Application Security Analyst
CaseWare, Canada

Experience
1 Year
Salary
0 - 0
Job Type
Job Shift
Job Category
Traveling
No
Career Level
Telecommute
No
Qualification
As mentioned in job details
Total Vacancies
1 Job
Posted on
Apr 10, 2021
Last Date
May 10, 2021
Location(s)

Job Description

CaseWare has gone remote first and this opportunity is open to applicants across Canada.
A bit about the role amp; team | the opportunity:
CaseWare is looking for an Application Security Analyst to join the Application Security team. The candidate will be a part of our growing security team to provide software security and software supply chain risk management expertise for the development, QA, DevOps and technology operation environments.
You will be part of a team that is committed to developing and delivering an integrated software with the other platforms made within CaseWare International and provide an excellent employee experience. Our customers are our distributors and resellers strategically placed globally who share the same goal of building a world class platform through customer obsession as us.
As part of the Application Security Team, you will be working with some great minds who are dedicated to CaseWare, the latest technology for cloud based apps and in a fast paced agile environment with a great team of people who only want to deliver the best to our users.Highlight of your responsibilities:
  • Responsible for Static Application Security Testing (SAST), and review security scan results and work closely with the development team to prioritize security vulnerabilities identified using a risk-based approach.
  • Participate in and support Dynamic Application Security Testing (DAST) and conducting penetration testing against CaseWare’s applications.
  • Participate in and support application security reviews and threat modeling.
  • Support and consult with product and development teams in the area of application security.
  • Develop scripts and/or automation and work with development and operation stakeholders to integrate automated security tools into the CI/CD pipeline.
  • Assist in development of automated security testing to validate that secure coding best practices are being used.
  • Research, identify, administer and support application security analysis tools.
  • Integrate security tools, standards, and processes into the software development life cycle (SDLC).
  • Manage application security framework and security technology improvement projects.
  • Be able to think both offensively (like a hacker) and defensively (evaluating product security and security architecture).
  • Perform any other application security or product security related activities or tasks as needed or directed.
  • Develop strong relationships across various levels of an organization to bring about positive results and communicate requirements effectively.
We are looking for someone who:
  • Can demonstrate experience in application security concepts such as secure coding, design or development and industry application security standards and best practices.
  • Has experience in performing manual penetration testing of applications to identify and recommend remediation to common.
  • Has experience in conducting risk assessment for application related security findings.
  • Has a good understanding of penetration testing processes, procedures and scoping requirements.
What you’ll bring:
  • Bachelor's degree in Computer Science or Engineering field.
  • An approach to application security from the risk management perspective.
  • Strong track record of using application security testing tools to perform static, dynamic code analysis, and penetration testing.
  • Deep hands-on experience with agile development processes and have experience integrating secure development practices into the model.
  • Experience writing and testing web applications and web services in the following programming languages: C/C++, Java, Python, TypeScript and JavaScript.
  • Experience working with a variety of development and testing tools, including: IntelliJ, Git, Jira, Confluence, Maven, New Relic, Jenkins, Cypress, Docker.
  • Expertise working with one or more SAST, DAST and IAST tools such as Veracode, BurpSuite, OpenVas, OWASP ZAP, NMAP, and Dependency-Track.
  • Experience in identifying and remediating common web application vulnerabilities as per the OWASP Top 10 and CWE 25.
  • Experience in application security concepts such as secure coding, design or development and industry application security standards and best practices.
  • Experience with cyber security attacks and best practices for mitigation methods.
  • Experience working with web applications and browser security; security assessments and penetration testing; identity and access control; applied cryptography and security protocols; security information and event monitoring and intrusion detection.
About CaseWareWith a head office in Toronto, CaseWare is one of Canada's original Fintech companies, having led

Job Specification

Job Rewards and Benefits

CaseWare

Information Technology and Services - Singapore, Singapore
© Copyright 2004-2024 Mustakbil.com All Right Reserved.