Overview
Skills
Job Details
Primary Duties:
• Deliver secure code review assessment on programming languages such as Java, C#, JavaScript & SQL
• Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques
• Train and assist developers in writing secure software and remediating existing vulnerabilities
• Develop and review custom vulnerability description, business impact and remediation content
• Develop, research and recommend open source tools assisting in secure code review
• Contribute to development and delivery of secure coding and remediation training
• Mentor and assist team members in effectively delivering assessments and enhancing skillsets
• Recommend best practices to integrate and automate application security testing in SDLC
Basic Qualifications:
• 3+ years of experience in application security including secure code review, web application penetration testing or threat modelling
• 2+ years of experience in secure code review / static application security testing
• Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code
• Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience