Application Security Specialist

1 week ago


Washington, United States Stefanini North America and APAC Full time
Job Title: Application Security Engineer

Stefanini Group is seeking a highly skilled Application Security Engineer to join our team in a globally recognized company.

This is a key role that will be focused on application security for mobile applications - native, native mobile, and hybrid. As a valued partner to software development and engineering teams, you will ensure secure architectures, patterns, and solutions are created and maintained.

Responsibilities:
  • Maintain knowledge of current and emerging secure mobile application technologies/products/trends
  • Install, configure, and maintain Mobile app security assessment tools for mobile application security assessments (iOS, Android, Roku, etc.).
  • Integrate Mobile app security assessment tools with existing CI/CD pipelines to ensure automated and continuous security testing.
  • Extend Mobile app security assessment to scan AndroidTV, FireTV and tvOS applications for comprehensive security analysis.
  • Develop and maintain scripts and tools for automated uploading of mobile binaries to Mobile app security assessment tools.
  • Automate the generation and export of security assessment reports.
  • Customize and optimize the Mobile app security assessment tools reporting functionality to meet organizational needs.
  • Ensure the accuracy and comprehensiveness of the security assessment reports.
  • Work closely with the development and DevOps teams to integrate Mobile app security assessment tools into the development lifecycle.
  • Collaborate with security analysts to interpret and act on the findings from the Mobile app security assessment tools reports.
  • Monitor and troubleshoot Mobile app security assessment tools - related issues and ensure the platform is running smoothly.
  • Keep Mobile app security assessment tools and related tools up to date with the latest security patches and updates.
Requirements:
  • Proficiency in setting up and managing Mobile app security assessment tools or similar mobile security assessment tools.
  • Strong scripting skills in Python, Shell, or other relevant languages.
  • Experience with CI/CD tools such as Jenkins, GitLab CI, or CircleCI.
  • Familiarity with mobile application development frameworks (Android and iOS).
  • Experience with integrating security tools for Android TV and tvOS applications.
  • Build, maintain, and utilize security tools for the Application Security program
  • Identify and define mobile application security requirements and security baselines
  • Actively and continuously share role-specific knowledge with team members and product teams
Preferred Qualifications:
  • 2-4 years of Junior experience/5+ years of Senior experience
  • Proven experience in mobile application security testing and automation
  • Knowledge of security best practices and common mobile application vulnerabilities
  • Hands-on experience with containerization technologies (Docker, Kubernetes) is a plus
  • Proven experience building tools and automation to support an Application Security team
  • Strong understanding of software development methodologies and secure coding practices
  • Strong understanding of the SDLC and CI/CD pipelines
  • Experience developing iOS and Android mobile applications
  • Experience reading and comprehending code, discerning business logic, and identifying security flaws in mobile-relevant languages, such as Swift, Objective-C, Kotlin, Java, JavaScript, and TypeScript.
  • Understanding of common mobile application authentication and encryption methods, including OAuth and PKI
  • Understanding of protocol and network analysis using mitmproxy and Wireshark
  • Understanding of platform-specific security features and best practices, such as Apple's App Transport Security, Android's Network Security Configuration, and Samsung Knox.
  • Familiarity with platform-specific development environments, SDKs, and tools, such as Xcode for iOS, Android Studio for Android, and Samsung's Tizen Studio.
  • Hands-on experience working with DevOps and Agile-driven product teams
  • Strong understanding of application security standards and practices, such as the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Security Testing Guide (MSTG)
  • Excellent written and verbal communication skills
Nice to Have:
  • Knowledge of cloud architecture and security principles
  • Bachelor's degree in IT, Computer Science, or Information Security preferred.
  • ISC2 CSSLP, GIAC (GMOB, GWEB, GCSA), or other Security Certifications.


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Systems SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a skilled Security Systems Specialist to join our team. As a Security Systems Specialist, you will be responsible for providing technical support and maintenance for our security systems, ensuring the highest level of security and...


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Systems SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a skilled Security Systems Specialist to join our team. As a Security Systems Specialist, you will be responsible for providing technical support and maintenance for our security systems, ensuring the highest level of security and...


  • Washington, Washington, D.C., United States Rangam Consultants Inc. Full time

    Job Title: Application System Security SpecialistRangam Consultants Inc. is seeking a highly skilled Application System Security Specialist to join our team. As a key member of our security team, you will be responsible for designing, implementing, and maintaining physical security systems to safeguard our facilities and assets.Key Responsibilities:Research...


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Solutions SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a technically skilled individual to fill this role. As a Security Solutions Specialist, you will be responsible for delivering exceptional service to our clients, ensuring the smooth operation of their security systems, and providing...


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Solutions SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a technically skilled individual to fill this role. As a Security Solutions Specialist, you will be responsible for delivering exceptional service to our clients, ensuring the smooth operation of their security systems, and providing...


