What are the responsibilities and job description for the IT Security Specialist 2 position at American Business Solutions Inc.?
Engagement Type
Contract
Onsite
- Security Integration: Integrate security as an integral part of the CI/CD pipeline, automating security testing and scanning processes.
- Vulnerability Management: Identify, assess, and manage security vulnerabilities throughout the SDLC.
- Security Automation: Implement and maintain security automation tools and scripts to streamline security processes.
- Threat Modeling and Risk Assessment: Conduct threat modeling and risk assessments to identify potential security vulnerabilities.
- Security Policy and Compliance: Enforce security policies and ensure compliance with agency policies and relevant regulations and standards.
- Collaboration: Work closely with other IT teams and stakeholders to ensure security best practices are followed.
- Incident Response: Participate in security incident response and recovery efforts.
- Continuous Improvement: Continuously improve security practices and tools based on industry best practices and emerging threats.
Documentation: Document security processes, procedures, and findings.
Required/Desired Skills Skill Required/Desired Amount of Experience College Degree Required 4 Years Proficiency with security scanning and vulnerability management tools (Qualys, Checkmarx, AutoRabit CodeScan) Required 4 Years Proficiency with DevOps platforms (Azure DevOps, Copado) Required 4 Years Proficiency with operating systems (Windows, Linux) Required 4 Years Experience with administering (security controls and management) Cloud computing platforms (Salesforce) Required 4 Years Working knowledge of security frameworks and standards (OWASP Top10, SANS 25, NIST SP 800-53, etc.) Required 4 Years Working knowledge of web application security tools (F5 Web Application Firewall, Cloudflare, AppOmni) Required 4 Years Working knowledge of SIEM/SOAR tools (Chronicle, Splunk) Required 4 Years Working knowledge of integration platforms (ServiceNow, MuleSoft, Oracle Integration Cloud, Tibco) Required 4 Years CompTIA Security Certification Highly desired 0 CySA Certification Highly desired 0 CISM Certification Highly desired 0 CISA Certification Highly desired 0 Familiarity with scripting and programming languages (Python, Power Shell,.Net) Nice to have 0 Familiarity with Cybersecurity platforms (CrowdStrike) Nice to have 0