Application Security Engineer, Senior

Application Security Engineer, Senior
EMW, Inc., United States

Experience
1 Year
Salary
0 - 0
Job Type
Job Shift
Job Category
Traveling
No
Career Level
Telecommute
No
Qualification
As mentioned in job details
Total Vacancies
1 Job
Posted on
Aug 6, 2022
Last Date
Sep 6, 2022
Location(s)

Job Description

  • Provide cybersecurity guidance and direction in the design, development and implementation of automated solutions, based on a set of standards and processes that enable CI/CD developers to easily apply cybersecurity and compliance services.
  • Responsible for, support of, and coordinating with other Engineers, Architects, and teams in implementing a comprehensive cloud and application cybersecurity program in a DevOps environment.
  • Automate cybersecurity testing using a variety of architectures and cutting-edge technologies.
  • Design, execute, and maintain automated cybersecurity testing for web applications (apps), mobile apps, and application programming interfaces (APIs).
  • Actively review and implement improvements to drive continuous improvement of the efficiency, speed, and quality of the CI/CD DevSecOps environment.
  • Leverage DevSecOps tools to build, harden, maintain and instrument a comprehensive cloud-based cybersecurity orchestration platform to be used in product CI/CD pipelines.
  • Integrate cybersecurity practices across the continuous delivery pipeline to provide a comprehensive automated cloud and application cybersecurity solution.
  • Perform risk and vulnerability assessments of CI/CD IT and IS platforms for authorization; prepare risk assessment reports for submission to the SCA and AO in accordance with DoD, USCYBERCOM, USSOCOM policies, procedures, and regulations.
  • Coordinate, manage and facilitate CI/CD application cybersecurity compliance processes with internal and external stakeholders to provide timely deliverables and rapid remediation.
  • Support the development of standards by creating templates and patterns for ease of use and increase the productivity of the cybersecurity program
  • Foster, and build a community of practice for collective learning of the cybersecurity tools, practices, and systems across all disciplines.
  • Maintain application cybersecurity toolsets used in the development pipelines. Work hand in hand with developer teams to implement testing into their pipelines.
  • Professional curiosity that leads to learning and staying current with business best practices.
  • Work with leadership to identify and revise cybersecurity testing approaches.
  • Able to work on multiple projects and prioritize accordingly.

Requirements

  • Experience with CI/CD DevSecOps integration with tools such as Jenkins, JIRA, GitLab, and Bitbucket Strong experience in cloud and application cybersecurity domains.
  • Experience with OR knowledge of supporting Cloud based platforms (Google, Microsoft, Amazon Web Services (AWS), and Military Cloud (MilCloud))
  • Experience with OR knowledge of Open Containers Initiative (OCI) compliant containers and OpenShift Container Platform technology utilizing Kubernetes orchestration technology.
  • Strong and evolving competence in one or more programming languages and scripting using Python, Personal Homepage (PHP), Just Another Virtual Architecture (JAVA), JAVA Script, Power Business Intelligence (BI) and .Net Core.
  • Experience with container cybersecurity solutions such as Twistlock and Claire to scan for vulnerabilities within OCI containers.
  • Have used source control (github/gitlab) to manage code.
  • Experience working in a Linux or Universal Network Information Exchange (UNIX) based environment.
  • Extensive experience in implementing and enforcing application cybersecurity and vulnerability management.
  • Thorough understanding of release strategies that minimize or eliminate application downtime.
  • Experience with Change Management and Ticketing Systems (Remedy).
  • A good understanding of the Software Development Life Cycle (SDLC) and Agile software development methodology
  • Experience with OR knowledge of the Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs) and NIST regulations
  • Active TS/SCI clearance required.
  • Bachelor’s degree
  • 8+ years relevant experience
  • IAT Level II

Job Specification

Job Rewards and Benefits

EMW, Inc.

Information Technology and Services - Mons, Belgium
© Copyright 2004-2024 Mustakbil.com All Right Reserved.