Today
Dept of Homeland Security
Unspecified
Unspecified
IT - Security
Westlake, TX (On-Site/Office)
Description:
** Hybrid on-site - Westlake, TX ** (One week on-site, one week remote)
The mission of the Secure Software Development Lifecycle (SSDLC) team is to protect Our Investment Management client's assets and their customers' livelihoods from the threat of exploitation by malicious adversaries.
The SSDLC team does this by providing secure software development training, static and dynamic application scanning, software composition analysis and secrets scanning tooling services aimed at preventing vulnerabilities from being introduced into code and ensuring that deployed code is scanned routinely and identified vulnerabilities are addressed, working with the software development teams in a positive, collaborative, and innovative manner.
Due to client requirement, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $55 - $60 / hr. w2
Responsibilities:
The Purpose of Your Role
Support the broad Investment Management Company business via execution of security scan execution, analysis and review.
Using our security champions program, collaborate with key business units to promote and embed standard methodologies for security within their team's development processes
Stay current on security standard methodologies and vulnerabilities.
The Value You Deliver
Our client provides key financial services to a wide variety of demographics. In many instances they are managing their customers financial future and savings. This is something they take very seriously. Protecting their customers and their data is of paramount importance. This role plays a key part in helping to protect the livelihoods of their customers around the world and plays a significant part in preventing real-world cyberattacks.
Experience Requirements:
The Skills You Bring
Education Requirements:
** Hybrid on-site - Westlake, TX ** (One week on-site, one week remote)
The mission of the Secure Software Development Lifecycle (SSDLC) team is to protect Our Investment Management client's assets and their customers' livelihoods from the threat of exploitation by malicious adversaries.
The SSDLC team does this by providing secure software development training, static and dynamic application scanning, software composition analysis and secrets scanning tooling services aimed at preventing vulnerabilities from being introduced into code and ensuring that deployed code is scanned routinely and identified vulnerabilities are addressed, working with the software development teams in a positive, collaborative, and innovative manner.
Due to client requirement, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $55 - $60 / hr. w2
Responsibilities:
The Purpose of Your Role
Support the broad Investment Management Company business via execution of security scan execution, analysis and review.
Using our security champions program, collaborate with key business units to promote and embed standard methodologies for security within their team's development processes
Stay current on security standard methodologies and vulnerabilities.
The Value You Deliver
Our client provides key financial services to a wide variety of demographics. In many instances they are managing their customers financial future and savings. This is something they take very seriously. Protecting their customers and their data is of paramount importance. This role plays a key part in helping to protect the livelihoods of their customers around the world and plays a significant part in preventing real-world cyberattacks.
Experience Requirements:
- 5+ years of IT experience with at least 2 of these being in a hands-on application security role
- Strong understanding of common application security vulnerabilities such as the OWASP Top 10 for Web, API and Mobile applications
- Intermediate development experience with a language such as Java, .Net or Node.js would be advantageous
- Experience working within an Agile development or DevOps/DevSecOps team would be a plus
- Preferred: Experience using a SAST / DAST assessment tool
- Preferred: Hands-on industry security certification such as eLearnSecurity, Portswigger, Offensive Security, CSSLP, AWS/Azure, SANS
The Skills You Bring
- Working knowledge of secrets management and remediation
- Understanding of OWASP Top 10
- Strong knowledge of application security mechanisms such as authentication and authorization techniques, data validation, and the proper use of encryption
- Technical knowledge of, and the ability to recognize, various types of application security vulnerabilities
- Experience with SAST and DAST tools
- Intermediate knowledge of a programming or scripting language such as C, C#, Python, Objective C, Java, Javascript, SQL,
- Proven analytical and problem-solving skills, as well as the desire to assist others in solving issues
- Excellent interpersonal skills with a strong interest in the application security domain
- Excellent communication and presentation skills and a proven ability to communicate threats and facilitate progress towards long-term remediation
- Highly motivated with the willingness to take ownership / responsibility for their work and the ability to work alone or as part of a team.
Education Requirements:
- Bachelor's degree or equivalent experience
group id: 10106647