Source description
About the role
8+ years of experience with auditing web applications.
3+ years using at least one high level programming language e.g. Node.js, Python, Go, Java, Ruby.
Experience utilizing web application security scanning software and penetration testing tools e.g. Burp Suite, ZAP, Nessus, Qualys, Metasploit, CANVAS, Nuclei, Cobalt Strike.
Experience and desire conducting Security training for developers and the security team.
Experience performing threat modeling and secure design review in order to assess the security implications and requirements of new systems and technologies.
Experience building or working with distributed multi-tier web server-client architectures.
Experience with cloud environments AWS or Azure.
Strong foundational understanding of network and application fundamentals and best practices; e.g. HTTP, DNS, VPN, SAML, OAuth, OpenID etc.
Strong understanding of OWASP Top 10 vulnerabilities in web applications, including XSS, SSRF, IDOR, RCE, CSRF vulnerabilities.
Working knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM)
Experience implementing security practices in automated CI/CD pipelines for application code, infrastructure, and/or serverless is a plus.
Strong sense of ownership, urgency and drive.
Strong ability to lead cross-team initiatives and communicate proposals and ideas concisely.
More at FloQast
Related open roles
Senior Performance Engineer
IN · Onsite
SAP Technical Solutions Consultant
Remote · United States
Technical Support Engineer (Integrations)
Los Angeles · Austin · Chicago · Hybrid
Senior Software Engineer, Core Platform
San Francisco Bay Area · Hybrid
Product Manager, Data Integrations
San Francisco Bay Area · Los Angeles · Onsite
Senior Product Manager, SAP
United Kingdom · Hybrid
