IT Security Auditor

3 weeks ago


Lansing, United States InfoPeople Corporation Full time
Top Skills & Years of Experience:
3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)
3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks
3+ years with networking, infrastructure, secure application development and security automation (DevSecOps).
3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications.
Ability to pass a CJIS background check

Will close submissions on: 8/26 at 10am EST.
Interview Process: Virtual Interview via MS Teams with 2nd round interviews being held IN PERSON at the Dimondale, MI office. Candidates submitted MUST be willing to come onsite for a face-to-face interview.
A screenshot photo of candidate will be required for any interviews as well as a vendor present at beginning of virtual interview to validate candidate (see bid submission requirement attachment for details).

Duration: 1 year with possible extension.
Position will be hybrid - 2 days a week onsite and 3 days working from home. Candidates MUST be local at time of submission. Hiring manager is not currently interested in candidates who will need to relocate to accept offer. NO REMOTE ONLY OPTION.

Please note screening questions (attached) which are required to be submitted along with bid documents.

IT Security Auditor - Job Description
Short Job Description
Senior Full Stack Application Development Security Auditor who is passionate about designing
and building secure platforms and applications through Dynamic, Static and Software
Composition Analysis assessments. This position is not a member of the Security Operations
Center, rather it is dedicated to working with software development teams on secure coding
practices. The ideal candidate will feel comfortable working with both front-end, back-end and
cloud-based application developers. Partnering with distributed teams to help transform the way
systems are built, secured, authorized and securely operated for continuous compliance and
risk mitigation. Specifically, this candidate will help lead efforts to implement security patterns
and practices with orchestration and automation tools that automate the secure configuration,
verification, compliance, and authorization of systems and their development. They will be a key
member of a team tasked with maturing the organization's secure software development
practices.
Long Job Description
Functional Knowledge:
" Chrome/Firefox/Edge Development tools to see the request/response headers
" Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC,
Container/Cloud) a must.
" Experience with Coverity, BlackDuck, STRM, Fortify a plus
" HTTP Request/Response headers for web and Restful API calls
" Ability to explain in detail any of the OWASP top 10 vulnerabilities
" Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc.
" API Security
" JWT
" OAUTH/OIDC/PKCE
" Web, API replay attacks
" High-level understanding of containers
" Cloud development experience (Azure, AWS, GCP)
Minimum of 5+ years of total IT related experience.
3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)
3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks
3+ years with networking, infrastructure, secure application development and security automation (DevSecOps).
3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications.

  • Lansing, Michigan, United States 360 IT Professionals Full time

    Position Overview: We are seeking a highly skilled Senior Security Compliance Auditor with extensive experience in IT security and auditing. The ideal candidate will possess a strong background in regulatory frameworks such as PCI, NIST, FISMA, HIPAA, and CJIS. Company Profile: 360 IT Professionals is a leading Software Development Company located in...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States Saxon Global Full time

    Title: IT Security AuditorPosition Type: Contract 12 monthsLocation: Lansing, MIneed locals onlyIT Security Auditor - Job DescriptionShort Job DescriptionSenior Full Stack Application Development Security Auditor who is passionate about designingand building secure platforms and applications through Dynamic, Static and SoftwareComposition Analysis...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States Saxon Global Full time

    Title: IT Security AuditorPosition Type: Contract 12 monthsLocation: Lansing, MIneed locals onlyIT Security Auditor - Job DescriptionShort Job DescriptionSenior Full Stack Application Development Security Auditor who is passionate about designingand building secure platforms and applications through Dynamic, Static and SoftwareComposition Analysis...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States VeeRteq Solutions Inc. Full time

    Job DescriptionJob DescriptionJob Title: IT Security AuditorLocation: Lansing, MI 48821Duration: 12 Months Job Type: Contract Work Type: HybridShort Job DescriptionSenior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition...

  • Security Auditor

    3 weeks ago


    Lansing, United States A-Line Staffing Solutions Full time

    IT Security Auditor - Job DescriptionLansing, MI Hybrid60-70/hr W2This is NOT a C2C PositionShort Job DescriptionSenior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition Analysis assessments. This position is not a member of the...

