Cyber Security

at Sriven Systems Inc.
Published June 23, 2022
Location Plano, TX
Category Default  
Job Type Full-time  

Description

Hands on Experience/ Primary Duties:  

  1. Cyber Threat modeling and risk assessment
  2. Cybersecurity requirements definition, code review, design guidance for development teams
  3. Cybersecurity testing to include pen testing and formal verification efforts where needed
  4. Deliver secure code review assessment on programming languages such as Java, C#, PHP, Python, Perl, C/C++ , SQL, >
  5. Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques
  6. Train and assist developers in writing secure software and remediating existing vulnerabilities
  7. Develop and review custom vulnerability description, business impact and remediation content
  8. Develop, research and recommend open-source tools assisting in secure code review
  9. Contribute to development and delivery of secure coding and remediation training
  10. Mentor and assist team members in effectively delivering assessments and enhancing skillsets
  11. Recommend best practices to integrate and automate application security testing in SDLC

Basic Qualifications:

  1. 3+ years of experience in application security including secure code review, web application penetration testing or threat modelling
  2. 2+ years of experience in secure code review / static application security testing
  3. Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code
  4. Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience
  5. Bachelor's Degree in Computer Science/ Engineering or equivalent with GPA of 3.0 or higher

Preferred Qualifications:

  1. Experience in detecting, analyzing, and providing recommendation guidance on security vulnerabilities in at least two of the following languages: Java, C#, PHP, Python, Perl, C/C++ , SQL, >
  2. Hands-on experience conducting security focused static analysis using commercial SAST tools such as Checkmarx, Appscan Source, Veracode, Coverity, Fortify and SonarQube
  3. Experience in software development in at least one server-side programming language
  4. Experience in integrating static application security tools in CI/CD environment

Master's degree in Computer Science/ Engineering or equivalent

- provided by Dice

Drop files here browse files ...