Application Security Engineer
Company: Cornerstone OnDemand
Location: Salt Lake City
Posted on: May 27, 2023
|
|
Job Description:
The Application Security Engineer position is a hands-on role
that involves evaluating and enforcing application security in all
phases of the Software Development Life Cycle (SDLC). This position
will work closely with our engineering teams to define the
application security best practices, perform software architecture
and design reviews, threat modeling, conduct white box security
testing, and support the identification, interpretation, and
remediation of vulnerabilities across a variety of applications,
programming languages, and platforms with a focus on supporting our
GovCloud program.
We are looking for someone with a strong background in information
security and a proven ability to deliver under pressure. Position
is remote and candidates must be willing to collaborate with team
on PST timezone. Requires U.S. Citizenship.
In this role you will---
Participate in architecture and design reviews with senior
Engineering/DevOps staff to incorporate effective security
standards into product design
Design, build & maintain security tools/processes to effectively
secure our cloud-based environments (AWS, GovCloud,GCP)
Implement a program to integrate security into the build/release
pipelines to ensure our code is secure before it goes to
production
Conduct white box security testing to assess and validate
application security---
Define, maintain and enforce application security best
practices---and evaluate application security tools to improve our
detection and prevention capabilities
Monitor and track progress of found vulnerabilities and maintain
the history---
Explain and demonstrate vulnerabilities to application/system
owners, and provide recommendations for mitigation---
Issue reports on assigned application and system scans---
Perform secure code development training to developers, quality
assurance personnel and relevant staff
You've got what it takes if you have---
Ability to obtain a security clearance which requires US
citizenship
Bachelor's degree in an Information Technology related field of
study or equivalent post high school education and/or work-related
experience---
4+ years of experience in web or mobile application security
Experience with STIG and/or CIS
Knowledge of information security principles, web applications, and
a level of familiarity with malicious code and common techniques
used by hackers---
Experience with CI/CD practices and tools (Git, Jenkins) and
integrating security solutions into CI/CD pipelines
Experience working on security responsibilities for a SaaS or PaaS
solutions, preferably running in AWS.
Understanding of SAST, DAST, Pen test and Open source vulnerability
testing
Experience with common SDLC tools: static and dynamic code
analysis, open source management, threat modeling, etc.---
Experience creating solutions in C#, Python, Node.JS, or Go, and
Infrastructure as Code (AWS Cloud Formation)
Experience with HTML and JavaScript along with a solid
understanding of HTTP protocol---
Excellent problem solving and analytical skills; outstanding oral
and written communication skills
Experience coordinating penetration testing activities
Experience interacting with security vendors and customers
Self-motivation and the ability to work under minimal supervision
are a must
Excellent at multitasking, and open to constant learning
Energetic and positive attitude
Demonstrated commitment to valuing diversity and contributing to an
inclusive working and learning environment
Consideration for privacy and security obligations
An extra dose of awesome if you have---
Experience working in AWS GovCloud or FedRAMP environment
Knowledge of microservices architectures
Basic knowledge of SQL and prior experience with programming in one
or more server-side technologies such as ASP.Net. .NET Core or
scripting (Python, Shell)
Thorough understanding of SDLC and software security maturity
models such as Building Security In Maturity Model (BSIMM) or OWASP
Software Assurance Maturity Model (SAMM)
Experience conducting secure code development training---
Knowledge of FIPS 140-2 and cryptographic tools
#LI-ET1
Equal Employment Opportunity has been, and will continue to be, a
fundamental commitment at Cornerstone OnDemand. All qualified
applicants are given consideration regardless of race, color,
gender, age, sexual orientation, national origin, marital status,
citizenship status, disability, veteran status, or any other
protected class as provided in applicable Federal, State, or Local
fair employment laws. If you have a disability or special need that
requires accommodation, please contact us at careers@csod.com
Keywords: Cornerstone OnDemand, Salt Lake City , Application Security Engineer, Engineering , Salt Lake City, Utah
Click
here to apply!
|