Information Security Analyst/ Application Security W2

Overview

Hybrid
Depends on Experience
Contract - Independent
Contract - W2
Contract - 12 Month(s)
Unable to Provide Sponsorship

Skills

Application Security
AWS
Cloud
Security
IAM Protocols

Job Details

Job Description:

Position Statement:

As Senior Lead Engineer for Application Security Architecture team, you will work closely with application team to help implement security solutions that are tailored to the specific risks facing the organization. You will be an influential technical lead, who will be work across a heavily matrixed global organization to aggressively drive secure discipline for customer and enterprise applications, as well as lead cybersecurity function for critical Hilton platforms. You will play an important role to help manage the compliance of policies and standards as a function of an end-to-end SDLC project lifecycle.

Develop advanced security solutions to meet the requirements of key stakeholders to ensure that solutions are secure, scalable, available, resilient, technically proficient, performance efficient, and fit into overall 
• Create and maintain security architecture strategies, patterns, standards, and guidelines which balance business priorities, information security risks, emerging threats, and best practice security application architecture to ensure the confidentiality, integrity

Qualifications
Please list specific qualifications/experience, knowledge, skills and abilities needed for this position.
• Working knowledge of one or more following technologies: Atlassian Stack, Node.js, react, relay, Graphql and NOSQL database such Couchbase.
• Experience with AWS Cloud environment and cloud security concepts and architecture.
• Experience reviewing application design, software framework, and infrastructure to identify issues. Capable of assessing underlying components (e.g., databases, servers), configuration, and security access controls.
• Experience with static code scan tools (e.g., Fortify, Checkmarx) and dynamic scanning tools (e.g., Burp, Qualys).
• Experience with development CI/CD tools such as Git, Jira, GitLab, or Jenkins.
• Familiarity with container orchestration services, especially Kubernetes.
• At least three years experience and proficient in a one of the public clouds such as AWS, Azure, Google Cloud Platform or Alicloud.
• Experience developing and authoring application security architectures, standards, and guidelines.
• Experience communicating application security requirements and risk to IT teams and business partners.
• Experience reviewing application design, software framework, and infrastructure to identify risks. Capable of assessing underlying components (e.g., databases, servers), configuration, and security access controls.
• Experience with DevSecOps and integrating security tools into a secure CI/CD pipeline.

Required Qualifications

• Minimum Education: BA/BS in Information Technology, Computer Science, Computer Engineering, or equivalent work experience.
• Minimum Years of Experience: 5+ years of experience combined with exposure to product development and web development on J2EE platforms or alternate technology stacks.
• Minimum 3 years of experience working with AWS Cloud technologies or alternate public cloud providers.
• Minimum Years of Experience: 3+ year of product development and web development on J2EE platforms or alternate technology stacks.