DE Jobs

Search from over 2 Million Available Jobs, No Extra Steps, No Extra Forms, Just DirectEmployers

Job Information

Next Level Business Services, Inc. Sr. Security Engineer in Atlanta, Georgia

Key Responsibilities:

Capable of leading projects to implement tools in CICD pipelines to aid in conducting Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA) using VeraCode

Experience working with tools such as Sonatype nexus firewall and lifecycle to track and block risk 3rd- party components

Work within the DevSecOps model to secure Containers, withing ROSA, Tekton and OpenShift pipelines

Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements.

Guide development teams in integrating new services and applications into the CI/CD pipeline, troubleshoot installations and build automated deployments of products into a high-security architecture.

Extensive knowledge of CI tools such as Jenkins, Tekton, CircleCI, GitlabCI, AWS Code Pipeline etc.

Test driven mindset with experience in automation with development tools

Comfortable with facilitating training on enterprise tools and best practices

Collaborate with and across Agile teams to design, develop, test, implement, and support technical solutions in full-stack development tools and technologies

Apply software development skills (e.g., Java, C#.NET, JavaScript) to recommend and apply secure coding practices

Utilize programming languages like JavaScript, Java, HTML/CSS, TypeScript, SQL, Python, and Go, Open-Source RDBMS and NoSQL databases, Container Orchestration services including Docker and Kubernetes, and a variety of AWS tools and services

Knowledge of secure coding standards.

Experience with Agile methodologies.

Experience with AWS and Kubernetes

Experience in working with 12-factor methodology and understanding its benefits, and able to demonstrate appropriate patterns to other team members Develops and presents finding and remediation reports to audiences including team members from all department areas and levels of the company

Consult with development Teams to perform security reviews of software designs and assist developers to ensure quality and robustness of our internal products

Conduct security assessments against web applications and APIs across a variety of technology stacks

Performs technical design reviews and code reviews.

Ensure adequate security requirements and privacy by design are built into all architecture/infrastructure/projects

Drive improvements in the security testing practice to include execution methodology and metrics

Drive awareness and knowledge of security in the developer community

Continually improve proficiency in application and API exploitation, tools, techniques, and countermeasures

Expertise in software development: clean and reliable code, API design, refactoring, test driven development, design patterns, abstractions, writing documentation, and the complete software development life cycle.

Quals-- Top 5 skills are as follows: Experience integrating Open-source controls Gitlab Implement tools in CICD pipelines AWS Cloud Microsoft Azure

WHAT YOU NEED TO SUCCEED (MINIMUM QUALIFICATIONS)

B.S. preferably in a technical or scientific field. 7 years of software and development experience with a minimum and 5+ years of hands-on experience working with DevSecOps Technologies.

Minimum 5+ years hands-on experience working with Cloud and/or DevSecOps related technologies.

Experience in API testing tools (Postman, BurpSuite or any comparable tools)

Excellent understanding of DevSecOps techniques and processes, guide integration of various tools in DevSecOps processes (GitLab/GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization).

Should be well versed with the AWS well architected framework or TOGAF and able to apply those principles while designing a solution

Experience uilding and supporting applications in the Cloud (AWS, Azure, GCP)

Experience engineering software within an Amazon Web Services (AWS) cloud infrastructure

Troubleshoot and resolve problems with existing cloud controls.

Knowledge of the OWASP Top 10

Experience with vulnerability risk and impact assessment

Understand how to integrate security capabilities in cloud and application lifecycle management platforms especially in a DevOps model

Excellent written and verbal communication skills

Strong sense of urgency and ownership

Consistently prioritizes safety and security of self, others, and personal data.

Embraces diverse people, thinking, and styles.

Possesses a high school diploma, GED, or high school equivalency.

Is at least 18 years of age and has authorization to work in the United States.

WHAT WILL GIVE YOU A COMPETITIVE EDGE (PREFERRED QUALIFICATIONS)

Extensive experience in application security and ethical hacking

Extensive experience exploiting web, mobile and application security vulnerabilities

Extensive experience in software development

Experience integrating secure coding techniques with product teams

Professional certifications such AWS practitioner, cloud security certification for AWS, and CISSP

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. NLB is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, contact HR department by sending an e-mail to notifications@nlbservices.com.

DirectEmployers