Application Security Engineer
Indexed description
You will join our team in partnership with New York State of Health (NYSoH) to provide comprehensive health coverage to more than 7.2 million New Yorkers through its Health Benefit Exchange (HBE)
How You Ll Make An Impact
- You ll join our talented Development Team. Our project is built on a multi-tier architecture including Service Oriented architecture, multi-tier web applications using Java and various other COTS products.
- Work closely with development teams to diagnose, document, and remediate application security vulnerabilities and identify appropriate security checkpoints in SDLC.
- Perform risk-based, technical assessments/penetration tests of applications, using dynamic and static scanning tools, and audits ensuring compliance with industry standards
- Consult with Development leadership on application development training.
- Research new attack vectors and stay current with cybersecurity news and trends.
Required Experience
8+ years Information Technology.
5+ years in software development role as a Developer, or Architect
Java/Web development with strong secure coding background in RHEL and JBoss.
3+years with Application Security Engineering conducting assessments, penetration testing, implementing tools for dynamic /automated code review, dynamic and static application scanning (Fortify, SonarQube); consulting on security designs of applications, potential vulnerabilities, and remediation, and creating training materials on key security concepts.
Hands-on experience assessing new code commits, pull requests, and architecture changes for vulnerabilities, misconfigurations, and compliance risks.
Hands-on experience integrating AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities and insecure coding patterns before deployment.
Hands-on experience designing and executing a repeatable process to aggressively prioritize issue dispositions and remediations of security findings while providing clear, concise status updates and risk reporting to leadership and stakeholders.
Skills
Strong oral and written communication skills, with a demonstrated ability to communicate complex topics to colleagues, and management.
Demonstrated collaboration and teaching abilities.
Strong analytical skills.
Identify and resolve problems in a timely manner; gather and analyze information skillfully; develop alternative solutions.
Critical thinking and creative problem solving
CISSP, CEH, CISA, OSCP, OSCE, or OSWE Certifications
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search