Description
Hybrid 4 days on-site, 1 day work from home in St. Louis, MO
Our client seeks a Cloud Application Software Security Engineer to remediate vulnerabilities and mature SDLC pipelines. The role will focus on addressing findings from Mythos, CVE and Known Exploited Vulnerabilities, and open HVA and SA&A assessments. The engineer will collaborate with development and platform teams to reduce risk across custom application code and infrastructure as code in AWS.
Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $75.00 to $85.00/hr. w2
Responsibilities
- Conduct security assessments using scanning tools and implement recommended remediations.
- Evaluate and remediate Known Exploited Vulnerabilities (KEVs) and Common Vulnerabilities and Exposures (CVEs) in custom applications and infrastructure.
- Support Security Assessment and Authorization (SA&A) processes, including documentation and evidence collection.
- Analyze Software Bill of Materials (SBOM) findings to identify vulnerable dependencies and recommend updates or alternatives.
- Review and remediate security vulnerabilities in VB.NET, SQL, and Python code.
- Perform security analysis and hardening of AWS Cloud Development Kit (CDK) infrastructure as code.
- Collaborate with development teams to implement secure coding practices and address identified vulnerabilities.
- Maintain security documentation and track remediation efforts through completion.
- Ensure compliance with federal security standards and frameworks such as NIST, FISMA, and FedRAMP within AWS GovCloud.
- Participate in security scanning automation and continuous monitoring initiatives.
Experience Requirements
- 3 to 5 years in application security or software development with a security focus.
- Proven experience with vulnerability assessment and remediation methodologies.
- Proficiency with Python, SQL, and VB.NET or legacy .NET frameworks.
- Experience with AWS CDK or similar IaC tools such as Terraform or CloudFormation.
- Hands-on experience in AWS environments, preferably AWS GovCloud.
- Experience with AWS security services such as GuardDuty, Security Hub, Inspector, and Config.
- Understanding of CVE and KEV identification and remediation processes.
- Knowledge of SBOM generation and analysis.
- Experience with SAST, DAST, and penetration testing.
- Strong analytical and problem-solving skills.
- Strong written and verbal communication skills.
- Preferred: Security certifications such as CISSP, CEH, GIAC GSEC, or AWS Security Specialty. Knowledge of container security, CI/CD pipeline security, DevSecOps practices, SSDLC, and zero trust principles.
Education Requirements
Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field, or equivalent work experience.