Sr. Security Engineer - Information Technology
Atlanta, Georgia Contract Added - 10/16/24
Job Description
Innova Solutions has a client that is immediately hiring for a Sr. Application & Cloud Container Security Engineer.
Position type: Contract with possible extension.
Duration: 12+ Months
Location: Atlanta, GA 30354 (Hybrid)
As a Sr. Application & Cloud Container Security Engineer, you will:
- Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Source Code Analysis (SCA) using Veracode.
- Correlate findings from tools such as the Veracode Source Code Agent to identify the presence of vulnerable methods in code.
- Research open-source community contributors and the NIST National Vulnerability Database (NVD) to understand residual risk and recommend a course of action.
- Determine how frequently and quickly fixes should be delivered for open-source findings.
- Review SCA reports to track new components and changes to existing SCA components in the environment.
- Have experience working with tools such as Sonatype Nexus Firewall and Nexus Lifecycle to track and block risks associated with third-party components.
- Work within the DevSecOps model to secure containers using ROSA, Tekton, and OpenShift pipelines.
- Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements.
- Guide development teams in integrating new services and applications into the CI/CD pipeline, troubleshoot installations, and build automated deployments of products into a high-security architecture.
- Possess knowledge of CI/CD orchestration tools such as Jenkins, Tekton, GitLab, or Bamboo.
- Provide operational support for container security tools (e.g., Palo Alto Prisma, Aqua, Wiz, or equivalent).
- Perform baseline image validation of new container template images.
- Evaluate scan results for container runtime environments to reduce security risk.
- Troubleshoot any connectivity or operational issues for clusters being evaluated in the Prisma tool.
- Validate and address vulnerability and threat findings from static and dynamic analysis tools.
- Characterize threats and provide recommendations for remediation; manage remediation efforts to completion.
- Develop and present findings and remediation reports to audiences, including team members from all department areas and levels of the company.
- Perform security reviews of software designs and assist developers to ensure the quality and robustness of our internal products.
- Conduct security assessments against web applications and APIs across a variety of technology stacks.
- Ensure adequate security requirements and privacy by design are built into all architecture, infrastructure, and projects.
- Integrate threat modeling practices into the application testing lifecycle.
- Impart application security and ethical hacking expertise into team processes.
- Drive improvements in the security testing practice, including execution methodology and metrics.
- Promote awareness and knowledge of security within the developer community.
- Continuously improve proficiency in application and API exploitation, tools, techniques, and countermeasures.
The ideal candidate will have:
- A B.S. degree in Computer Science, Computer Engineering, Information Assurance, or a related field.
- Professional experience in application security, penetration testing, security assessment, secure software development, or a related field.
- Hands-on experience working with Cloud and/or DevSecOps-related technologies.
- An excellent understanding of DevSecOps techniques and processes, with the ability to guide the integration of various tools in DevSecOps processes (GitLab/GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization).
- Familiarity with the AWS Well-Architected Framework or TOGAF and the ability to apply those principles while designing a solution.
- Experience building and supporting applications in the Cloud (AWS, Azure, GCP).
- Experience engineering software within an Amazon Web Services (AWS) cloud infrastructure.
- The ability to troubleshoot and resolve problems with existing cloud controls.
- Extensive knowledge of the OWASP Top 10.
- Experience with vulnerability risk and impact assessments.
- Experience integrating security capabilities in cloud and application lifecycle management platforms, especially in a DevOps model.
- Extensive knowledge of static analysis tools and flaw triage tools such as HP Fortify, IBM Rational, Veracode, Coverity, FindBugs, FindSecurityBugs, Brakeman, and open-source scanning tools like Sonatype CLM.
- Excellent written and verbal communication skills.
- A strong sense of urgency and ownership.
Qualified candidates should APPLY NOW for immediate consideration!
PAY RANGE AND BENEFITS:
Pay Range*: < $57-62/hr. on W2 >
*Pay range offered to a successful candidate will be based on several factors, including the candidate's education, work experience, work location, specific job duties, certifications, etc.
Benefits: Innova Solutions offers benefits (based on eligibility) that include the following: Medical & pharmacy coverage, Dental/vision insurance, 401(k), Health saving account (HSA) and Flexible spending account (FSA), Life Insurance, Pet Insurance, Short term and Long term Disability, Accident & Critical illness coverage, Pre-paid legal & ID theft protection, Sick time, and other types of paid leaves (as required by law), Employee Assistance Program (EAP).
ABOUT INNOVA SOLUTIONS: Founded in 1998 and headquartered in Atlanta, Georgia, Innova Solutions employs approximately 50,000 professionals worldwide and reports an annual revenue approaching $3 Billion.
Innova Solutions is an Equal Opportunity Employer and prohibits any kind of unlawful discrimination and harassment. If you are an individual with a disability and need a reasonable accommodation to assist with your job search or application for employment, please contact us at or (770) 493-5588.
#J-18808-Ljbffr