Vulnerability Security Engineer/Analyst

Vulnerability Security Engineer/Analyst

19 Jan 2024
Georgia, Atlanta, 30022 Atlanta USA

Vulnerability Security Engineer/Analyst

Vacancy expired!

End to End Systems Security analysis, Design and Implementation
Analyze, documentation and provide solution for any security breach / suspicious activity
Work with Incident response / threat management team to understand the impacted application and the issue
Use Splunk and Kibana ELK to analyze the logs for security threats or malicious behaviour
Analyze applications, identify threats, recommend new security remediation, and implement security policy, standards and procedures. Software/Application Development and Architecture - Secure App Development
Help App developers for secure coding practices using Fortify, Checkmarx (Static Assessment Security Testing), help them in mitigating vulnerabilities to produce secure code
Help developers in mitigating open source library vulnerabilities identified by Black Duck (SAST) by using latest versions of libraries in the source code. Use OWASP ZAP (Dynamic Assessment Security Testing), Client Web Inspect (DAST) and Burp Suite for Pen testing web application identifying vulnerabilities, exploiting them
Perform vulnerability assessment on the organization's network, servers using Tenable Nessus to identify and mitigate IP issues by applying patches
Integration of security engineering automation tools into CI/CD pipeline using Jenkins.Security Assessment: Conduct security reviews/assessments for all new and existing apps
Analyze apps on the basis of Security Best Practices and work with the testing team to create security testing test cases. Assess security requirements for new applications
Identify OWASP TOP 10 vulnerabilities and mitigate those issues. Implement Prevoty (RASP) for all applications. Implementation includes non-prod, prod deployment
Onboard Prevoty and Application Logs to Splunk for logging and monitoring purposes
Provide security testing signoff before deploying into Production, and create dashboards, alert setup for suspicious activity.Patching and Security Testing:
Secure source code testing using tools like Black Duck, Fortify, OWASP-ZAP, Client Web Inspect.Application Compliance and Reporting
Help application teams in managing compliance profile and adhere to company's security policies like PCI-DSS, CPI-81 etc
Work with the app and compliance team and making sure the SOX compliance requirements are met and applications are made SOX compliant
Use NIST Framework to make sure the organization is compliant following all the security guidelines protecting the confidential information
Use UML, Use Cases, Sequence Diagrams for Object Oriented Design and Graphic UI Design of Business Modules.Education Requirement: Bachelor's degree in Computer Science, Cybersecurity or a similar field.Kind regards,
Shradha Nimje
Sr IT Recruiter
Concept Software & Services Inc.
Alpharetta, GA 30022
Contact: +1
Email:

Related jobs

  • At ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can’t wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive for ingenuity. We know that your best work happens when you live your best life and share your unique talents, so we do everything we can to make that possible. We dream big together, supporting each other to make our individual and collective dreams come true. The future is ours, and it starts with you.

  • Summary:

  • Are you an experienced, passionate pioneer in technology who wants to work in a collaborative environment? As an experienced Project Delivery Senior Analyst-Senior Integration Engineer you will have the ability to share new ideas and collaborate on projects as a consultant without the extensive demands of travel. If so, consider an opportunity with Deloitte under our Project Delivery Talent Model. Project Delivery Model (PDM) is a talent model that is tailored specifically for long-term, onsite client service delivery.

  • Allied Universal® Executive Protection and Intelligence Services, North America’s leading specialized protection company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time executive protection jobs!

  • Meet MacStadium. We build cloud solutions to simplify Mac for business. We actively participate in and influence the Apple ecosystem in a cool way and have been a part of it since day one. Developers and end users at leading tech companies, big enterprises, and small teams rely on MacStadium’s innovative solutions every day. We have a passionate team of hard working, hard playing professionals with a big, shared vision. Come join us as we grow again!

  • At ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can’t wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive for ingenuity. We know that your best work happens when you live your best life and share your unique talents, so we do everything we can to make that possible. We dream big together, supporting each other to make our individual and collective dreams come true. The future is ours, and it starts with you.

  • Responsible for the design, testing, evaluation, implementation, support, management, and deployment of security systems/devices used to safeguard the organization’s information assets. Also responsible for analyzing the information security environment and assisting with the development of security measures to safeguard information against accidental or unauthorized modification, destruction, or disclosure. \'-Works with the technical team to recover data after a security breach. -Configures and installs firewalls and intrusion detection systems. -Develops automation scripts to handle and track incidents. -Investigates intrusion incidents, conducts forensic investigations and mounts incident responses. -Delivers technical reports and formal papers on test findings. -Installs firewalls, data encryption, and other security measures. -Maintains access by providing information, resources, and technical support. -Ensures authorized access by investigating improper access; revoking access; reporting violations; monitoring information requests by new programming; recommending improvements. -Updates job knowledge by participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations. -Accomplishes information systems and organization mission by completing related results as needed. \'-Builds, deploys, and tracks security measurements for computer systems and networks. -Mitigates security vulnerabilities by implementing applicable solutions and tools. -Performs vulnerability testing, risk analyses, and security assessments. -Collaborates with colleagues on authentication, authorization, and encryption solutions. -Tests security solutions using industry standard analysis criteria. -Responds to information security issues during each stage of a project’s lifecycle. -Performs risk assessments and testing of data processing systems. -Establishes system controls by developing framework for controls and levels of access; recommending improvements

Job Details

  • ID
    JC32069122
  • State
  • City
  • Job type
    Permanent
  • Salary
    BASED ON EXPERIENCE
  • Hiring Company
    Concept Software & Services, Inc.
  • Date
    2022-01-18
  • Deadline
    2022-03-19
  • Category

Jocancy Online Job Portal by jobSearchi.