What are the responsibilities and job description for the Application Security Engineer in dynamic application security testing (DAST) & Automation position at Bey?
Job Description
Job Title: Security Engineer
Duration: 12 Month (s)
Location: New York, NY / Winston-Salem, NC / Charlotte, NC/ Plano, TX / San Francisco, CA – Fully Onsite Role
Job Description:
- Lead or participate in computer security incident response activities for moderately complex events.
- Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies.
- Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards.
- Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security.
- Review and correlate security logs.
- Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity. Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives.
- Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals.
Required Qualifications:
- 4 years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
- We are seeking Senior Information Security Engineer to conduct dynamic application security testing (DAST) using automated penetration testing tools.
- Review test results from tools
- Ensure that automated tests are completed successfully
- Identify and remove any false positives from automated testing tool reports
- Triage & Disposition results and enforce a Bug Bar
- Verify/validate defect fixes
- Provide application security consulting SME Support to developers
- Assist developers with understanding of security defects and risk
- Assist in defining acceptable solution to fix defects
- Communicate and document security risks, issues and controls for security planning purposes with line of business liaisons
- Help maintain Security Coding Standards and Bug Bar as required
- Provide training
- Develop and review malicious use cases/threat models
- Certifications such as GPEN, GWAPT, OSCP, and CEH are desirable but not required.
- Cloud Computing
- The resources will be expected to be in-office 5 days per week.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Application Security Engineer II
504 CGCG-US CG Companies Global-US -
New York, NY
Security Engineer II - Application Security
Datadog -
New York, NY
Security Engineer II, Stores Application Security
Amazon -
New York, NY