1. Security Engineer works on defining security frameworks for existing and new systems.
2. Represents the IT security team for enterprise projects during development phases like architecture/design review, providing IT security consulting and recommendations, to ensure the implementation of a secure application design.
3. Responsible for supporting the implementation and enforcement of secure application design principles
4. Responsible for explaining and demonstrating vulnerabilities to application/system owners, and provide recommendations for mitigation.
5. Responsible for defining and designing security code analysis tools and framework, Performing code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices.
6. Provides direction and support in security management and security architecture standards and documentations.
7. Provides fault resolution and escalation advice.
8. Responsible for defining processes to manage and enforce application security.
9. Conducts active penetration tests; discover vulnerabilities in information systems.
10. Participate in IT security compliance and audit efforts (eg PCI DSS )
• College degree (relevant field) or equivalent experience; 3-5 years of work experience.
• 2+ years of experience in web application development in .NET, Java EE, and SQL
• 1+ years of experience in web or mobile application security preferred
• HTTP protocol knowledge required
• Knowledge of authentication mechanisms like SAML, OAuth etc. along with web service security protocols for SOAP such as WS-Security are nice to have
• Knowledge of information security principles, web applications and a level of familiarity with malicious code and common techniques used by hackers
• Experience with application security code review practices / static analysis and methods, such as OWASP Top Ten
• Detailed knowledge and understanding of the Payment Card Industry (PCI) data security standards (PCI DSS) as well as experience in the implementation of controls to mitigate PCI issues
• Experience with Application Security Firewalls, F5’ ASM / Citrix’s Teros etc are desirable
• Experience in creating, maintaining, and executing Incident Response Plans
• Strong interpersonal and communications skills along with strong customer service skills
• Strong programming background with: JavaScript, JSP, PHP, ASP.Net strongly preferred
• Knowledge of Security Flaws and its Resolution as listed in sites like OWASP, SANS etc.
• Knowledge and understanding of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, DNS, LTM, GTM) preferred
• Experience in technical security countermeasures, risk management, contingency planning, and data communications networking preferred
All your information will be kept confidential according to EEO guidelines.
http://www.eliassen.com/consulting-services-consultant/agile-consulting-services
Job details are sourced from the employer's original posting.
Open job postingAbout the company
Eliassen Group is all about connecting highly skilled people who have the desire and ability to contribute to helping our clients successfully address the many challenges that arise in the course of running their businesses. We have decades of experience and continuity in our own staff that allow us to really know our clients and the consultants we provide; creating good culture and skill fits for both. Please visit us at www.eliassen.com for more information.