Overview:Quantam Solutions provides IT solutions and consulting for various clients. We offer competitive hourly wages, health benefits, paid time off, and a 401(k) plan. We are currently seeking a Senior Application Security Engineer. Candidates must be located within 90 miles of Lansing, MI. Interviews will be held in person in Lansing, MI. There is no option for a video interview. The work schedule is hybrid with two days onsite in Lansing, MI and three days remote. There is no option for a fully remote work schedule.
Job DescriptionOur client is seeking a
Senior Application Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic Application Security Testing, Static Application Security Testing, and Software Composition Analysis assessments.
This position is not part of the Security Operations Center. The role is dedicated to working with software development teams on secure coding practices and requires experience working with front-end, back-end, and cloud-based application developers.
The Senior Application Security Auditor will partner with distributed teams to help improve the way systems are built, secured, authorized, and securely operated for continuous compliance and risk mitigation. This role will also help lead efforts to implement security patterns and practices using orchestration and automation tools that support secure configuration, verification, compliance, and authorization of systems and their development.
Key Responsibilities - Partner with software development teams to support secure coding practices.
- Work with front-end, back-end, and cloud-based application developers.
- Support Dynamic, Static, and Software Composition Analysis assessments.
- Help implement security patterns and practices using orchestration and automation tools.
- Support secure configuration, verification, compliance, and authorization of systems and their development.
- Help mature the organization's secure software development practices.
- Review HTTP request and response headers for web and RESTful API calls.
- Assess application security risks and vulnerabilities.
- Support secure application development and security automation/DevSecOps practices.
Required Skills and Experience - Minimum of 5+ years of total IT-related experience.
- 3+ years of experience implementing or utilizing federal, industry, and open-source security guidance and secure coding practices, including OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, and SafeCode.
- 3+ years of experience with compiled and interpreted languages and technologies such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere Application Server, Oracle JBoss, and .NET stacks.
- 3+ years of experience with networking, infrastructure, secure application development, and security automation/DevSecOps.
- 3+ years of hands-on experience building and deploying secure, complex distributed web and mobile applications.
- Experience with Application Security scanning tools, including SAST, DAST, SCA, ASOC, and Container/Cloud tools.
- Experience using Chrome, Firefox, and Edge development tools to review request and response headers.
- Strong understanding of HTTP request and response headers for web and RESTful API calls.
- Ability to explain OWASP Top 10 vulnerabilities in detail.
- Knowledge of Cross-Site Scripting, injection attacks, SSRF, CSRF, XML Entity vulnerabilities, and related application security risks.
- Knowledge of API Security.
- Knowledge of JWT.
- Knowledge of OAuth, OIDC, and PKCE.
- Knowledge of web and API replay attacks.
- High-level understanding of containers.
- Cloud development experience with Azure, AWS, or Google Cloud Platform.
- Ability to pass a CJIS background check.
Preferred Skills - Experience with Coverity, Black Duck, SRM, or Fortify.
Skills:innovation,programming languages,java,leadership,c sharp (programming language),analysis,database,consulting,testing,articulate,git,vulnerability management,decision-making,aws,burp suite,sql,windows,cissp,equities