Job Description:
Application Security Engineer
Should have a strong proficiency in at least one of the following areas
- Application Security Testing particularly with BurpSuite and/or ZAP; additional toolsets are expected, but highly dependent on the engineer’s experience
- Web application security engineers must have line a. from the additional hardskill requirements below
- DevSecOps practices (Hands on keyboard experience integrating security linting tools, SAST, or DAST into CI pipelines)
- This area must be accompanied by some in depth knowledge of a language (c++, or JS / NodeJS, or Python), as well as line b from the additional hardskill requirements below
- Cloud Security Posture Management engineering experience implementing automated solutions behind cloud resource security (e.g. designing and implementing a honeypot resulting in automation automatically blocking ingress traffic from malicious traffic).
Peripheral hard skill requirements
- Strong understanding of AWS Cloud Technologies and Solutions
- Strong understanding of vulnerabilities and the assessment thereof
- Strong understanding of the Software Development Lifecycle (SDLC)
- Ability to explain vulnerabilities in Engineering language, or Laman’s terms dependent on audience