What are the responsibilities and job description for the Application Security Engineer position at Prism, Inc.?
Job Details
This hybrid remote position must be onsite in Greenbelt, MD with (1) day of remote work.
Must be local to MD, DC, VA (Greater Washington, DC Area)
Due to Federal Government Security Clearance Requirements: U.S. Citizenship OR Perm Resident
PRISM Seeks Web Application Security Engineer: Be a Digital Guardian on the Front Lines
Are you a cybersecurity warrior with a keen eye for vulnerabilities? Do you thrive in the fast-paced world of web application security, constantly innovating to stay ahead of evolving threats?
If you're a passionate Web Application Security Engineer looking to make a real impact, we want you on our team!
Join us and become a guardian of our digital fortress!
Here's what awaits you in this exciting role:
- Become a Security Superhero: Identify, analyze, and eliminate vulnerabilities in our web applications before malicious actors can exploit them. You'll be our frontline defense against cybercrime!
- Penetration Testing Prowess: Conduct penetration testing to simulate real-world attacks and proactively discover weaknesses in our applications.
- Secure Coding Champion: Collaborate with developers to champion secure coding practices and build security into the fabric of our applications from the ground up.
- Stay Ahead of the Curve: Continuously learn and adapt to the ever-changing threat landscape, staying informed about the latest hacking techniques and security best practices.
- Automation Advocate: Develop and implement automated security testing tools to streamline processes and maximize efficiency.
Required:
- Bachelor s degree in Computer Science or four additional years of software development.
- 5 years of experience with application development, security, or related fields.
- 3 years' experience in application security technologies, with knowledge of application security threats. Experience with threat modeling, attack surface analysis, penetration testing, software vulnerability assessments, and understanding of software security threat vectors.
- Knowledge of Component Analysis using tools such as OWASP Dependency-Check, Bytesafe Dependency Checker, Patton, PHP Security Checker, etc.
- Knowledge of burp suite, MetaSploit, Nessus is a must.
- Some Experience with static and dynamic application security testing.
- Required Certifications (at least one from this list):
- Certified Secure Software Lifecycle Professional (CSSLP) from ISC2
- Certified Application Security Engineer (CASE) from EC-Council
- GIAC Penetration Tester (GPEN) from SANS Institute
- GIAC Web Application Penetration Tester (GWAPT) from SANS Institute
- Certified Penetration Testing Professional (CPENT) from EC-Council
- Secure Programming Certified Leader (S-CSPL) from SECO Institute