Application Security Engineer - AppSec
Docebo
This job is no longer accepting applications
See open jobs at Docebo.See open jobs similar to "Application Security Engineer - AppSec" Work In Tech.Responsibilities:
- Provides application security support to development teams. This includes collaborating to manage and integrate application security tools and processes.
- Provide vulnerability and remediation guidance, and perform basic configuration of scans.
- Triage and validate scan findings, before inputting the associated work tickets.
- Maintain a focus on automation, to support scalability and efficiency.
- Coordination and review of penetration testing activities by third-party ethical hackers and vendors.
- Tuning of DAST/SAST/SCA tools to remove false findings.
- Management of the Threat Modeling program, to drive a triaged and structured approach towards managing security risks.
- Work closely with architecture and product teams to drive security issues to resolution, and monitor against SLAs.
Requirements:
- Fluent in English
- Deep technical knowledge of Threat Modeling and OWASP methodologies.
- Hands-on experience using Burp Suite, ZAP, SAST & DAST tools.
- Understanding of how scanning tools, penetration tests, and post-deploy scanning tools work together in the application security lifecycle.
- Deep, hands-on experience implementing AppSec tools into a DevOps pipeline.
- Solid understanding of application security issues, risks, and mitigation strategies.
- Experience developing and refining Secure SDLC documents and processes.
- Experience building and leading Information Security training focused on secure development practices and based on OWASP principles.
- Experience assessing and securing open-sourced software components.
- Advanced interpersonal verbal and written communications skills.
Nice to have:
- Background as a Developer, with experience in QA.
- Experience as a DevOps or SRE Engineer.
- Experience in Software Development and/or Security-related positions
- Hands-on experience with Terraform is a plus.
- Professional certification is a plus (OCSP, SANS, or similar).
This job is no longer accepting applications
See open jobs at Docebo.See open jobs similar to "Application Security Engineer - AppSec" Work In Tech.