Technical Consultant

3 weeks ago


Poland, United States IBM Full time

Technical Consultant - Application Security IBM For more than a century, IBM has been a global technology innovator, leading advances in AI, automation and hybrid cloud solutions that help businesses grow. Introduction At IBM, work is more than a job – it’s a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you’ve never thought possible. Are you ready to lead in this new era of technology and solve some of the world’s most challenging problems? If so, let's talk. Your Role and Responsibilities This role requires extensive knowledge and experience in identifying and providing recommendations to security risks specific to software applications hosted in AWS & Azure cloud environments in-line with industry standards & best practices. It requires expertise in areas such as secure coding practices, interface review, API security review & threat modeling, security testing techniques, and compliance requirements. You will lead all the technical discussions with application owners & customer stakeholders and provide guidance to internal teams in executing security assessments. We are looking for an experienced resource with strong knowledge & skill set to support the application security assessment part of the DevSecOps track. Required Technical and Professional Expertise Technical skills: Experience in AppSec toolchain. Eg tools: Burp Proxy, ZAP, Checkmarx, Synopsys etc. To help product team to implement/integrate Security tool set into DevSecOps CI/CD (Jenkins) pipeline. Should be familiar with Secure-SDLC phases, Good in OWASP Standards & guideline and ASVS. Hands-on to perform both white & grey box AppSec test in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software composition analysis (SCA), Software dependency scanning. Acquaint in AppSec posture management, Review Security Vulnerability Reports & false positive analysis. Familiar with IT Policy Framework covers Backup Restoration & Disaster Recovery, Logging monitoring reviews, validate the Configuration & System Integration reviews. Expert in Manual & tools-based penetration testing experience (Grey & Black Box) for Applications, ReST based Web APIs or Web Services, and report findings with fix remediations & recommendations to dev team. Architecture Design / Solution Outline Reviews from security perspective with Architect & Product team to suggest solutions for secure architecture. Threat Modelling Analysis using any of STRIDE / PASTA methodologies or SD Elements. Logical Access Model Review -Good understanding on User access models, RBAC & various authentication & authorization, SSO and Federated identity management, basic of Identity Access Management (IAM), Privilege Access model (PAM). Guiding development team for Secure Coding best practices & verification to suggest Secrets scanning in Product IDE using plugins in Bitbucket/Code repo. Capable of executing Secrets scanning, Container Security using Aqua, Analyze Infrastructure As a Code (IaC) Scanning reports and Terraform & Checkov reports. Project Management & Soft skills: Handling Jira tool & align with Agile Sprints, Weekly & monthly reporting. Good Communication skills to support geo-diverse teams includes Dev/Product team, Infosec and management. Self-learn and pro-active to drive security team and Self-managed to prioritize individual task. Understanding complex cloud, on-prem, hybrid & multi cloud architectures to ensure the design covered key security aspects and latest implementations like Microservices, AI BOTs & IoT to secure architecture etc. Knowledge on Enterprise Security Architecture Framework to SABSA, TOGAF, COBIT certifications. Client-Server, Legacy, Monolithic, Microservices Architecture, Well-Define Architectures in AWS Cloud. Should have work experience in Migration & Cloud Modernization or digital transformation projects. Preferred Technical and Professional Expertise AWS Cloud certification preferred or Knowledgeable in MS-AZURE or Google Cloud & additionally SAP, Salesforce etc. Key Job Details Role: Technical Consultant – Application Security Location: Wroclaw, PL Category: Consulting Employment Type: Full-Time Travel Required: Up to 20% or 1 day a week Contract Type: Regular Company: (0109) IBM Polska Sp. z o.o. Req ID: 736188BR #J-18808-Ljbffr


  • Technical Writer

    1 month ago


    Poland, United States Sperton Global AS Full time

    We are seeking a Technical Writer for a project focused on Platform Definition & Governance. The role involves defining roles responsibilities and governance aligned with company architecture and security guidelines ensuring compliance with audit standards. The primary task is to develop guidelines for Platform Owners and Tenants to facilitate efficient...


  • Poland, United States SmartRecruiters Inc Full time

    Our customers are looking to transform their talent operations and processes to meet their evolving business priorities. Through the value of the SmartRecruiters Talent Acquisition Suite and professional services we are positioned to deliver on their needs and ensure they acquire the best talent to achieve business success.As a Technical Integration Support...


  • Poland, United States SmartRecruiters Inc Full time

    Our customers are looking to transform their talent operations and processes to meet their evolving business priorities. Through the value of the SmartRecruiters Talent Acquisition Suite and professional services we are positioned to deliver on their needs and ensure they acquire the best talent to achieve business success.As a Technical Integration Support...

  • IT Project Manager

    3 weeks ago


    Poland, United States Sperton Global AS Full time

    HI For our Client from banking industry we are looking for IT Project Manager Job Summary:The Project Manager will be responsible for overseeing the planning execution and successful delivery of a project focused on removing obsolete infrastructure software such as Java Python and Virtual C versions from the organizations systems. The Project Manager will...


  • Poland, United States Kyndryl Full time

    Kyndryl At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The Role Are you...