What are the responsibilities and job description for the Security Specialist position at Smart Folks Inc.?
Job Details
Role:
The Security Specialist will formulate plans and work towards client Development team to integrate build tools with Enterprise security tools. The Specialist will identify security weaknesses and evaluate the risk posture. This role will be responsible for security services delivery, including the use of application security tools for detection, triage, and remediation of security weaknesses. The Specialist will partner with our client development and business teams to explain relevant security weaknesses and provide guidance for remediation. The Specialist is also responsible of preforming manual/automated security analysis and look for loopholes of applications written in different programming languages.
This role reports to the Sr. Manager of Enterprise Risk and Compliance.
Responsibilities
Perform triage of the results found by tools to determine true positives and eliminate the false positives.
Develop proof of concepts to demonstrate the severity of the attacks to the developers.
Work with the development teams to integrate their build process with the automated scan tools.
Conduct kick off meetings with application team to understand the applications architecture, business logic and source code repository
Assess and report security weaknesses and their risk according to client s application penetration testing methodology
Document and report security weaknesses in client systems and provide detailed reports to appropriate development and business teams
Work directly with Client development teams to provide remediation guidance for identified security weaknesses
Identify testing methodology or process improvements and make recommendations to EIP Application Security Teams
Perform other security checks like Authorization, session management, SSL test, encryption algorithms check to look for issues.
Organize onboarding meetings with application teams to explain them the details of security testing engagement, Secure SDLC and the timelines for each project.
Perform personal research to stay current on security trends, new vulnerabilities, and technology
Other duties as assigned
Experience Qualifications
5 years of experience SAST and SCA security tools; Checkmarx and CheckmarxOne, and Nexus IQ
5 year of experience developing new queries and customizing the existing security tools queries that are not out of the box to find new vulnerabilities
5 years of experience conducting end-to-end SAST and SCA analysis, using commercial application scanning tool.
5 years of experience application onboarding, triaging, remediation with application teams and verifying proposed findings.
3 years of recent, hands-on development experience, working with, or developing RESTful APIs in a modern, automated development environment including a deep understanding of CI/CD.
3 years, with expert-level skills, in SDLC workflow management tools like Jira, Confluence, SharePoint or similar.