jobholds
Application Security Engineer
كولومبيا
•
تاريخ النشر: 2022-04-08
•
129 مشاهدة
تفاصيل ومتطلبات الوظيفة
<b>Job Summary</b><br> <br> The Application Security Engineer will be in charge of assessing the security of different types of applications developed by Schlumberger teams or acquired from 3 rd party vendors. Work with company development teams or vendors to detect, prioritize and remediate security flaws within the applications. Collaborate with IT and the business to identify and implement appropriate software development related security controls. Strives to develop a security-oriented mindset throughout the application development cycle from concept phase through testing and implementation. The engineer will be required to analyze various data security, authentication/authorization, encryption, application level security and auditing requirements and recommend security mitigations and solutions that integrate with the business.<br><br><b> Reporting</b><br> <br> Reports to the Application Security Manager based in Houston<br><br>Key responsibilities <ul> <li> Perform application security assessment for web, mobile, cloud, thick client, IoT and O365 applications</li> <li> Perform different types of application security assessments as needed; this involves application penetration testing, network penetration testing, attack surface evaluation, threat modelling and security design reviews</li> <li> Perform web services (APIs) penetration testing and analyze communications between client and servers</li> <li> Perform manual penetration testing of applications using appropriate tools and techniques to uncover critical security vulnerabilities in the software, the infrastructure, the configuration and business logic</li> <li> Check separation of duties and access controls, review accounts management and check SSL certificates</li> <li> Perform risk analysis and define prevention and mitigation controls for application vulnerabilities</li> <li> Explain all vulnerabilities and weaknesses in the OWASP Top 10, WASC TCv2, and CWE 25 to application development teams or application vendor, and discuss effective defensive techniques</li> <li> Provide mitigation strategies for applications from infrastructure, architecture and secure coding perspectives.</li> <li> Utilize application security scanning tools, interpret reports and validate identified vulnerabilities and associated risks</li> <li> Manage application security assessment requests from multiple locations, plan and prioritize testing activities</li> <li> Collaborate with development teams across multiple locations to prioritize and remediate vulnerabilities throughout the application lifecycle</li> <li> Work with development teams and IT staff to review application code and configuration for possible security risks</li> <li> Write standards, guidelines and best practices related to application security</li> <li> Evaluate/Develop new tools for application security testing</li> <li> Contribute to the DevSecOps program and the automation of security testing as part of CI/CD pipeline</li> <li> Develop training materials and conduct presentations and technical security awareness training for software architects, QA, and IT and development staff as business needs dictate </li> <li> Follows the technical governance (standards, best practices, etc.)</li> <li> Attend industry cybersecurity webinars and conferences related to application security</li> </ul> Qualifications and Requirements Essential qualifications <ul> <li> Bachelor's or Master's Degree (IT, Computer Science, Cybersecurity, Telecommunications, Engineering, etc.)</li> <li> 5 -7 years equivalent experience</li> <li> Professional information security certification (CSSLP, CISM, CEH, CISSP, GPEN, GWAPT, OSCP or similar)</li> <li> Experience with software penetration testing, architectural risk assessment, threat modelling, static code analysis and secure code review</li> <li> Experience with network penetration testing, firewalls configuration, network architecture and security</li> <li> Experience in manual penetration testing of websites, APIs and networks using a variety of tools and technologies</li> <li> Experience in testing network isolation, escalation of privileges, authentication, expanding the attack surface and exploiting vulnerabilities</li> <li> Experience with mobile application security testing on iOS and Android platforms</li> <li> Experience securing applications on a myriad of platforms and languages including Java, .Net, Angular, etc.</li> <li> Experience in OS hardening on Windows and Linux environments</li> <li> Experience with a variety of testing tools, including: HCL AppScan, Burp Pro Suite, Veracode, Qualys Suite, NMAP, Metasploit, Kali Linux, Wireshark and OWASP ZAP.</li> <li> Understanding of common Web Application vulnerabilities like XSS, CSRF, and others.</li> <li> Experience in identifying and resolving false positive findings in assessments</li> <li> Experience in writing scripts using languages such as Bash, Python, Perl and Powershell</li> <li> Knowledge of DevSecOps process to integrate security in each phase of application development lifecycle</li> <li> Firm understanding of networks, operating systems and data-center architecture.</li> <li> Familiarity with cloud technologies (IaaS, PaaS, SaaS, containers) on Google, Azure and AWS environments</li> <li> Working knowledge of MSSQL and Oracle Databases, IIS and Apache Tomcat web servers</li> <li> Project management experience, the ability to plan, manage and maintain a complex list of project tasks</li> <li> Experience performing Red Team, Blue Team Operations is a strong plus.</li> <li> Programming experience and abilities in at least one or more of the top common languages a strong plus</li> </ul> Other Skills and abilities <ul> <li> Ability to work in global distributed setting without supervision</li> <li> Self-driven, Proactive, Systems Thinking</li> <li> Strong organizational, personal discipline and time management skills to manage multiple tasks and changing priorities.</li> </ul> <ul> <li> Demonstrated ability to lead team efforts and to manage and coordinate complex projects</li> <li> Ability to properly handle confidential information and personnel-related matters</li> <li> Understands the business impact of decisions on operations</li> <li> Ability to reconcile competing demands between conflicting interests and priorities</li> <li> Comfortable with defending a position to upper management</li> <li> Demonstrated ability to facilitate coordination and work collaboratively.</li> <li> Demonstrated initiative and resourcefulness with ability to learn, work and lead with limited supervision</li> <li> Strong process-oriented skills for troubleshooting, problem solving and problem resolution</li> <li> Possess sufficient technical knowledge to assure further development of advanced skills in in a relatively short period of time through formal and on the job training</li> <li> Ability to define, document and deploy standards, processes and procedures</li> <li> Ability to work with others to deliver and provide a high level of service</li> <li> Strong communications skills both verbal and written with the ability to talk to both business and technical people</li> <li> High standards, strong attention to detail.</li> <li> Fluency in English</li> <li> Ability to work well with all levels of the company</li> </ul>
وظائف مشابهة قد تهمك
Security Officer
قطر
عرض →
Supervisor de Seguridad
المكسيك
عرض →
Security Officer
المملكة المتحدة
عرض →
Business Security Manager
الهند
عرض →
Principal Security Engineer
السعودية
عرض →
Staff Product Security Analyst - IAM (Industrial Asset Management)
الهند
عرض →
Low Voltage Electrical / Integrated Electronic Security System (
بولندا
عرض →
Security Lead
العراق
عرض →
Application Security Lead
الهند
عرض →
Senior Oracle Application Security Analyst
إيطاليا
عرض →
ملخص الوظيفة
المجال / التصنيف
أمن
الدولة
كولومبيا
نوع الدوام
دوام كامل
إعلان وظيفة موثوق ومعتمد
تم التحقق من بيانات الإعلان لضمان تجربة تقديم آمنة ومباشرة للباحثين عن عمل.