Detail-oriented... Show more

 • Promoted

VP Global Key Account -Data Center Segment

Eaton PlcWake Forest, NC, United States
Full-time

Global Account VP for Data Center.The Global Account VP for Data Center is a senior-level global sales role and the single point of contact for assigned global hyperscaler and MTDC accounts.Account... Show more

 • Promoted

Security Account Manager

Allied Universal SecurityButner, NC, United States
Full-time

Company Overview: Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose.While working in a dynamic, welcomi... Show more

 • Promoted

Physical Therapist (Part-Time) - Wake Forest, NC

Athletico Physical TherapyWake Forest, NC, United States
Full-time +1

Position Overview About Us: At Athletico, we believe in the power of support - because a little help can lead to extraordinary achievements.Physical therapy isn't just about recovery; it's about ... Show more

 • Promoted

Sr Manager Cloud Security Operations

LenovoRaleigh, NC, United States
Full-time

Why Work at LenovoHere at Lenovo, we believe in smarter technology for all, so we spend our time building a society that's brighter and more inclusive.We're not just a Fortune 500 company, we're on... Show more

 • Promoted

Border Patrol Agent (BPA) Experienced - New Hire Sign-On and Retention Incentives

U.S. Customs and Border ProtectionWake Forest, NC, US
Full-time

Border Patrol Agent (BPA) – in the Federal Security and Public Safety Sector Experienced (GL-9 GS-11).You love protecting your community and doing your part to keep our nation safe.But maybe you’re... Show more