Security Application Engineer---------------Need GC and USC
Posted today
usm systemsSeattle (WA)
Information Security EngineersComputer Systems Design Services
SENIORITY
Lead
About the role
Job DescriptionSecurity Application EngineerSeattle (Bellevue, WA) Long Term ProjectNeed GC and USCMust have IBM App Scan, Fortify, BURP Suite, Kali Linux, SOAP UI, Application Test, Penetration Test expertiseTop Three Skills: 1) IBM App Scan 2) Web Services Tools (SOAP UI, BURP Suite, Kali Linux) Job Description: Security team is seeking an enthusiastic Security Application tester who will test applications for security compliance. The successful candidate will have experience with Enterprise Applications and Information Security.The scope of applications to be tested are software that are used to run its business, not software which is sold or provided to end customers. The type of applications range from web services to line of business applications to mobile or cloud applications. Candidates will be responsible for insuring all applications meet enterprise minimum security specifications and escalate for potential deviations when they do not.Being able to communication clearly, establish partnerships with team members and stakeholders as well as potentially offload portions of the work to staff augmentation resources will be required. Essential FunctionsPerform security, compliance, and risk assessments on projects throughout project lifecycle using sdlc, waterfall or rup methodologiesSupport information security review of new technologies, designs, and remediation planning effortsInvestigates and identifies security needs & recommends plans/resolutions. Implements, tests & monitors info security improvements.Maintain visibility inside & outside of info security, interfacing with groups such as billing ops, application support, engineering ops, finance, legal, privacy, risk management, etc.Support info security policy lifecycle throughout, including intake, creation, review, approval, implementation, publishing, communication & maintenanceSupports security projects driven by groups both internal and external to info securityExperience with static and dynamic vulnerability identification using industry leading scanning tools and manual code reviewsExperience with the Top 10 OWASP (Open Web Application Security Project) vulnerabilities (most critical web vulnerabilities) and how to identify and remediate themSolid understanding of Information Security in general and the specific behaviors that would secure Intel's information assetsAbility to translate Information Security policies and procedures into language that a business and/or technical person can understand; and ability to effectively communicate with both non-technical and technical peopleStrong problem solving with the ability to methodically and objectively analyze and resolve Information Security challengesAbility to work well inside and outside the team. Exchanging ideas, knowledge, experience and thoughts can boost the quality and the efficiency of the solution, so great testers must always be eager to coordinate well with their team members and other teams as well.Great stakeholder management skills and experience due to the escalation processAdditional InformationIf you are interested in the below position please forward your profile to preethib@usmsystems(dot)com or call me on 703 468 0398.SummaryFunction: Information TechnologyExperience level: Mid-Senior LevelIndustry: Information Services
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
