Information Security Engineer
Core
Conduct web application security assessments, manage application security assets, and partner with development teams to remediate vulnerabilities.
Role type
Web application security engineer
Builds
Secure web applications and software development lifecycle
Domain
Cybersecurity / Web Application Security
Required skills
Web application vulnerability assessment, OWASP Top 10 knowledge, HTTP/HTTPS and web architecture understanding, vulnerability remediation, secure coding principles, security testing tools (Burp Suite, OWASP ZAP), asset inventory management, false positive analysis
Preferred skills
Secure software development lifecycle (SSDLC) support, vulnerability management processes, security certifications (Security+, CEH, OSCP)
Technologies
Burp Suite, OWASP ZAP, WebInspect, HTTP/HTTPS, APIs
Responsibilities
Perform periodic security assessments and vulnerability testing of web applications; Conduct pre-production security assessments for new applications; Identify, analyze, and document web application vulnerabilities; Track vulnerabilities through remediation and perform retesting; Provide security guidance and training to developers; Investigate reported security concerns; Prepare vulnerability assessment reports and documentation; Collaborate with development and infrastructure teams to improve security posture
Seniority
Mid-level, hands-on IC