Padmi

Application security engg

PolandPosted 42 months ago
CybersecurityUnspecified
Apply at eTeam

Opens the source posting on www1.jobdiva.co.uk

Source description

About the role

View original

Position Application security engineer (SDLC)

Responsibilities The Application Security Testing function delivers global services and technology capabilities to ensure alignment with the strategy and key investment areas identified in the Application Security space. These include: · Contribute to the protection of Client’s web and mobile applications and information assets, · Ensure proper operation of security testing services and tools, · Define and implement efficient security and compliance controls within CI/CD pipelines to enable agile development efforts, · Define and implement processes for remediation of findings and vulnerabilities identified in security testing · Contribute to the updates of internal standards, policies, processes and learning materials to reflect changes in secure application development space and investment in new tools, A key purpose of this role is to provide support in the areas of application security and secure software engineering practices. It will help drive key technologies and processes in a manner that will further reduce potential risk to Client systems and data. The role will be an advocate for the secure software engineering strategy when interacting with engineering teams across the organisation and support the implementation of security solutions throughout the software engineering lifecycle. This is a collaborative role working across global services and functions, supporting customers from multiple business units and liaising with 3rd party vendors and partners when required.

Specific roles and

responsibilities · Run and support a variety of automated security tools and services embedded throughout the application lifecycle such as Threat Modelling, SCA, SAST, DAST · Onboard development teams · Support users in the use of security tools · Ensure alignment of the tool with the Client standards and policies · Work closely with diverse product and platform teams throughout Client to promote the embedding of security into Software engineering processes · Work with developers, project leads and business customers to explain application security issues and their potential business impact · Deliver the service within the defined SLA, providing an enhanced user experience in the global service line through solutions that are agile, well optimized and cost effective · Suggest service changes and improvements in response to the constantly evolving information security landscape · Propose enhancements of the Client Secure Software Engineering Strategy

Must have

requirements We are looking for professionals with these required skills to achieve our goals: · Proven track record of working in an IT group with experience in application security, threat analysis or vulnerability management, · At least 1 year background in more than one of the following: DevSecOps, web / mobile application development, · Passionate about computer security, willingness to learn new technologies · Excellent communication skills, both written and verbal, to openly convey information relevant to a variety of stakeholders, using their own terminology · Software development experience · Good command of English (B2/C1) Additional Qualifications:

If you have the following characteristics, it would be a plus: · Familiarity with Open Web Application Security Project (OWASP) testing guides and methodologies for web and mobile applications · Familiarity with various categories of security testing tools, e.g. VM scanners, SAST, DAST etc. · Experience of working with 3rd Party vendors · Background in software development (Python / Golang / Java) · Experience with pipeline technologies and automation (Jenkins, Azure DevOps, Chef) · Experience of embedding security into pipelines (SCA, SAST, DAST, SCA, Container Sec) · Experience with container/orchestration tools (Kubernetes, Docker) · Experience with building solutions on cloud platforms (Azure and GCP) · Experience of working in an Agile team (Scrum, VFQ, SAFE)

Job type: Full Time/Contract Division: eTeam Workforce Limited Reference: 23-01177

One address, no account. We’ll tell you when matching roles go live.

More at eTeam

Related open roles

View all roles