Request Technology, LLC

Senior Application Security Engineer

Request Technology, LLC 美国 伊利诺伊州 芝加哥

保存

直接发消息给Request Technology, LLC的职位发布者

Senior Engineer – Application Security

Salary: Open + Bonus

Location: Chicago, IL / Dallas, TX

Hybrid: 3 days onsite, 2 days remote

*We are unable to provide sponsorship for this role*


Qualifications

  • Bachelor’s degree
  • 3+ Years’ strong proficiency in network and application penetration testing.
  • Strong proficiency with common penetration testing tools (Kali, Armitage, Metasploit, Cobalt Strike, Nmap, Qualys, Nessus, Burp Suite, Wireshark etc.).
  • Strong experience with database security testing (MSSQL, DB2, MySQL, etc.).
  • Experience testing in commercial cloud environments (AWS, Azure, GCP, IaaS/PaaS/SaaS).
  • 5+ Years’ experience in Information Assurance or Information Security environment.
  • Strong experience with custom scripting (python, C++, PowerShell, bash, etc.) and process automation.
  • Experience writing scripts and working with containers in a CI/CD pipeline
  • Experience with CI/CD pipelines and software development/coding: Docker, Jenkins, GitHub, SVN, Terraform, and others.
  • Ability to understand and modify code in a diverse range of programming languages and frameworks.
  • Familiarity with application frameworks and their built-in security services and API’s (i.e., Sun J2EE, MS .NET, OMG CORBA, Spring, etc.)
  • Good understanding of regulatory standards including CSF, NIST, PCI, SSAE 16, SAS 70, HIPPA, FIPS 199, COBIT 5 and others as needed.


Responsibilities

  • Application Security Testing
  • Perform retests of vulnerabilities to verify previous findings have been remediated.
  • Review reports of the testing and conduct security risk assessments of the vulnerabilities.
  • The use and maintenance of cloud and self-managed security scanning tools, manual source code reviews, and manual penetration assessments.
  • Conduct code scans using automated tools and risk rate the vulnerabilities according to the organization risk profile and mitigating controls.
  • Conduct IT/Security code review meetings to eliminate false positives and encourage collaboration between Security and IT development teams.
  • Assist with application security vulnerability management including implementation of new vulnerability management tools.
  • Setup Command & Control C2 Infrastructure.
  • Understand vulnerabilities and develop relevant payloads for use during pen testing activities.
  • 职位级别

    中高级
  • 职位性质

    全职
  • 职能类别

    信息技术
  • 所属行业

    信息技术和服务

找人内推,获得Request Technology, LLC面试的机会可以提高 2 倍

找找认识的领英会员
新职位发布时接收通知。

相似职位

看过本页的会员还看了

相似搜索

查看协作文章

我们将以全新的方式解锁社区知识。专家直接在借助人工智能撰写的文章中添加见解。

查看更多