A tech security company in the United Kingdom is seeking a candidate with expertise in secure coding practices. The role involves performing secure code reviews and conducting penetration tests to identify vulnerabilities such as broken access control and SQL injection. Candidates should have strong experience in software engineering or security operations with a focus on application-layer security. Collaboration with development teams to enhance the overall security environment is essential.
Qualifications
Strong relevant experience in software engineering or security operations focused on application-layer security.
Expertise in secure code review and professional penetration testing.
Familiarity with OWASP Top 10, CWE, and modern vulnerability classes.
Responsibilities
Perform expert-level secure code reviews.
Identify, triage, and remediate application-layer vulnerabilities.
Conduct and document penetration tests.
Skills
Secure code review expertise
Penetration testing
Understanding of OWASP Top 10
Application-layer security
Job description
Perform expert-level secure code reviews focusing on OWASP Top 10 and CWE vulnerability classes.
Identify, triage, and remediate application-layer vulnerabilities, including broken access control and SQL injection.
Conduct and document penetration tests, collaborating with teams to drive remediation initiatives.
Advise development teams on secure coding practices to enhance security throughout the software lifecycle.
Stay informed of emerging threats and incorporate best practices within the customer's environments.
Requirements
Have strong relevant experience in software engineering or security operations with a focus on application-layer security.
Have expertise in secure code review and professional penetration testing.
Possess strong familiarity with OWASP Top 10, CWE, and modern vulnerability classes.
Have a proven ability to detect, prioritize, and remediate vulnerabilities in production applications.