Job Description:
Technical Skills
Strong programming experience in Java, .NETC#, Python, Node.js, Go, or C++
Experience with secure coding practices (OWASP Top 10, CWE, SANS Top 25)
Hands-on experience identifying and fixing application security vulnerabilities
Experience with REST APIs, Microservices, and Web Applications
Cloud experience (AWS, Azure, or Google Cloud Platform) with security best practices
Strong understanding of the Secure Software Development Lifecycle (SSDLC) and DevSecOps.
Vulnerability Management Experience
Candidates should have experience with:
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Dependency vulnerability remediation
Threat modeling
Code reviews focused on security
CVE analysis and remediation
Security patching and hardening.
Security Tools
Experience with tools such as:
SonarQube
Checkmarx
Veracode
Fortify
Snyk
Black Duck
Prisma Cloud
Qualys
Burp Suite
OWASP ZAP
GitHub Advanced Security
Jenkins, GitLab CICD, Azure DevOps.
Responsibilities
Develop secure, high-quality code
Review source code for security vulnerabilities
Remediate findings from SASTDASTSCA scans
Integrate security checks into CICD pipelines
Work with security teams to resolve vulnerabilities
Perform root cause analysis of security issues
Ensure compliance with secure coding standards and industry frameworks