What are the responsibilities and job description for the Security Analyst 2 position at eeho/CX_1/?
About the role
In this role of a Security Analyst, you will be conducting and documenting highly complex information security risk assessments and developing and implementing security processes. As a member of the Software Assurance team, you will be responsible for reviewing various security SAST and SCA tooling findings. You will ensure findings are not false positives by performing further analysis to increase the accuracy and quality of your reports. You will also be responsible for partnering with highly talented security researchers for planning, developing, and documenting processes while interacting with a variety of teams across our Software Assurance organization. There will be opportunities for improvement as you take on feedback from team members to raise the bar for yourself and your organization. You are comfortable with ambiguity and thinking outside of the box!
Who We Are
We are a world class team of high caliber application security researchers and analysts who thrive on new challenges. We are an inclusive and diverse team with a full spectrum of experience distributed globally. We have the resources of a large enterprise and the energy of a start-up, working on critical software assurance initiatives in collaboration with our cloud, data science, and mobile engineering teams. We are a dedicated team, leveraging each other’s insights and abilities to produce cutting edge solutions to difficult problems through automation and CI/CD. Join us to grow your career and create the future of software assurance at scale together.
Work You’ll Do
- Review and categorize software security analysis vulnerability findings
- Report and document vulnerability findings
- Identify duplications and false positive in vulnerability reports
- Partner with security researchers through ongoing vulnerability identification
- Seek out opportunities to improve systems and reporting mechanisms
What You’ll Bring
- Have a Master's degree in Computer Science, Cyber Security or related disciplines by August 2023.
- Good understanding of application security, CVE classification system (Common Vulnerabilities and Exposures) and OWASP top 10
- Have worked and understand report outputs through SAST and SCA tooling.
- Ability to review vulnerabilities in open-source software written in Java and/or GoLang, C/C , Python.
- Foundational skills in Python programming
- Familiar with SCM/software version control tools (e.g., Git)
- A strong interest in application security, willingness to learn and seek out information to solve challenging problems is essential
- Strong analytical skills combined with good communication skills and fluent English
- Eligibility to work in the United States without sponsorship is essential
- Desire to work onsite
- Reside in the United States and/or attend a university in the US.
- Able to obtain work authorization in the US in 2023.
Nice to Have
- Prior experience in a software development role
- Knowledge and experience of security testing tools
- DevSecOps and/or CI/CD experience
- Automation experience using Python
What We’ll Give You
- The ability to work onsite with a talented team
- A team of very skilled and diverse personnel across the globe
- Ability to work in a flexible work from home arrangement
- Exposure to mind blowing large-scale cutting-edge systems
- The resources of a large, global operation while still having the small, start-up feel of a smaller team day to day
- Develop new skills and competencies working with our vast cloud product offerings
- Ongoing extensive training and skills development to further your career aspirations
- Incredible benefits and company perks
- An organization filled with smart, enthusiastic, and motivated colleagues
- The opportunity to impact and improve our systems and delight our customers