Web Application Security Engineer

3 days ago


San Francisco CA United States Direct Staffing Inc Full time

Visa candidates are welcome to apply.

Shopping has changed more in the past five years than in the past five decades, and going forward, retailing will require investing more in people and technology. With the rapid changes in retail, it is critical that technology be a strategic enabler for our company to accelerate delivery, be adaptive to market changes, and effective in rapidly delivering solutions to meet the needs of our customers. The Web Application Security Engineer works as a member of the Information Security team.

Primary Responsibilities:
  1. Performs static/dynamic code testing, manual code inspection, threat modeling, design reviews and penetration testing of internal web applications and external partner applications to identify vulnerabilities and security defects.
  2. Supports the implementation and enforcement of secure design principles according to policies, standards, and patterns of Information Security.
  3. Serves as a Subject Matter Expert (SME) in web application security for enterprise projects during development phases to provide Information Security consulting and recommendations, ensuring the implementation of approved security requirements.
  4. Develops and implements manual and automated web application security testing of e-commerce web applications to enforce security standards.
  5. Works with security product vendors and service providers to evaluate security offerings, including product evaluations, proof of concept and pilot installations.
Qualifications:
  1. Bachelor's degree in Computer Science, Software Engineering or related field or equivalent combination of education and experience.
  2. 5-7 years of experience in performing penetration testing, secure code review, static, dynamic and manual source code review.
  3. Experience in identifying and remediating common web application vulnerabilities such as OWASP Top 10.
  4. Experience in use of various commercial and open source penetration testing tools and methodologies and performing penetration testing of web applications and operating systems.
  5. Familiarity with APT attack and kill chains.
  6. Experience with various code repositories including GitHub and Apache Subversion (SVN).
  7. Experience with continuous integration servers such as Jenkins and ElectricCommander.
SCREENING QUESTIONS
  1. Do you have experience performing penetration testing?
  2. Do you have experience identifying vulnerabilities within a web application?
  3. Are you ok working in SF or Pleasanton?
  4. Do you have examples consulting enterprise level development projects?
  5. Are you ok taking a 75 question assessment?
Additional Information

All your information will be kept confidential according to EEO guidelines.

#J-18808-Ljbffr

  • San Francisco, United States IDENTIFY SECURITY Full time

    We are seeking a highly skilled Staff Application Security Engineer with a strong background in cloud software service management and application security to join our dynamic team. In this role, you will play a crucial part in ensuring the reliability, scalability, and security of our software systems and digital experiences. You will work closely with the...


  • San Jose, California, United States TemperaturePro Full time

    TemperaturePro is a leading provider of innovative temperature management solutions. We are seeking an experienced Backend Web Application Engineer to join our dynamic team.About the RoleWe offer a competitive salary of $90,000 - $110,000 per year, depending on experience.Job DescriptionAs a Backend Web Application Engineer at TemperaturePro, you will be...


  • McLean, VA, United States EnDyna, Inc. Full time

    We are looking for an experienced and passionate application security engineer to join our cybersecurity team. You will be responsible for providing security solutions to our clients, who are mainly federal government agencies. You will conduct security assessments, code reviews, penetration testing, and vulnerability remediation for their web and mobile...


  • Santa Clara, CA, United States Lamwork Full time

    APPLICATION SECURITY ENGINEER RESUME EXAMPLE Updated: July 26, 2024 - The Application Security Engineer plays a crucial role in ensuring the resilience and scalability of web applications, advising on secure design principles, and addressing security issues. Responsibilities include validating, tracking, and prioritizing security issues, developing internal...


  • San Francisco, United States Bridge Technologies and Solutions Full time

    We need a resource who has experience working within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience.Responsibilities:• Experience with any of the following commercial application scanning tools such as Acunetix, IBM's AppScan, Client's WebInspect, NTOSpider, Cenzic's Hailstorm, Burp Suite...


  • San Francisco, California, United States University of California - San Francisco Campus and Health Full time

    Job Title: Software Development Engineer II - Web Application ReliabilityA software development engineer position at the University of California, San Francisco Campus and Health is available.About the Role:This position requires experience in developing, maintaining, and migrating web applications to ensure reliability and efficiency.The successful...


