ITSecurityAuditor

JPC TECHNO INC

Dimondale (MI)

On-site

USD 90,000 - 140,000

Full time

13 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

JPC TECHNO INC in Dimondale, MI seeks a Senior Full Stack Application Development Security Auditor to reinforce secure coding across frontend, backend and cloud environments.

You will lead security pattern implementation with automated checks, work with software teams on secure DevOps, and drive continuous risk reduction through dynamic, static and software composition analysis.

Onsite presence is required; candidates must reside near the Dimondale area to be considered for this onsite position.

Qualifications

  • Minimum 5+ years of IT-related security experience.
  • Experience with application security scanning and secure coding practices.
  • Ability to explain in detail OWASP top 10 vulnerabilities and mitigations.
  • Experience with securing web and RESTful APIs and modern stacks.

Responsibilities

  • Senior Full Stack Application Development Security Auditor focused on secure platforms and applications through Dynamic, Static, and Software Composition Analysis assessments.
  • Collaborate with software development teams; not a SOC role, but security-focused support for secure coding practices.
  • Lead security pattern implementation with orchestration and automation to verify configuration, compliance, and authorization of systems.
  • Partner with distributed teams to mature the organization's secure software development practices.
  • Drive risk reduction and secure software delivery across front-end, back-end, and cloud environments.

Skills

IT Security auditing
SAST DAST SCA
OWASP Top 10
Web API security
Full stack development
DevSecOps
Cloud security
Troubleshooting
Browser dev tools

Education

B.S. in CS or related field

Tools

Coverity
BlackDuck
Fortify

Job description

Only qualified IT Security Auditor candidates located near the Dimondale MI area to be considered due to the position requiring an onsite presence

REQUIRED EXPERIENCE KNOWLEDGE ABILITIES AND SKILLS:
  • Experience with Application Security scanning tools (SAST DAST SCA ASOC Container/Cloud) a must
  • HTTP Request/Response headers for web and Restful API calls
  • Ability to explain in detail any of the OWASP top 10 vulnerabilities
  • Cross Site Scripting Injection attacks SSRF CSRF XML entity etc
  • Minimum of 5+ years of total IT related experience
  • Implementing/utilizing Federal Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10 SANS CERT CWE Top 25 Critical Security Controls Cloud Security Alliance SafeCode etc) (3+ years)
  • Both compiled and interpreted languages such as Angular React Nodejs Java Spring Boot IBM WebSphere App server Oracle JBoss NET stacks (3+ years)
  • Networking infrastructure secure application development and security automation (DevSecOps) (3+ years)
  • Hands-on knowledge building and deploying secure complex distributed web and mobile applications (3+ years)
  • Chrome/Firefox/Edge Development tools to see the request/response headers
PREFERRED EXPERIENCE KNOWLEDGE ABILITIES AND SKILLS:
  • Experience with Coverity BlackDuck SRM Fortify a plus
  • High-level understanding of containers
JOB RESPONSIBILITIES:
  • Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic Static and Software Composition Analysis assessments
  • This position is not a member of the Security Operations Center rather it is dedicated to working with software development teams on secure coding practices
  • The ideal candidate will feel comfortable working with both front-end back-end and cloud-based application developers
  • Partnering with distributed teams to help transform the way systems are built secured authorized and securely operated for continuous compliance and risk mitigation
  • Specifically this candidate will help lead efforts to implement security patterns and practices with orchestration and automation tools that automate the secure configuration verification compliance and authorization of systems and their development
  • They will be a key member of a team tasked with maturing the organization's secure software development practices
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Auditor
IT Security Auditor

Stafford Gray • Lansing (MI)

On-site
USD 110,000 - 160,000
IT Security Auditor
IT Security Auditor

The Stafford Gray Group • Lansing (MI)

On-site
USD 110,000 - 160,000
IT Security Auditor
IT Security Auditor

Stafford Gray • Town of Lansing (NY)

On-site
USD 120,000 - 160,000
Full Stack Application Security Auditor
Full Stack Application Security Auditor

IO Datasphere • Dimondale (MI)

Hybrid
USD 120,000 - 180,000
IT Manager - Lansing Area
IT Manager - Lansing Area

The Pivot Group • Lansing (MI)

On-site
USD 81,000 - 99,000
Full Stack Application Security Auditor - DTMB-CIP
Full Stack Application Security Auditor - DTMB-CIP

I O DATASPHERE • Michigan

Hybrid
USD 90,000 - 130,000
Application Development Security Auditor - Dimondale, MI
Application Development Security Auditor - Dimondale, MI

Digital Technology International • Dimondale (MI)

On-site
USD 120,000 - 150,000
Competitive salary
IT Security Auditor
IT Security Auditor

Aroha Technologies, Inc • Dimondale (MI)

Hybrid
USD 110,000 - 150,000
IT Security Auditor(Local to MI)
IT Security Auditor(Local to MI)

American business solutions inc • Dimondale (MI)

On-site
USD 120,000 - 170,000
IT Security Auditor
IT Security Auditor

Jobtailor • Missouri

On-site
USD 120,000 - 180,000