IAM Engineer (ASM - Attack Surface Management - Scanning) L2

Hybrid in Barker, NY, US • Posted 1 day ago • Updated 1 day ago
Contract W2
12 Months
No Travel Required
Able to Sponsor
On-site
$35 - $45/hr
Fitment

Dice Job Match Score™

✨ Finding the perfect fit...

Job Details

Skills

  • Application Service Management
  • Oracle ASM
  • PCI DSS
  • Penetration Testing
  • Python
  • JavaScript
  • Management
  • Microsoft Azure
  • Nessus
  • OSCP
  • OWASP
  • Good Clinical Practice
  • Google Cloud Platform
  • HIPAA
  • ISO 9000
  • Java
  • Continuous Delivery
  • Continuous Integration
  • Data Link Layer
  • DevOps
  • Certified Ethical Hacker
  • Cloud Security
  • Collaboration
  • Qualys
  • Regulatory Compliance
  • Authentication
  • Bash
  • Burp Suite
  • C#
  • CISA
  • Software Security
  • Testing
  • Vulnerability Management
  • Vulnerability Scanning
  • Cloud Computing
  • Reporting
  • SANS
  • SQL
  • Scripting
  • Security QA
  • Web Application Security
  • Web Applications
  • Windows PowerShell

Summary

KEY RESPONSIBILITIES AND DUTIES:

  • Lead the end-to-end vulnerability management lifecycle, including discovery, assessment, validation, prioritization, remediation coordination, and verification.
  • Conduct vulnerability assessments across infrastructure, web applications, cloud environments (AWS, Azure, Google Cloud Platform), and containerized platforms.
  • Perform Dynamic Application Security Testing (DAST) and manual validation of security vulnerabilities.
  • Analyze and prioritize vulnerabilities using CVSS, EPSS, CISA advisories, exploit intelligence, and business risk.
  • Manage and optimize vulnerability scanning tools, asset discovery processes, and reporting mechanisms.
  • Collaborate with Infrastructure, DevOps, Engineering, Cloud, and Security teams to drive remediation efforts.

 

"MUST HAVE" SPECIFIC KNOWLEDGE AND SKILLS:

  • 5+ years of experience in Vulnerability Management, Application Security, or Penetration Testing.
  • Hands-on experience with vulnerability management tools such as Tenable (NessVMDR), Wiz, Qualys, Rapid7, Burp Suite, OWASP ZAP, Checkmarx, Veracode, and Insight AppSec.
  • Strong knowledge of OWASP Top 10, SANS Top 25, CVSS, EPSS, and CISA vulnerability prioritization frameworks.
  • Experience identifying, validating, and remediating vulnerabilities across web applications, networks, systems, and cloud environments.
  • Proficiency in web application security testing, including SQL Injection (SQLi), Cross-Site Scripting (XSS), CSRF,
  • SSRF, IDOR, and Authentication Bypass testing.
  • Experience with cloud security assessments in AWS, Azure, and/or Google Cloud Platform.

 

ADDITIONAL SKILLS AND OTHER REQUIREMENTS:

  • Certifications such as OSCP, GWAPT, CEH, CSSLP, or equivalent.
  • Experience with penetration testing and application security architecture reviews.
  • Knowledge of compliance frameworks including PCI DSS, GDPR, HIPAA, CIS, NIST, and ISO standards.
  • Experience with external attack surface management and third-party risk tools such as Shodan, SSLScan,
  • SecurityScorecard, and BitSight.
  • Knowledge of container security and cloud-native vulnerability scanning.
  • Experience integrating security testing and vulnerability management into CI/CD pipelines.
  • Scripting/programming skills in Python, PowerShell, Bash, JavaScript, Java, or C#.
  • Ability to drive remediation SLAs, vulnerability governance, and executive reporting initiatives.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91138713
  • Position Id: 8996978
  • Posted 1 day ago
Contact the job poster
SR

Suneetha Reddy

Recruiter @ V-Work Infotech Solutions INC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

9d ago

Easy Apply

Contract

$45 - $47

Remote

Today

Full-time

USD 106,000.00 - 130,000.00 per year

Remote

Today

Full-time

Remote or North Carolina

Today

Full-time

USD 48.62 per hour

Search all similar jobs