Open to Peoria, IL and Dallas, TX as well
NOTES: We're looking for candidates with a coding background and a strong, in-depth understanding of AppSecurity who can coach the development team during the architecture design phase to identify potential security issues.
Role and Overview of the role
Its Application Security Engineer position in the software development team. Candidate will be working with the application team very closely. Main focus is on application security. It's very important that candidate able to educate or communicate the Cybersecurity topics with the development team with the leadership. So it's important that, the candidate who will on board not only technical capable but also able to explain or communicate this situation to different groups of people. Adopting AI capability rapidly. Candidate who is familiar with AI programming, utilizing different AI models, have some experience with AI programming, that will also be a plus. Team actually supports the e-com development group within client. So it's a web development work that they will support. It's a very business revenue driven application. Once have your application external facing there's a lot of potential security concerns coming in.
Top Skills
- Application Security.
- Candidate has some sort of software development experience. So it is much easier to the candidate to engage with the development team at all the stages. (SDLC and Product Development Processes) (Development Experience (Java OR Python OR .Net, OR JS, OR Equivalent)
- Familiar with some concept on how to integrate some of the Cyber Security tools used in software development. Familiar with SAS, DAS, and familiar with the security governance process. familiar with GitHub. (SCA/SAST/DAST)
- Implementation of automation and scripting
- Some experience with AI. (Boarder line hard requirement)
Position’s Contributions to Work Group
As a Lead Cybersecurity Engineer, you will be responsible for understanding and contributing to Security by Design practices, secure application software development lifecycle practices, security testing and assessment, and the integration of Security with DevOps. This role is responsible for security engineering of the cloud (AWS, Azure) environments and vulnerability management of both Infrastructure as Code (IaC) and application development (SAST/DAST). Engineers will spend their time helping development teams identify and track security risks to remediation while embracing concepts of agile delivery and DevOps
Typical task breakdown:
- Security Defect Management - Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. In other words, our security engineers are partners to software engineers who require accurate information on why a vulnerability exists and what they can do about it.
- Engineering Consulting – Serving as a “best friend” to software engineers, architects, product owners, and leaders, provide contextually-aware guidance to help these groups make good decisions, document those decisions and resulting architectures, and navigate relevant review & approval processes (where necessary) when implementing new features and remediating existing issues.
- Tool Enablement - Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process.
- Security Test Onboarding & Management – Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process.
Interaction with team:
- Accountable for a dedicated set of applications to work directly with development teams. Part of a larger security engineering team that sets standards and ways of working for interacting with development teams.
- Security Engineers will help development teams identify security gaps in their applications and services and assist in coming up with solutions to close those gaps and make services compliant to enterprise security requirements.
Education & Experience Required:
- Bachelor’s degree in computer science or a related field with 8+ or more years in information security
- Master’s Degree must have 6+ years’ experience
Technical Skills
(Required)
- Application security expertise understanding vulnerabilities and remediation solutions (OWASP, CWE/CVE, SANS 25)
- Enterprise security architecture
- Threat modeling
- Vulnerability assessment
- SDLC and product development processes
- Identity and access management
- API security
- SCA/SAST/DAST
- Cloud security experience with MS Azure and/or AWS
- Professional certification (CISSP, CCSP, GWAPT, GWEB, AWS SA / Certified Security, etc.)
- Development experience (Java, Python, .Net, JS, or equivalent)
- Implementation of automation and scripting
- AI Fluency is preferred.
- Web services security Desired: Professional information security certification (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB etc) ; Strong understanding and experience with information security technologies
Soft Skills
(Required)
- Excellent written and verbal communications skills; demonstrated ability to communicate highly technical security concepts to non-security audiences
- Ability to coordinate multiple teams in accomplishing process review and improvement