  • Washington, Washington, D.C., United States CloudShape Full time

    Job OverviewCloudshape is seeking a talented Application Security Analyst to join our growing team. This role will be responsible for assisting various technical teams in maintaining the security of web applications and application servers within the customer's portfolio.Key ResponsibilitiesAssist technical teams in maintaining the security of web...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    Job SummaryWe are seeking a highly skilled Application Security Engineer to join our team at Booz Allen Hamilton. As a key member of our security team, you will be responsible for supporting and maintaining a resilient security posture for our highly visible applications.Key ResponsibilitiesCollaborate with the client and application community to identify...


  • Washington, United States Insight Global Full time

    Application Security Penetration TesterInsight Global's client is seeking a skilled Application Security Penetration Tester to join their team in Washington, D.C. This individual will work closely with a team of 5 experts to conduct source code reviews and penetration testing to identify security concerns and vulnerabilities within mobile applications.Key...


  • Washington, United States Kavaliro Full time

    About the RoleKavaliro is seeking an experienced Application Penetration Tester with a strong background in cybersecurity and application security.Key ResponsibilitiesIdentify and address vulnerabilities in web, mobile, and cloud-native applicationsWork with cross-functional teams to implement security measures and best practicesConduct thorough security...


  • Washington, United States Kavaliro Full time

    Job Title: Application Penetration TesterKavaliro is seeking a seasoned Application Penetration Tester with a strong background in cybersecurity and application security to join our security team. As a key member of our team, you will be responsible for identifying and addressing vulnerabilities in web, mobile, and cloud-native applications, while...


  • Washington, Pennsylvania, United States Am-Gard Security, Inc. Full time

    Job OverviewAs a Security Operations Specialist at Am-Gard Security, Inc., you will play a crucial role in maintaining a safe and secure environment for our clients. With over 40 years of experience in the security industry, Am-Gard is a family-owned business dedicated to serving the southwestern Pennsylvania region.Company BackgroundAm-Gard Security, Inc....


  • Washington, Washington, D.C., United States Kavaliro Full time

    Kavaliro Cybersecurity RoleWe are seeking an experienced Lead Application Penetration Tester to join our team at Kavaliro. This role is ideal for someone passionate about cybersecurity and skilled in identifying and mitigating vulnerabilities in application security.ResponsibilitiesLead the application security team in identifying and mitigating...


  • Washington, United States Kavaliro Full time

    Lead Application Penetration TesterKavaliro is seeking an experienced cybersecurity professional to lead our application penetration testing team. This role is ideal for someone passionate about identifying and mitigating vulnerabilities in application security.Key ResponsibilitiesConduct comprehensive security assessments of cloud-native,...

  • IT Specialist

    1 month ago


    Washington Navy Yard, United States National Nuclear Security Administration Full time

    As an Information Technology Specialist (Cloud Computing Cyber Security), you will: Serve as a senior cyber security specialist responsible for administering cyber security policy. Coordinate and assess policy and evaluation of other organization's cyber security implementations, the breadth of these responsibilities spans Naval Reactors Headquarters,...


  • Washington, Washington, D.C., United States Kavaliro Full time

    Job Title: Lead Application Penetration TesterKavaliro is seeking an experienced Lead Application Penetration Tester to join our cyber security team. This role is perfect for someone passionate about cybersecurity and skilled in identifying and mitigating vulnerabilities in application security.Key Responsibilities:Lead and mentor a team of penetration...


  • Washington, Washington, D.C., United States Kavaliro Full time

    Lead Application Penetration TesterKavaliro is seeking an experienced cybersecurity professional to lead our application penetration testing team. As a seasoned expert in cloud-native, microservices-based applications, you will be responsible for identifying and mitigating vulnerabilities in web, mobile, and cloud security.Key Responsibilities:Leadership &...

  • Security Officer

    4 weeks ago


    Washington, United States Sunstates Security Full time

    About Sunstates SecuritySunstates Security is a leading provider of security services, committed to delivering exceptional customer service and quality work environments for its team across the country.Our Mission and VisionOur mission and vision statement are at the heart of everything we do, focusing all efforts on honor, integrity, and trust.Job SummaryWe...


  • Washington, Washington, D.C., United States Editech Staffing Full time

    Job Title: Lead Application Penetration TesterJob Summary:We are seeking a highly skilled and experienced Lead Application Penetration Tester to join our team. As a key member of our cybersecurity team, you will be responsible for leading comprehensive security assessments of cloud-native, microservices-based architectures.Key Responsibilities:Lead and...


  • Washington, Washington, D.C., United States Motion Recruitment Full time

    Senior Application Security EngineerWashington, District Of ColumbiaHybridFull Time$150k - $180kWe are seeking a highly skilled Senior Application Security Engineer to join our team based out of Tyson's Corner, VA.The ideal candidate will have extensive experience in Java and similar languages, as well as familiarity with code scanning systems.As a leader in...

  • Security Specialist

    4 weeks ago


    Washington, United States Inter-Con Security Full time

    Job OverviewInter-Con Security Systems, Inc. is a leading provider of physical security services to government and commercial clients worldwide.Job ResponsibilitiesProvide high-level security services to clients with complex security needs.Develop and implement customized security solutions to meet client requirements.Manage and train a team of security...