Security Engineer - Remote

SemanticBits
Posted 3 years ago

Summary SemanticBits is looking for a Security Engineer to keep our business, users, and data safe by assuring the security of our applications and platforms. This will be a highly collaborative position, in which the right candidate works to secure existing applications and platforms, makes platform and security enhancements, and helps to scale our security program through automation, process improvement, and tool creation. The selected candidate will be required to work on multiple products and must be able to develop and present secure solutions and advice to technical teams as well as leadership. The candidate will further be required to assess risks and advise on security standards, best practices, and solutions. All this must be done by maintaining security quality and customer satisfaction. Responsibilities

  • Collaborating with various teams to secure new platforms/applications
  • Implementing platform security and framework improvements
  • Implementing analysis and monitoring tools
  • Working with engineering and QA teams to build tools and scale security in a continuous deployment environment
  • Assessing the security of applications, APIs, and platforms via penetration testing and code reviews
  • Document System Security plan and Contingency Plans for related projects

Required Qualifications

  • A Bachelor's degree or higher in Computer Science, Electrical Engineering, Information Assurance, Network Security Computer Engineering or a related field, or equivalent experience
  • At least 5 years of experience in the following: NIST 800-53 security controls, Penetration Testing, System Hardening (blue team), Programming/Scripting (java, node, python, etc), Incident Response
  • Strong knowledge to perform the following penetration testing: Static Analysis/Static Application Security Testing, Vulnerability Assessment/Scanning, Dynamic Analysis/Dynamic Application Security Test (DAST), Malicious Software Analysis
  • Strong foundation in one or more of the following: Data management security, Authentication, Applied cryptography, Linux security, Network &Cloud security
  • Advanced knowledge of Linux platforms
  • Advanced knowledge of application mobile security tools
  • Strong technical acumen securing software and hardwareUnderstanding of software development and working experience with any one of the higher level programming languages or scripting
  • Familiarity and experience with security technologies such as security engineering, security architecture, cryptography, data security, risk management, identity and access management, communication and network security, security assessment and testing, software development security, security operations
  • Familiarity and experience with popular open source security projects such as OWASP ZAP and Snort
  • Thorough understanding of issues documents in the OWASP Top Ten and CWE Top 25
  • Demonstrated ability to exploit and mitigate application-level vulnerabilities
  • Strong understanding of cryptography as applied to web application security (encryption, hashing, PKI management), including analysis and implementation
  • Experience using Linux/Unix at the command line for tasks related to web application development and deployment (DevOps)

One or more of the following certifications is preferred;OSCP, OSCE, OSWE, CISSP, GPEN, GXPN