SOFTWARE SECURITY ENGINEER

Target Labs, Inc

Rockville (MD)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading tech company is seeking a Software Security Engineer responsible for ensuring software security throughout the application life cycle. The ideal candidate will have experience in assessing security, implementing security controls, and providing guidance on secure software development. If you have a strong background in application security, we invite you to apply and contribute to enhancing our security practices.

Qualifications

  • At least 1 year of experience in software security focused on web-based systems using Java/J2EE and/or C#/ASP/.NET.
  • Hands-on experience evaluating security using manual and automated techniques.
  • Strong written and verbal communication skills.

Responsibilities

  • Evaluate applications for appropriate use of security controls using various tools.
  • Provide guidance on the implementation of application security controls.
  • Participate in research of information security technologies.

Skills

Communication
Software Security Assessment
Security Infrastructure
Security Awareness Training

Education

Bachelor of Science in Computer Science

Tools

Fortify SCA
HP WebInspect
IBM Rational AppScan
BurpSuite
Metasploit
Core Impact

Job description

The Software Security Engineer (SSE) is responsible for supporting the promotion, design, and evaluation of software security in all phases of the application life cycle. The SSE shall ensure that appropriate and effective security techniques and solutions are identified, implemented, and used.

Essential Job Functions:

- Software Security Assessment: Evaluate applications for appropriate and effective use of security controls using tools and techniques such as source code analysis, vulnerability scanners, and manual testing techniques.

- Software Security Control Development: Provide expert guidance to developers on the appropriate selection and implementation of relevant application security controls.

- Security Infrastructure: Support various deployment and integration activities for security considerations associated with enterprise-wide infrastructure and services such as DLP, CMDB, ESB, Identity & Access Management, Network Segregation, Trusted Communications, …

- Security Awareness Training: Design, develop and deliver presentations focused on raising awareness for crucial security relevant considerations and defensive programming techniques.

Other Job Functions:

Participate in research of information security technologies (in the areas of application and application infrastructure components) and propose ideas for new security service development. Participate in all aspects of security service development projects including the following project phases: business case development, requirements gathering, architecture development, product/service selection and procurement, functional & QA testing, detailed technical design, technology infrastructure implementation and deployment, migration from existing services, operational process and procedure documentation, operations staff training, and internal marketing of security services. Advise and consult internal clients on appropriate application of security practices and existing security services to solve problems or enable new business opportunities. Deliver previously developed information security services in support of corporate needs including: requirements gathering, technical design, service deployment and integration, migration, operational transition, end user documentation, user training. In support of various enterprise IT initiatives, recommend, customize, implement, document, and transition to operations reusable technical security service components including application level intrusion detection systems, authentication systems, authorization systems, audit trail management systems, cryptographic systems, and others as defined by management. Research and implement new security technologies to be used as point solutions for IT initiatives unable to take advantage of or needing greater functionality than reusable enterprise security services. Recommend new security service development ideas based on accumulated knowledge of project-specific security requirements.Identify and implement improvements to application security team processes and supporting software tools (Java and C#/ASP based)to continually improve the team’s effectiveness and efficiency.Serve as subject matter expert on application and information security technologies and methodologies.Perform other duties and responsibilities as assigned.

Essential Education/Experience Requirements:

- Bachelor of Science in Computer Science, or equivalent education or experience. Emphasis in software security a plus.

- At least three (1) year of professional experience, including.

- Software development with emphasis on Internet-exposed, multi-tier, web-based systems using Java/J2EE and/or C#/ASP/.NET (experience with both a plus).

- Hands-on experience evaluating the security of applications using both manual and automated techniques. Relevant tool experience should include code security scanners such as Fortify SCA, web vulnerability scanners such as HP WebInspect or IBM Rational AppScan, assessment support tools such as BurpSuite, Metasploit, Core Impact, etc.

- Masters degree may be considered in lieu of experience.

- Strong written and verbal communication skills. Specific relevant experience may include technical reports (especially application security assessment reports), technical whitepapers, presentation development and delivery (for both technical and business audiences), technical training, etc. Candidate should have experience making and defending sound technical arguments that incorporate relevant technical and business considerations, and building consensus among stakeholders.

Other Desirable Experience:

- Security-related experience with the following.

- Providing software architecture security guidance, including developing application threat models and methodically protecting against business logic and design flaws that could introduce security vulnerabilities.

- Web Application Firewalls such as ImpervaSecureSphere.

- Design patterns and coding standards for secure software.

- Secure configuration and operation of Application Servers, Web Servers, Directory Servers, Media/Content Servers, Messaging Servers, Database Servers, and Integration Servers.

- Application authentication & authorization systems such as RSA ClearTrust and NetegritySiteminder.

- Knowledge of cryptographic tool kits for application development such as RSA BSAFE or others.

- Knowledge of and experience with built-in and add-on security capabilities of common application infrastructure components such as MS SQLServer, Oracle, MS IIS, iPlanet Directory, MS Active Directory, MQSeries, MSMQ, MS Exchange.

- Knowledge of general application security API's and protocols such as: MS CryptoAPI, Kerberos, SSL/TLS, SAML, S/MIME, and PKCS API's.

- Knowledge of cryptographic solutions for protection of data in use, in transit and at rest, such as: Masking, SSL/TLS, IPSec, format preserving encryption & sanitization, etc.

- Knowledge of security considerations related to virtualization and cloud computing.

- Mobile Application Security on iOS and/or Android devices; includes experience in secure development of applications and/or analysis.

- Financial services industry (Insurance, Banking, Investments) experience a plus.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

APPLICATION SECURITY ENGINEER
APPLICATION SECURITY ENGINEER

Target Labs, Inc • Rockville (MD)

On-site
USD 100,000 - 130,000
APPLICATION SECURITY RISK MANAGER
APPLICATION SECURITY RISK MANAGER

Target Labs, Inc • Rockville (MD)

On-site
USD 100,000 - 140,000
SECURITY COMPLIANCE ENGINEER
SECURITY COMPLIANCE ENGINEER

Target Labs, Inc • Scottsdale (AZ)

On-site
USD 80,000 - 120,000
Application Security Engineer
Application Security Engineer

Eliassen Group • Washington

On-site
USD 90,000 - 120,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Application Security
Application Security

Infojini Inc • Bethesda (MD)

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

GlobalXperts • Reston (VA)

On-site
USD 70,000 - 100,000
Sr. IT Application Security Engineer (USC or Green Card a must)
Sr. IT Application Security Engineer (USC or Green Card a must)

Creative Solutions Services, LLC • Reston (VA)

Hybrid
USD 108,000 - 180,000
Security Engineer
Security Engineer

RouteOne • Farmington Hills (MI)

On-site
USD 85,000 - 115,000
SECURITY CONSULTANT
SECURITY CONSULTANT

Target Labs, Inc • San Francisco (CA)

On-site
USD 90,000 - 130,000