Home

IT Security Auditor --134181--Locals @ MI --Client:'State of MI' at Remote, Remote, USA
Email: [email protected]
Hi,

We have a great
opportunity with one of our clients. We are looking for an IT Security
Auditor. I believe your profile and skill set are compatible with this
opportunity. Please go through the JD and let me know your views.

Title
: IT Security Auditor

Location
: Dimondale, MI

Description:

Senior
Full Stack Application Development Security Auditor who is passionate about
designing and building secure platforms and applications through Dynamic,
Static, and Software Composition Analysis assessments. This position is not a
member of the Security Operations Center, rather it is dedicated to working
with software development teams on secure coding practices. The ideal candidate
will feel comfortable working with both front-end, back-end, and cloud-based
application developers. Partnering with distributed teams to help transform the
way systems are built, secured, authorized, and securely operated for
continuous compliance and risk mitigation. Specifically, this candidate will
help lead efforts to implement security patterns and practices with orchestration
and automation tools that automate the secure configuration, verification,
compliance, and authorization of systems and their development. They will be a
key member of a team tasked with maturing the organization's secure software
development practices.

Minimum
of 5+ years of total IT-related experience.

3+
years implementing/utilizing Federal, Industry, and Open-Source Security
Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top
25, Critical Security Controls, Cloud Security Alliance, SafeCode, etc.)

3+
years with both compiled and interpreted languages such as Angular, React,
Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET
stacks

3+
years with networking, infrastructure, secure application development, and
security automation (DevSecOps).

3+
years of hands-on knowledge building and deploying secure complex
distributed web and mobile applications.

Functional
Knowledge:

Chrome/Firefox/Edge
Development tools to see the request/response headers

Experience
with Application Security scanning tools (SAST, DAST, SCA, ASOC,
Container/Cloud) is a must.

Experience
with Coverity, BlackDuck, SRM, and Fortify a plus.

HTTP
Request/Response headers for web and Restful API calls

Ability
to explain in detail any of the OWASP top 10 vulnerabilities

Cross-site
scripting, Injection attacks, SSRF, CSRF, XML entity, etc.

API
Security

JWT

OAUTH/OIDC/PKCE

Web,
API replay attacks

High-level
understanding

Cloud
development experience (Azure, AWS, GCP)

Thanks & Regards,

Vinuth G

Real World Technologies Inc

Senior Technical Recruiter

Wixom, Michigan

248-516-7336 ext 312

--

Keywords: javascript information technology golang Michigan
IT Security Auditor --134181--Locals @ MI --Client:'State of MI'
[email protected]
[email protected]
View all
Sat Aug 24 01:31:00 UTC 2024

To remove this job post send "job_kill 1690242" as subject from [email protected] to [email protected]. Do not write anything extra in the subject line as this is a automatic system which will not work otherwise.


Your reply to [email protected] -
To       

Subject   
Message -

Your email id:

Captcha Image:
Captcha Code:


Pages not loading, taking too much time to load, server timeout or unavailable, or any other issues please contact admin at [email protected]
Time Taken: 33

Location: , Michigan