  • IT Security Auditor

    1 week ago


    Lansing, United States System Soft Technologies Full time

    Title: IT Security AuditorLocation: Lansing,MI (Hybrid)Contract 12 Months +Rate: $60.00/HRTop Skills & Years of Experience:3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)3+ years with both...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States Themesoft Inc. Full time

    Job Title: IT Security AuditorLocation: - Lansing, MIDuration: Contract Candidate MUST have at least 5-8 years of total IT experience* Position will be hybrid - 2 days a week onsite and 3 days working from home. Candidates MUST be local at time of submission. Hiring manager is not currently interested in candidates who will need to relocate to accept offer....

  • IT Security Auditor

    3 weeks ago


    Lansing, United States Themesoft Inc. Full time

    Job Title: IT Security AuditorLocation: - Lansing, MIDuration: Contract Candidate MUST have at least 5-8 years of total IT experience* Position will be hybrid - 2 days a week onsite and 3 days working from home. Candidates MUST be local at time of submission. Hiring manager is not currently interested in candidates who will need to relocate to accept offer....

  • IT Security Auditor

    3 weeks ago


    Lansing, United States System Soft Technologies Full time

    Title: IT Security AuditorLocation: Lansing,MI (Hybrid)Contract 12 Months +Rate: $60.00/HRTop Skills & Years of Experience:3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)3+ years with both...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States System Soft Technologies Full time

    Title: IT Security AuditorLocation: Lansing,MI (Hybrid)Contract 12 Months +Rate: $60.00/HRTop Skills & Years of Experience:3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)3+ years with both...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States InfoPeople Full time

    Top Skills & Years of Experience: 3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.) 3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot,...

  • IT Security Auditor

    3 days ago


    Lansing, United States Umanist Staffing LLC Full time

    Job DescriptionJob Description& & Short Job Description& Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition Analysis assessments.& This position is not a member of the Security Operations Center, rather it is dedicated to...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States Software People, Inc. Full time

    Job DescriptionJob DescriptionDirect Client In person interview needed. Onsite from day 1 Location: Lansing, MIDuration: 12+ monthsSenior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition Analysis assessments. This position is...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States RICEFW Technologies Full time

    Mode of work: Hybrid at Lansing, Michigan Mode of interview: In-Person interview at Dimondale, MichiganIT Security Auditor - Job DescriptionShort Job DescriptionSenior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition Analysis...


  • Lansing, Michigan, United States InfoPeople Corporation Full time

    Position Overview:We are seeking a highly skilled Senior Full Stack Application Development Security Auditor who is dedicated to ensuring the integrity and security of our software platforms. This role focuses on collaborating with software development teams to implement secure coding practices and build robust applications.Key Responsibilities:1. Conduct...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States RICEFW Technologies Inc Full time

    Mode of work: Hybrid at Lansing, Michigan Mode of interview: In-Person interview at Dimondale, MichiganIT Security Auditor - Job DescriptionShort Job Description Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States RICEFW Technologies Inc Full time

    Mode of work: Hybrid at Lansing, Michigan Mode of interview: In-Person interview at Dimondale, MichiganIT Security Auditor - Job DescriptionShort Job Description Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition...

  • IT Security Auditor

    2 weeks ago


    Lansing, United States Sri USA Full time

    Job DescriptionJob DescriptionFunctional Knowledge:• Chrome/Firefox/Edge Development tools to see the request/response headers• Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud) a must.• Experience with Coverity, BlackDuck, STRM, Fortify a plus• HTTP Request/Response headers for web and Restful API calls•...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States Sri USA Full time

    Job DescriptionJob DescriptionFunctional Knowledge:• Chrome/Firefox/Edge Development tools to see the request/response headers• Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud) a must.• Experience with Coverity, BlackDuck, STRM, Fortify a plus• HTTP Request/Response headers for web and Restful API calls•...

  • IT Security Auditor

    3 weeks ago


    Lansing, United States California Creative Solutions Inc. Full time

    Job DescriptionJob DescriptionFunctional Knowledge:Chrome/Firefox/Edge Development tools to see the request/response headersExperience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud) is a must.Experience with Coverity, BlackDuck, STRM, and Fortify is a plusHTTP Request/Response headers for web and Restful API callsAbility to...