Location : Tempe, AZ Employment Status : PermanentDepartment : IT and Computer
Job Description
Summary of This Role
Responsibilities include auditing code, architecture, and databases used in custom-developed web and cloud applications. The role involves testing for common application-level vulnerabilities, conducting vulnerability analysis, and providing development advice for application hardening. The applicant must have a strong background in software development, secure coding techniques, secure architecture, software security frameworks, and vulnerability analysis. Experience in securing web and mobile applications, APIs, micro-services, containers, and cloud/hybrid architectures is required.
Responsibilities include :
Collaborate with application development and QA teams to review, evaluate, and prioritize vulnerability findings.Provide SME support on secure code implementation, design, and architecture.Perform threat modeling and risk analysis.Participate in security training sessions.Assist in providing annual OWASP & PCI training for developers.Maintain updated secure coding best practices.Identify and address common application-level vulnerabilities.Conduct risk management activities.Prioritize findings and vulnerabilities.Develop mitigation strategies.Review, validate, recommend, and create security standards and controls.Review open-source libraries for security risks.Develop and implement Web Application Firewall (WAF) rules.Review and recommend security technologies.Requirements
- Bachelor's degree in Computer Science or related field with 6+ years of experience applying information security best practices and 5+ years of software development experience.
- Experience with static and dynamic vulnerability scanning tools and manual code reviews.
- Knowledge of the Top 10 OWASP vulnerabilities and remediation strategies.
- Strong understanding of information security principles and behaviors that secure assets.
- Ability to translate security policies into understandable language for technical and non-technical audiences.
- Excellent problem-solving skills and ability to analyze and resolve security challenges.
- Note: No relocation packages, remote work, or work visa sponsorship available. Candidates must have their own work authorization.
Interested candidates should send their updated CV and answer the following questions:
Have you worked or applied to this company before?What is your distance from the location? Where are you located?What are your salary expectations?Are you a US citizen or green card holder?How many years of experience do you have in this industry?Why are you seeking a new opportunity?#J-18808-Ljbffr