  • Los Angeles, CA, United States DBA Web Technologies Full time

    Location: California Job Function: Developer Date Of Job Posting: 07-21-2018 (There are 10 positions at various grade levels with experience level between 1 to 10+ years) Locations: San Jose, CA Duration: Full-Time Permanent positions (no contracts, no corp to corp, no remote) Salary: Excellent Compensation with benefits (Salary will depend on experience as...


  • San Francisco, United States Capital One Full time

    Principal Associate, Application Security EngineerApplication security is one of our highest priorities at Capital One. As a Capital One customer, you benefit from an environment built to meet the requirements of one of the most security–sensitive organizations in not only the financial industry, but also the technology landscape. As a Capital One Security...


  • San Francisco, United States Nexus Full time

    We’re looking for an enthusiastic, self-motivated engineer to help us build the verifiable Internet. As a core team member, you will gain ownership over our web products, as well as the ability to influence the creation, design, and execution of future products. You will be responsible for ensuring a consistent, high-quality user experience across prover...


  • Draper, UT, United States BAMM Staffing Full time

    Contract to Hire, Onsite in Draper Utah (US Citizen or GC Only)As a Senior Application Security Engineer, you will work to support the various processes and procedures related to application security and gather information from product engineering teams related to these activities. You will make a difference in promoting a culture of security inside the...


  • Draper, UT, United States BAMM Staffing Full time

    Contract to Hire, Onsite in Draper Utah (US Citizen or GC Only)As a Senior Application Security Engineer, you will work to support the various processes and procedures related to application security and gather information from product engineering teams related to these activities. You will make a difference in promoting a culture of security inside the...


  • Woodland Hills, CA, United States Ekman Associates, Inc Full time

    Job Description Remember to check your CV before applying Also, ensure you read through all the requirements related to this role. Title: Senior Application Security Engineer Location: Remote - Southern California preferred Ekman Associates is a management consulting firm that specializes in developing business, digital, and technology strategy,...


  • San Francisco, CA, United States IDENTIFY SECURITY Full time

    We are currently seeking a Staff Embedded Security Engineer . This position requires an experienced professional with a proven track record of cyber security development achievements. Our ideal candidate exhibits a can-do attitude and approaches his or her work with vigor and determination. Candidates will be expected to demonstrate excellence in their...


  • San Francisco, California, United States University of California - San Francisco Campus and Health Full time

    Job OverviewUCSF is seeking an experienced IT Security Analyst 3 to conduct comprehensive assessments of web applications to identify vulnerabilities and improve security. The incumbent will be responsible for conducting penetration testing, identifying potential vulnerabilities, and providing actionable reports to technical teams and stakeholders.About the...


  • San Francisco, California, United States Zurich Insurance Company Ltd. Full time

    About the RoleWe are seeking a skilled Software Development Professional to join our team at Zurich Insurance Company Ltd.This is an exciting opportunity to develop a web application that prioritizes user security and efficiency. You will be responsible for designing and implementing robust user authentication and authorization mechanisms, ensuring the...


  • San Francisco, California, United States University of California - San Francisco Full time

    Job Description:We are seeking an experienced Senior Cybersecurity Specialist to specialize in web application testing. The incumbent will be responsible for conducting comprehensive assessments of our web applications to identify vulnerabilities and improve security. This position supports the California Immunization System and involves work implementing...


  • San Francisco, CA, United States Tbwa ChiatDay Inc Full time

    Headway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled national network of providers accepting insurance. 1 in 4 people in the US have a treatable mental health condition, but the majority of providers don’t accept...


  • San Francisco, California, United States Cloudflare Inc Full time

    Cloudflare IncAbout UsWe are a global network that powers millions of websites and other Internet properties. Our mission is to help build a better Internet by protecting and accelerating any Internet application online without adding hardware, installing software, or changing a line of code.We realize people do not fit into neat boxes. We are looking for...


  • San Francisco, United States Headway Full time

    Headway Find therapists near you who accept insurance. We'll help you find the right fit—and save you money. Get started today with online or in-person sessions.Headway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled...


  • San Francisco, California, United States Uncountable Inc Full time

    Uncountable Engineering is seeking experienced platform engineers who are passionate about user experience and scaling web applications. We're looking to revolutionize industrial research and development by building a state-of-the-art development platform used across Fortune 500 companies.Possible ProjectsWe are architecting a database to enable complex...