Job Description:
RESPONSIBILITIES:
• Support and consult with development and engineering teams in the areas of application security
• Educates development team on security procedure and standards, and ensures they are followed
• Research and help develop security solutions to help secure applications (API Security, Data Protection, Identity Protection)
• Create Security guidance/documentation for development/engineering teams
• Experience working with AWS or other cloud environments (development/architecture)
• Experience with cloud and API security standards (OWASP API Top 10, CIS Top 20)
• Perform security risk assessments for all proposed application-related (APIs) changes.
EXPERIENCE and SKILLS:
• 3+ years of experience in software development in one or more of the following programming languages, .NET, Python, Java/Springboot (REST), JavaScript (Node/React), and/or Go
• Comfortable with tools like Noname/NeoSec/Salt Api security, OWASP ZAP, Veracode, etc.
• 3+ years of experience with API Security
• Experience with API Management solutions like Mulesoft
• Technical and foundational knowledge of software engineering, computer systems, security engineering, authentication, and/or applied cryptography.
• Excellent knowledge of all web technologies, especially web services, web applications, Service Oriented Architectures, and network/web protocols
• Knowledge of application threat modeling, Remediation of OWASP API Top 10, CIS Top 10, SANS Top 25 a plus
• Experience with attacker tactics, techniques, and procedures, and corresponding mitigation methods.
• Sound knowledge of all procedures, standards, and regulations for authorization and authentication, applied cryptography, and security vulnerabilities.