Sr. Application Security Engineer

Bridge Technologies and Solutions

San Francisco (CA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading tech firm in San Francisco is seeking an experienced professional to manage and enhance their Vulnerability Management Program. The ideal candidate will have 5-7 years of experience in application security, a thorough understanding of security vulnerabilities, and hands-on experience with commercial scanning tools. Essential skills include strong problem-solving abilities, excellent communication, and knowledge in programming languages such as C#, Java, or Python. The role involves ensuring secure software development practices and potentially overseeing remediation efforts.

Qualifications

  • 5-7 years of experience in security, ideally in application security.
  • Experience with certifications like CISSP, CEH, GWAPT, GPEN, OSCP.
  • Demonstrated understanding of vulnerability remediation.

Skills

Experience with application scanning tools (e.g., Acunetix, IBM's AppScan)
Understanding of Web Services technologies (XML, SOAP, AJAX)
Web Server configuration knowledge (Microsoft IIS, Apache HTTP Server)
Experience in application level attacks and bypassing firewalls
Secure code review experience
Software Engineering experience
Knowledge of OWASP Top 10
Familiarity with malicious code identification
Understanding of advanced cryptographic concepts

Job description

We need a resource who has experience working within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience.

  • Experience with any of the following commercial application scanning tools such as Acunetix, IBM's AppScan, Client's WebInspect, NTOSpider, Cenzic's Hailstorm, Burp Suite Professional
  • Understanding of Web Services technologies such as XML, SOAP, and AJAX
  • Understanding of various web application frameworks such as ASP.NET, J2EE, Zend
  • Web Server configuration knowledge: Microsoft IIS, Apache HTTP Server, Apache Tomcat
  • Experience in application level attacks, bypassing firewalls, evading intrusion detection
  • Experience building automated tool sets or expanding existing toolset libraries
  • Secure code review experience using automated toolsets
  • Software Engineering career experience
  • Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP
  • Thorough understanding of software vulnerabilities
  • Knowledge of OWASP Top 10, SANS Top 25, CWE, WASC
  • Ability to demonstrate understanding of vulnerability remediation
  • Familiarity with malicious code identification and common hacker attack techniques
  • Ability to research and reproduce vulnerability exploitation
  • Understanding of advanced cryptographic concepts.
  • Ability to demonstrate manual testing experience including all of OWASP Top 10.
Qualifications

Skills Required

  • Excellent problem solving and analytical skills
  • Superior oral and technical writing communication skills
  • Independence, self-managed, and motivated
  • Knowledge of the Software Development Lifecycle in an enterprise environment
  • Programming experience in two of the following languages: C#, Java, Python, Ruby
Additional Information

All your information will be kept confidential according to EEO guidelines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • Montvale (NJ)

On-site
USD 80,000 - 110,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • Cherry Hills Village (CO)

On-site
USD 80,000 - 110,000
Security Engineer
Security Engineer

Veriipro • Seattle (WA)

On-site
USD 90,000 - 130,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Application Offensive Security Consultant
Application Offensive Security Consultant

StaffWorthy • Jersey City (NJ)

On-site
USD 90,000 - 120,000
Jr. Penetration Tester
Jr. Penetration Tester

vTech Solution, Inc. • Augusta (ME)

On-site
USD 70,000 - 90,000
Application Security
Application Security

Sonsoft Inc • Exton (PA)

On-site
USD 90,000 - 120,000
Application Security
Application Security

Infojini Inc • Bethesda (MD)

On-site
USD 90,000 - 120,000
Application Security Engineer
Application Security Engineer

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
APPLICATION SECURITY MANAGING CONSULTANT
APPLICATION SECURITY MANAGING CONSULTANT

Target Labs, Inc • Jersey City (NJ)

On-site
USD 110,000 - 150,000