Description
The successful candidate will perform application security assessments, code reviews, and Software Development Life Cycle (SDLC) security consulting in a customer environment. The candidate will be responsible for identifying specific and systemic security issues within applications and the application development and life cycle maintenance process, and will also be a resource for the client in establishing and expanding the base of client knowledge in the area of application security.
Projects may include:
Performing application vulnerability and security assessments
Performing application security risk assessments
Performing code review across a variety of programming languages
Performing assessments of SDLC processes
Developing testing scripts and procedures
A successful candidate will likely possess some or all of these qualifications as well:
Experience with web application development (eg, ASP.NET, ASP, PHP, J2EE, JSP) Application security experience with high level programming languages (eg, Java, C, C++, .NET (C#, VB)
Experience leading software development projects
Experience with threat modelling and security risk assessment
Experience with vulnerability scanning tools (eg, Qualys, Nessus, Nexpose, Saint)
Experience with web application vulnerability scanning tools (eg, IBM AppScan, HP, Webinspect, Accunetix, NTO Spider, Burpsuite Pro)
Basic knowledge in application development and coding in modern languages
Basic knowledge in OWASP tools and methodologies
Basic knowledge in and understanding of HTTP and web programming
If this role is of interest to you, please get your CV forward to Viro (see below), along with a valid phone number.