Application Security Specialist

5 days ago


Atlanta, Georgia, United States FIRST SOFTSOLUTIONS INC Full time
Job Title: Application & Cloud Container Security Engineer

We are seeking a highly skilled Application & Cloud Container Security Engineer to join our team at First SoftSolutions Inc.

Job Summary:

The successful candidate will have a deep understanding of cybersecurity and application security testing expertise to identify vulnerabilities in applications. They will conduct application security assessments, code reviews, container security, and manual API testing using tools like Burp Suite.

Responsibilities:
  • Conduct Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA) using VeraCode
  • Correlate findings from tools such as VeraCode Source Code Agent to identify presence of vulnerable methods in code
  • Research open-source community contributors and NIST NVD to understand residual risk and recommend course of action
  • Determine how frequently and quickly fixes should be delivered for open-source findings
  • Review SCA reports to track new and changes to SCA components in the environment
  • Experience working with tools such as Sonatype nexus firewall and lifecycle to track and block risk 3rd-party components
  • Work within the DevSecOps model to secure Containers, within ROSA, Tekton and OpenShift pipelines
  • Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements.
  • Guide development teams in integrating new services and applications into the CI/CD pipeline, troubleshoot installations and build automated deployments of products into a high-security architecture.
  • Knowledge of CI/CD orchestration tools such as Jenkins, Tekton, GitLab, or Bamboo.
  • Provide operational support for container security tools (Palo Alto Prisma, Aqua, Wiz or equivalent)
  • Perform Baseline Image validation of new container template images.
  • Evaluate scan results for container runtime environments to reduce security risk
  • Troubleshoot any connectivity or operational issues for clusters evaluated in the Prisma tool.
  • Apply software development skills (e.g., Java, C#.NET, JavaScript) to recommend and apply secure coding practices
  • Validate and address vulnerability/threat findings from static and dynamic analysis tools
  • Characterizes threats and provides recommendations for remediation; manages remediation efforts to completion
  • Develops and presents finding and remediation reports to audiences including team members from all department areas and levels of the company
  • Perform security reviews of software designs and assist developers to ensure quality and robustness of our internal products
  • Conduct security assessments against web applications and APIs across a variety of technology stacks
  • Ensure adequate security requirements and privacy by design are built into all architecture/infrastructure/projects
Requirements:
  • B.S. degree in Computer Science, Computer Engineering, Information Assurance, or related field
  • Minimum 5+ years of professional experience in application security, penetration testing, security assessment, secure software development or related field
  • Hands-on experience working with Cloud and/or DevSecOps related technologies
  • Excellent understanding of DevSecOps techniques and processes, guide integration of various tools in DevSecOps processes (GitLab/GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization).
  • Should be well-versed with the AWS well-architected framework or TOGAF and able to apply those principles while designing a solution
  • Experience building and supporting applications in the Cloud (AWS, Azure, GCP)
  • Experience engineering software within an Amazon Web Services (AWS) cloud infrastructure
  • Troubleshoot and resolve problems with existing cloud controls
  • Extensive knowledge of the OWASP Top 10
  • Experience with vulnerability risk and impact assessment
  • Experience integrating security capabilities in cloud and application lifecycle management platforms especially in a DevOps model
  • Extensive knowledge with static analysis tools and flaw triage such as HP Fortify, IBM Rational, Veracode or Coverity, FindBugs, FindSecurityBugs, Brakeman and Open-Source scanning tools such as Sonatype CLM
  • Excellent written and verbal communication skills


  • Atlanta, Georgia, United States Stefanini North America and APAC Full time

    About the RoleWe are seeking a highly skilled Application Security Specialist to join our team at Stefanini North America and APAC. As a key member of our Global Information and Content Security (GICS) team, you will play a critical role in ensuring the security of our mobile applications.Key ResponsibilitiesMobile Application Security: Maintain knowledge of...


  • Atlanta, Georgia, United States Zelis Healthcare Full time

    Job Title: Application Security EngineerZelis Healthcare is seeking a highly skilled Application Security Engineer to join our team. As a key member of our corporate application development teams, you will be responsible for ensuring the security of our applications.Responsibilities:Partner with corporate stakeholders to understand regulatory, industry, and...


  • Atlanta, Georgia, United States Stefanini North America and APAC Full time

    Job Title: Application Security EngineerStefanini North America and APAC is seeking a highly skilled Application Security Engineer to join our team.About the RoleWe are looking for a talented individual to work closely with our client's product teams and engineering groups to ensure secure architectures, patterns, and solutions are created and maintained.Key...


  • Atlanta, Georgia, United States Saxon Global Full time

    Job Title: Application Security TesterWe are seeking a highly skilled Application Security Tester to join our team at Saxon Global. As an Application Security Tester, you will be responsible for identifying weaknesses and vulnerabilities in our applications and systems.Key Responsibilities:Identify and assess vulnerabilities in our applications and...


  • Atlanta, Georgia, United States Insight Global Full time

    Job Title: Application Security EngineerWe are seeking a skilled Application Security Engineer to join our team remotely. As a key member of our security team, you will be responsible for ensuring the security and integrity of our software applications.Job Summary:The successful candidate will have a strong background in application security, with experience...


