-
Location:
Jersey City
-
Job type:
-
Job ref:
895730
-
Published:
11 months ago
-
Expiry date:
12/04/2023
-
Startdate:
ASAP
Position: Application Security Engineer
Location: Jersey City, NJ
Duration: CTH
The Application Offensive Security Consultant-Secure Code Reviewer is responsible for providing technical direction and performing secure code review on applications. The person in this role should possess good understanding of application security vulnerabilities, secure coding, software development life cycle (SDLC), offensive security methodology and SAST/DAST.
Your Primary Responsibilities:
- Perform Manual Secure Code Review against applications.
- Analyze and identify vulnerabilities in source code using manual analysis techniques.
- Coordinate with application development teams to collect the application details.
- Provide the vulnerability information in the predefined report format after performing the testing using manual methodology
- Assist the developers and business teams in detailing the vulnerabilities reported along with the recommendations for remediation
- Align risk and control processes into day-to-day responsibilities to monitor and mitigate risk; escalates appropriately
- Generate reports on assessment findings and summarizes to facilitate remediation, document technical issues identified during security assessments
- Perform threat modeling, design, and code views to assess security implications and requirements
- Be a subject matter expert and respond to any security engineering questions/ requests related to Application Defense enhancements
- Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality product.
Qualifications:
- Minimum of 3+ years of experience in secure code review
- Minimum of 5+ years in application security
- Experience in performing manual secure code review
- Bachelors Degree and/or equivalent experience
Talents needed for Success:
- Minimum of 5 years of experience in application security
- Minimum of 3 years of detecting and analzying vulnerabilities in at least two of the following languages: Java, C#, C/C++, Python, PHP
- Ability to explain vulnerabilities and weaknesses in OWASP Top 10 and SANS Top 25 to any audience and discuss effective defensive techniques
- Proficiency with application security best practices with focus on secure coding
- Ability to work under pressure, multitask and be flexible
- Experience in conducting analysis using commercial tools such as Fortify, VeraCode, SonarQube or related tool
Dexian is a leading provider of staffing, IT, and workforce solutions with over 12,000 employees and 70 locations worldwide. As one of the largest IT staffing companies and the 2nd largest minority-owned staffing company in the U.S., Dexian was formed in 2023 through the merger of DISYS and Signature Consultants. Combining the best elements of its core companies, Dexian's platform connects talent, technology, and organizations to produce game-changing results that help everyone achieve their ambitions and goals.
Dexian's brands include Dexian DISYS, Dexian Signature Consultants, Dexian Government Solutions, Dexian Talent Development and Dexian IT Solutions. Visit https://dexian.com/ to learn more.
Dexian is an Equal Opportunity Employer that recruits and hires qualified candidates without regard to race, religion, sex, sexual orientation, gender identity, age, national origin, ancestry, citizenship, disability, or veteran status.