Application Security Engineer
Location :BangaloreTotal Experience:
5+ years
Job Skills:
- BS degree or 3+ years of security tools experience focused on host and application security
- Coding proficiency related to configuration, deployment, and reporting against security tools
- Seasoned experience with integration/automation of toolsets, using custom approaches that require programming and job scheduling
- Experience working in cloud environments like AWS and Azure
- Self-driven, with a sense of responsibility and an internal drive to complete projects
- Strong proficiency with tools such Veracode, Burp Suite Professional, Blackduck, and Nessus
- Working knowledge of Rest API integration and related tools, including Postman
- Working knowledge of JSON, XML, HTTP headers, and related rest API
authentication/authorization approaches.
Responsibilities:
- Hands-on experience integrating security testing tools into build environments, including Jenkins and CircleCI
- Working knowledge of SAML and Okta setup/configuration as it relates to security scanning tools
- Programming proficiency in python, go, java or similar. Proficiency with shell scripting (bash or similar)
- Hands-on proficiency with Splunk, configuring searches and related dashboards and exposing this information to end-users securely. ELK stack experience can substitute for Splunk
- Experience deploying applications, databases, APIs, and lambda functions in AWS. GCP and Azure experience also a plus
- Working knowledge of host vulnerability scanning. Experience with Qualys, Nessus, Rapid7 or similar
- Working knowledge of static code analysis tools. Experience with Veracode, Coverity, Fortify, or similar
- Working knowledge of dynamic code testing tools. Experience with Acunetix, WebInspect, Burp, Zap, or similar
- Experience working with product teams for tool onboarding and related RBAC, ideally through automation
- Background assisting with the selection of security tools, including the development of requirements against which vendor offerings are measured
- Experience working with security vendors to ensure that feature requests and defects are triaged, assigned, and resolved in a timely manner.