Insight Global

Application Security Engineer

Insight Global 美国 伊利诺伊州 芝加哥

保存

Insight Global提供的薪酬范围

此薪酬范围由Insight Global提供。您的实际薪酬根据您的技能和经验而定 — 跟招聘人员沟通,了解更多信息。

基本薪酬范围

US$140,000.00/年 - US$145,000.00/年

2 days on site in Chicago


Technical Skills

  • 5+ years of experience as a software engineer (in any language or framework)
  • 5+ years of experience as a software development-focused cybersecurity professional
  • 5+ years of experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect.
  • Experience analyzing and remediating security findings from automated and manual sources such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing, Software Composition Analysis (SCA), etc.
  • Experience leveraging one or more of the following resources to support secure coding and decision-making: OWASP Top 10, MITRE Common Weakness Enumeration (CWE) Top 25, OWASP Application Security Verification Standard (ASVS) and Other industry-standard best practice guides or frameworks
  • Experience building or supporting web applications and API’s including Single Page Applications (SPA) and RESTful API’s.
  • Proficiency in one or more programming languages.


Typical task breakdown:

  • Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. (The security engineers are partners to software engineers who require accurate information on why a vulnerability exists and what they can do about it.)
  • Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process.
  • Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process.
  • Consulting with software engineers on practices which will improve their application’s security maturity according to scorecards and maturity models.
  • Authoring, in close partnership with software engineers, correction of error reports which help engineers and architects across avoid similar mistakes in their own applications.

  • 职位级别

    中高级
  • 职位性质

    合同工
  • 职能类别

    信息技术
  • 所属行业

    人才中介

找人内推,获得Insight Global面试的机会可以提高 2 倍

找找认识的领英会员
新职位发布时接收通知。

相似职位

看过本页的会员还看了

相似搜索

查看协作文章

我们将以全新的方式解锁社区知识。专家直接在借助人工智能撰写的文章中添加见解。

查看更多