What are the responsibilities and job description for the Application Security Engineer position at Tandym Group?
An entertainment organization in New Jersey is currently seeking a new Application Security Engineer to join their team.
Responsibilities:
- Develop, enhance, and maintain security testing methodologies, including dynamic application security testing (DAST) and other security assessment tools
- Perform penetration testing across web applications, mobile platforms, and APIs to identify and remediate vulnerabilities prior to deployment
- Support DevSecOps program and secure software development lifecycle (SSDLC) initiatives
- Enable continuous integration and continuous deployment of applications and infrastructure by the adoption of Secure Software Development Lifecycle pipelines
- Identify vulnerabilities, perform false-positive analysis, remediation recommendations to mitigate risk present in the applications
- Ensure assets supporting applications and infrastructure are protected against the latest attack techniques by deploying automated software update tools
- Track, monitor, follow-up, and drive conversations to mitigate identified vulnerabilities
- Triage, prioritize, and coordinate remediation efforts to reduce the company's overall security risk Automate security processes and develop scripts or integrations to improve program efficiency
- Collaborate closely with cross-functional business units to drive essential security initiatives
- Support program maturity and compliance initiatives by expanding adherence to leading cybersecurity frameworks
Qualifications:
- 4 years of experience in Cybersecurity
- Bachelor's degree in Cybersecurity, Computer Science, or a related field
- Hands-on experience in Web, Mobile, and API Security
- Strong understanding of application security, penetration testing, and various strategies used to monitor and mitigate risks
- Technical expertise and deep understanding of application security concepts, tools, & practices
- Proficiency in manual application security penetration testing (web, mobile, and API) and associated tooling
- Experience in Python, Perl, JavaScript, and Shell scripting
- Expertise in working with CI/CD tools and pipeline such as Azure DevOps, GitHub, and BitBucket
Desired Skills:
- Advanced Degree or relevant certifications (OSWA, OSWE, OSCP)