Role: Security Applications Developer
No visa
restriction
local candidates are the preference/priority
I'm not looking for a cyber or network security person but a developer who has worked on
security apps.
AWS is required.
The main function of a Security Engineer
is to plan, coordinate, and implement security measures for information systems
to regulate access to computer data files and prevent unauthorized
modification, destruction or disclosure of information. A typical data security
administrator is responsible for planning, coordinating and implementing security
measures to safeguard the computer database.
- Required:
- Solid Java Knowledge, and ideally at least historical
Development Skills; e.g. a good understanding of the language, a few
related frameworks (e.g. Spring, Hibernate, …).
- Strong desire to make their career path
- Strong
understanding of both Web Application and Web Service architectures, as
well as associated protocols
- Application Security (AppSec) domain
knowledge/experience, with knowledge of most common vulns; in order of
preference:
- Manual source code review
- Experience analyzing DAST/SAST scan results (not just running
the tools); Ideally
with AppScan and Checkmarx
- Application penetration testing; ideally with BurpSuite
- Web Application Firewall (WAF) knowledge/experience
- Networking fundamentals (ideally security-centric)
- Basic understanding of Cloud Computing (AWS strongly preferred)
- Highly Desired:
- Either hands on AWS Development Skills (e.g. ideally not just
AWS Console access, but API level exposures) OR solid
AWS Security knowledge; possibly with AWS certification.
- Python Knowledge + Development Skills
- Relevant Credentials, such as (Masters in Cybersecurity,
OSCP, CEH, …)
- Capture the Flag (CTF) / red team exercise experiences.
- Desired:
- Selenium testing automation