We are looking for Application Security Engineer (Remote). Focus on tool implementation, integration, and automation experience. Strong DAST and SBOM tool experience; experience with ServiceNow integration; experience with Palo Alto XSOAR/Palo Alto XSOAR integration; experience with leading Application Vulnerability Management platforms. If you or know anyone would be interested please reach out to me at praveen.vemula@teksalt.com
Top Skills
Developing and executing POC test plans for SBOM and/or DAST tool, generating POC reports
Implementing, testing, and validating enhanced SBOM capabilities of existing tools
Implementing, testing, and validating new SBOM and/or DAST tools
What You’ll Do
Participating in evaluating existing tools for suitability in meeting enhanced SBOM requirements
Participate in developing selection criteria of SBOM and/or DAST tools based on functional requirements and organizational priorities
Participating in market research and assessment of candidate SBOM and/or DAST tools
Establishing and verifying test environment resources and capabilities for performing POCs of SBOM and/or DAST tools
Developing and executing POC test plans for SBOM and/or DAST tool, generating POC reports
Implementing, testing, and validating enhanced SBOM capabilities of existing tols
Implementing, testing, and validating new SBOM and/or DAST tools
Integrating new SBOM and/or DAST tools with existing Application Vulnerability Management and other enterprise tools such as:
ServiceNow
Palo Alto XSOAR
Required Qualifications
BS in Computer Science, Software Engineering, Cybersecurity or an equivalent technical degree.
Strong knowledge of OWASP Top 10 Application Security Risks, CWE Top 25 Most Dangerous Software Weaknesses, etc.
Experience with tool integration using APIs, scripting, and custom-coding as needed
Experience with software vulnerability management, including thorough vulnerability risk analysis and mitigation plans.
5+ years’ experience in DevSecOps with a focus on onboarding and optimizing security tooling such as DAST, SAST, SCA, etc. in a DevOps environment.
Experience working with continuous integration and continuous deployment (CI/CD) pipelines as well as how security fits into the delivery process (i.e. DevSecOps).
Experience with developer tools such as source code repositories (Github/Gitlab, CI servers, IDEs, test automation tools, etc.).
Experience with containerization technologies including Docker and Kubernetes.
Knowledge of cloud platforms such as AWS and/or Azure.
Prefer prior experience with Invicti DAST implementations.
Knowledge of SBOM and VEX.
Ability to apply secure engineering best practices, problem solving, analytical skills and technical troubleshooting skills.
Excellent written and verbal communication skills with ability to communicate problem statements and solutions to both technical and non-technical stakeholders.
Proven ability to write clear and concise technical documentation.
Thank you,
Praveen
TekSalt Solutions
praveen.vemula@teksalt.com
612-852-4887