phia, LLCposted about 2 months ago
Full-time - Mid Level
Washington, DC

About the position

phia is seeking an Application Security Engineer with hands-on experience using Veracode for application security testing and vulnerability management. The ideal applicant should be proficient in utilizing Veracode's static and dynamic analysis tools and interpreting scan results, and able to provide clear and actionable remediation guidance. This individual will work with the Federal client to maintain a resilient security posture for highly visible applications. This position allows you to work remotely from anywhere within the United States. U.S. citizenship is required, and able to obtain Public Trust approval.

Responsibilities

  • Collaborate with the federal client and application teams to maintain a robust security posture for high-visibility applications
  • Lead proactive security discussions with development teams to integrate best practices throughout the software development lifecycle
  • Conduct comprehensive application security assessments using dynamic and static testing methodologies
  • Perform threat modeling and security requirements analysis using tools like SD Elements
  • Execute in-depth application penetration testing using industry-standard tools such as Burp Suite
  • Implement and leverage the latest OWASP frameworks to enhance application security
  • Develop and maintain security controls to protect applications, systems, and infrastructure services
  • Provide expert guidance on remediating identified security flaws and vulnerabilities
  • Stay current with evolving security threats and compliance standards to ensure continuous improvement of security measures

Requirements

  • Veracode experience is a must
  • 6+ years of Information Technology experience
  • 3+ years of experience with supporting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Veracode
  • 2+ years of experience with Java, Python, .NET, or C#
  • 3+ years of experience with Burp Suite
  • 3+ years of experience using the design and implementation of enterprise-wide security controls to secure applications, systems, network, or infrastructure services
  • Experience with Eclipse, JDeveloper, including pipeline development, or Visual Studio
  • Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25
  • Knowledge of federal compliance standards, including NIST 800-53, FIPS, or FedRAMP
  • Knowledge of Linux or UNIX environments, including navigating and troubleshooting basic website connectivity issues
  • Ability to obtain a security clearance
  • HS diploma or GED
  • U.S. citizenship and ability to obtain a Public Trust clearance

Nice-to-haves

  • Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field
  • Experience with Interactive Application Security Testing (IAST) tools and methodologies
  • Proficiency with Selenium for automated testing
  • Skill in writing bash scripts for security automation
  • Hands-on experience with OWASP ZAP or Burp Proxy
  • Certifications in application security or related fields (e.g., CSSLP, OSCP, GWAPT)

Benefits

  • Comprehensive medical insurance to include dental and vision
  • Short Term & Long-Term Disability
  • 401k Retirement Savings Plan with Company Match
  • Tuition and Professional Development Assistance
  • Flex Spending Accounts (FSA)
Hard Skills
VeraCode
4
Burp Suite
2
Eclipse
1
Experience API
1
JDeveloper
1
0D5UeCcHOk MgGm2zbH3UscNX
0
15DHfJneZKjrLA qiRPuSwKcUI
0
163pURZkygds D80MjzQFO xipmsCGw
0
2yCYgcsPd hw8iakOFISZ5X zr0wdQLM6
0
4kLsMA2gOKEx R6xWuNEIr
0
7EzhgQP
0
7SwQDzp14 ijVBToL5f
0
ATsaJ9P4o 5j27lQAyO
0
ClvrB h9Qr
0
ENbkejZSTwWf VMdgCQT6bt
0
FDKTk
0
GcKCTB 3Tl5ZSWtN
0
HQt0UnaEFZx6 S48YL0Ay
0
JTknSEjZVsC2 Bh8ZbquGALV
0
NtRSgpZGxhAJ 9wXUFPTC5
0
P032v ypSQnh8KMjz
0
QFEvGkDUp C3uPNwg7rhb9
0
RBnYc
0
U4PxWa
0
Vlq34ubpAJ ZhigD
0
XLNExHhAg
0
YP1KaslqbVfE mFoDnu46Z
0
bMnwvmdPCEK dfAJHzgSu
0
bUVEof9qd hnNaemb7ZYTD
0
bmkCVKFIMxsn OrSbUGcw3
0
doD1HmVSlLEU oHdQGnD01
0
gHNA TEyxkOfFqDoe wGnDgUF2h
0
lobEQzIMY uNZK8P1aUV
0
mdhnWKy5Dlk 5iXEkgoPnfYt
0
o1Zix0APS TC34uKIw
0
pXt0WRFSV xcsKi6GLp7AbHI1
0
qjHLcZ1iSGdF 5DcLVZY0z
0
w7bJEeloN LtjnvIS
0
y5c6gqBxjzvb qf4weth2d 9ounzT8B
0
Soft Skills
ivu8k0tI zurE9IJ7
0
oMR1XIHs yQd2RkAC
0
Build your resume with AI

A Smarter and Faster Way to Build Your Resume

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service