Security Assessor

2 days ago


Dallas, United States Photon Full time

Greetings from Photon


Who are we?

Photon has emerged as one of the world’s largest and fastest-growing Digital Agencies. We work with 40% of the Fortune 100 on their Digital initiatives and are known for our ability to integrate Strategy Consulting, Creative Design, and Technology at scale. For a brief 1 minute video about us, you can check


Position: Security Assessor

Location: Dallas, TX (Onsite)


Job Description

As a Security Engineer/Tester, you will be performing authorized security testing on some of the very complex, massive scale, and highly critical applications. You must be self-directed, able to work independently, as well as work in a team-oriented and fast-paced environment. You need to be aware of varied application security domains like authentication, authorization, identity management, cryptography, etc. As part of a shift left focus, you will be working part of the development team along with developers to proactively identify any security vulnerabilities (OWASP Top 10, SANS Top 25, CWE) at the earliest before they are discovered late in cycle by InfoSec teams or in production. You will be working as a liaison between the Infosec team and development teams, understanding the security issues reported by central InfoSec teams to development teams to help them understand and fix them. You require very good communication and presentation skills to be able to present your findings to Leadership/Management/Development teams to help them understand the Risk so that they can take informed decisions on mitigations, controls and residual risk. You need to be highly passionate in following the constantly changing threat landscape and familiarize yourself with the latest security vulnerabilities that impact the teams.


Responsibilities:

Conduct web application security testing on the applications and report the findings to Leadership / Management / Development teams

Understand the security issues reported by InfoSec teams and work with development teams to make them understand and fix.

Evangelize application security concepts within development community to help prevent security vulnerabilities in first place.


Required Skills

Deep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), browser technologies, etc.

In depth domain understanding of application security in terms of Identity and Access Management (IAM), different authentication technologies (passwords, biometrics, OTP, digital certificates & PKI, device authentication, FIDO U2F/Passkeys, etc.

Proven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools,

Deep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, attack patterns (CAPEC), etc.

Bachelor's Degree in Computer Science or equivalent experience.

Must be self-directed, able to work independently, as well as work in a team-oriented and fast paced environment


Desired Skills:

Working experience on different security technologies and standards like Single Sign On (SSO) using SAML/OpenID, OAuth protocols, etc.

Good understanding of Cryptographic algorithms and standards like Symmetric/Asymmetric crypto techniques, digital signatures, JWS/JWE tokens, Hardware Security Modules (HSMs), etc.

Understanding of Security vulnerabilities related to Cloud environments is an added advantage.

Well known Security certifications is an added advantage

Understanding of Threat Modelling concepts and Secure Development Life Cycle processes.

Mobile Application Security familiarity is desirable.


  • Security Specialist

    2 days ago


    Dallas, Texas, United States Photon Full time

    Job Title: Security AssessorPhoton is seeking a highly skilled Security Assessor to join our team. As a Security Assessor, you will be responsible for performing authorized security testing on complex applications and identifying potential security vulnerabilities.Key Responsibilities:Conduct web application security testing and report findings to leadership...


  • Dallas, United States The Goldman Sachs Group Full time

    The Risk division is responsible for credit, market and operational risk, model risk, independent liquidity risk, and insurance throughout the firm. Organization: Risk Division, Operational Risk Team / Role: Technology Operational Risk - CORE Engineering Risk Level/Location : Vice President, Dallas The Operational Risk Division at Goldman Sachs is an...


  • Dallas, United States Omni Hotels Full time

    Overview: Omni Hotels and Resorts creates genuine, authentic guest experiences at 60 distinctive luxury hotels and resorts in leading business gateways and leisure destinations across North America. Omni Hotels is known for its exemplary culture, authenticity to the markets in which we operate, innovation and exceptional service. Our commitment to career...