Infosec Engineer IV
- SAST
- DAST
- Penetration Testing
- Java
- Python
- WAF
- Microservices
- NIST
- OWASP
- AWS
- Azure
- GCP
- Oracle
- Docker
- Kubernetes
- CSSLP
- GWAPT
- CEH
- CISSP
- CCSP
Job Description:Â Â
Application security engineer will be executing automated application Security tools for security Â
weaknesses, performing vulnerability scans, managing security tools and providing security guidance  to software development teams.Â
Responsibilities: Â
• Execute automated SAST and SCA scans to identify security vulnerabilities in web, API, and mobile applications.Â
• Perform manual secure code reviews to validate findings and detect security issues not identified by automated tools.Â
• Analyze vulnerability scan results, prioritize risks, and provide remediation recommendations to development teams.Â
• Collaborate with developers to resolve security issues and promote secure coding best practices.Â
• Integrate application security testing into the Software Development Life Cycle (SDLC) to ensure security is embedded throughout development.Â
• Manage application security tools, perform re-validation of fixes, and support continuous improvement of the organization's application security posture.Â
Key Skills Required:Â
• Expertise in automating secure coding tools and processes (SAST, SCA, DAST, Mobile & API Security). Â
• Review security test results from vulnerability scans, penetration testing for true positives and propose appropriate remediation measures or mitigation control. Â
• Experience with programming languages such as Java, Python, or Go, and at least one scripting language. Â
• Knowledge on WAF.Â
• Knowledge of web, mobile, API, Microservices and network pen testing. Â
• Knowledge of security best practices, principles, and common security frameworks, such as NIST and OWASP,Â
etc. Â
• Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities. Â
• Knowledge of AWS, Azure, Google cloud or Oracle is preferable. Â
• Knowledge on securing container platforms such as docker and Kubernetes. Â
• Ability to interact with a broad cross-section of personnel to explain and enforce security measures. Â
• Good written and verbal communication skills.Â
Education & Experience:Â
• Bachelor's degree in Computer science, Information Technology, Cyber Security, or related discipline or equivalent experience. Â
• 4 to 6 years of Application Security experience with knowledge on security tools and vulnerabilities.Â
• Certifications: • CSSLP • GWAPT • CEH • CISSP • CCSPÂ
Infosec Engineer IV · 7-Eleven