Role & responsibilities
We are seeking a dedicated CyberSecurity Specialist with expertise in Threat and Vulnerability Management (TVM) to join our team. The ideal candidate will have 7 to 11 years of experience in cybersecurity, focusing on web services testing and security practices. This role involves working in a hybrid model with day shifts, ensuring the security of our digital assets and contributing to the safety of our users.
Responsibilities
- DAST Triage and Vulnerability Assessment Review and triage dynamic application security testing DAST scan results identify, prioritize, and validate vulnerabilities in running applications using CVSS scoring and risk frameworks to determine business impact and recommend remediation strategies False Positive Management Assess and validate false positives from DAST scans using tools such as Burp Suite and Postman working with development teams to understand their application document findings and maintain accuracy of vulnerability data Remediation Support Work with development teams to identify and implement fixes for DAST identified vulnerabilities track remediation efforts and verify resolutions Policy Compliance Support enforcement of application security policies ensure compliance with security requirements for web and API applications Documentation Create vulnerability assessments remediation guidance and knowledge base articles for development teams based on DAST findings processes and identified best practices Tool Management Assist in managing and optimizing enterprise DAST tool maintain tool hygiene and data quality DevOps Integration Support integration of DAST tools within CICD pipelines assist with security gate implementation for DAST testing Cross functional Collaboration Partner with developers DevOps and security teams to embed dynamic testing practices into the SDLC Reporting and Metrics Track and report on DAST vulnerability metrics remediation status and security trends 2 4 years of experience in application security software development or DevOps Strong knowledge of Dynamic Application Security Testing DAST tools and runtime vulnerability management Understanding of vulnerability assessment and prioritization CVSS risk scoring Proficiency in at least one programming language Python Go JavaScript Java or similar Familiarity with SQL and database concepts including querying data manipulation data dashboarding and visualization Familiarity with web application and API fundamentals including HTTP methods error codes request response structures authentication authorization web traffic analysis and the use of browser developer tools eg network tab Experience with vulnerability databases NVD CVE GitHub Advisory or similar Basic understanding of CI CD pipelines and DevOps practices Strong analytical and problem solving skills Excellent written and verbal communication skills Ability to work cross functionally with development and operations teams
Certifications Required
- Experience with additional security scanning tools (SAST, DAST, container scanning) - Knowledge of compliance frameworks (OWASP, CWE, CVSS, SLSA) - Relevant certifications in app security testing