  • Atlanta, Georgia, United States Better Hire Full time

    About the RoleWe are seeking a highly skilled Application Security Engineer to join our team at Better Hire. As a key member of our security team, you will be responsible for ensuring the security and integrity of our cloud-based applications and infrastructure.Key ResponsibilitiesDesign and implement secure solutions for authentication and authorization,...


  • Atlanta, Georgia, United States Genesis10 Full time

    Job Title: Application Security EngineerGenesis10 is seeking an experienced Application Security Engineer to join our team in Atlanta, GA. This is a 12+ month contract position.Description:We are looking for a skilled Application Security Engineer to conduct Static Application Security Test (SAST), Dynamic Application Security Test (DAST), and Source Code...


  • Atlanta, Georgia, United States Softpath System Full time

    Job Title: Application SecurityAt Softpath System, we are seeking a highly skilled Application Security professional to join our team. The successful candidate will be responsible for conducting remediation validations, manual code reviews, and static code analysis to ensure the security of our applications.Key Responsibilities:Conduct remediation...


  • Atlanta, Georgia, United States CAMP Full time

    Job Title: Application Security EngineerCAMP Systems is a leading provider of aircraft compliance and health management services to the global business aviation industry. As a pioneer in its field, CAMP has established itself as the pre-eminent brand in the industry, with a strong presence in 13 locations worldwide.Our company has grown significantly since...


  • Atlanta, Georgia, United States CAMP Systems International, Inc. Full time

    About CAMP Systems International, Inc.CAMP Systems International, Inc. is a leading provider of aircraft compliance and health management services to the global business aviation industry. With a strong presence in 13 locations worldwide, the company has grown from a single location in 2001 to over 1,300 employees. CAMP's relationships with business aircraft...


  • Atlanta, Georgia, United States ImagineX Consulting Full time

    Job OverviewImagineX Consulting is a software company that helps clients transform their businesses by embracing emerging technologies. We're looking for an Application Security Engineer to join our team.This is a 100% remote position with aggressive salary and bonus packages, and 401K matching. Must be comfortable working standard west coast hours.Key...


  • Atlanta, Georgia, United States ImagineX Consulting Full time

    Job OverviewImagineX Consulting is a software company that helps clients transform their businesses by embracing emerging technologies. We're looking for an Application Security Engineer to join our team.Key ResponsibilitiesProvide guidance and assistance to development personnel in understanding security vulnerabilities and remediation options.Collaborate...


  • Atlanta, Georgia, United States Insight Global Full time

    Security Software Assurance AnalystWe are seeking a skilled Security Software Assurance Analyst to join our team remotely. This role offers a competitive salary range of $45-$70 per hour, with exact compensation varying based on skills, experience, and education.Benefits:Medical, dental, and vision insuranceHSA, FSA, and DCFSA account options401k retirement...


  • Atlanta, Georgia, United States The Transportation Security Administration Full time

    Secure the Future of TransportationAt The Transportation Security Administration, we are committed to safeguarding the American way of life by securing our nation's transportation infrastructure. As a Supervisory Transportation Security Inspector, you will play a critical role in ensuring the freedom of movement for people and commerce.Key...


  • Atlanta, Georgia, United States Security 101 Full time

    Job Summary:We are seeking a highly skilled and experienced Senior Electronic Security Systems Specialist to lead our team in installing, programming, and servicing commercial electronic security devices, primarily IP network systems and overall security systems.Key Responsibilities:Install, troubleshoot, program, and test security systems with minimal...

  • Security Specialist

    2 weeks ago


    Atlanta, Georgia, United States Culpepper & Associates Security Services, Inc. Full time

    Job OpportunityCulpepper & Associates Security Services, Inc. is seeking a skilled security professional to join their team in Atlanta, GA.Key Responsibilities:Ensure a secure and safe environment for clients and staffConduct regular patrols and monitor premises as directedProvide direction to clients and visitorsAssess and respond to potential threats or...


  • Atlanta, Georgia, United States DKMRBH Inc. Full time

    Job Title: Application SpecialistThis role involves collaborating with stakeholders to define testing requirements, contributing to the development and modification of applications, and analyzing system performance to identify and resolve issues. The specialist will also document processes, communicate technical information to non-technical stakeholders, and...


  • Atlanta, Georgia, United States DKMRBH Inc. Full time

    Job Title: Application SpecialistThis role involves collaborating with stakeholders to define testing requirements, contributing to the development and modification of applications, and analyzing system performance to identify and resolve issues. The specialist will also document processes, communicate technical information to non-technical stakeholders, and...


  • Atlanta, Georgia, United States Sirius XM Radio Inc Full time

    About the RoleSiriusXM is seeking a highly skilled Application Security Engineer to join our security organization. As a key member of our team, you will play a vital role in supporting our technology objectives and ensuring the security of our software and applications.ResponsibilitiesDesign and implement secure features to enable developers to write secure...


  • Atlanta, Georgia, United States Sirius XM Radio Inc Full time

    About SiriusXMSiriusXM is a leading audio entertainment company in North America, delivering music, sports, talk, news, comedy, and podcasts to millions of listeners. Our vision is to shape the future of audio, where everyone can be effortlessly connected to the voices, stories, and music they love.Job SummaryWe are seeking an experienced Application...