Vacancy expired!
- Developing automation & complex orchestration to scale out the vulnerability tools, output of vulnerability data and correlated (enrichment) data across the organization
- Assist with maintaining pipeline integration of security tools into various development SDLCs
- Educate Engineers, developers, and product teams on the importance of vulnerability management, effectively utilize the tools and remediate findings identified in an automated fashion
- Continually evaluate the current state of the program; work with the team constantly find ways to automate and develop future roadmap
- Communicate complex technical issues simply to different audiences
- Ability to quickly learn new Information Security concepts and adapt to a fast-paced, ever-changing organization
- BS or MS degree preferred in computer science, information assurance
- Expertise in interpreted languages (Python is a must) and high-level languages (Java script, .Net, PowerShell) with full-stack development experience
- Hands on experience with ETL tools (i.e. Apache Nifi, MS-SSIS, jasper) and concepts
- Software development background and strong knowledge of software development lifecycles
- Previous experience deploying and maintaining configuration as code systems, services, containers and applications in AWS, Azure and/or Google Cloud Platform
- Hands on experience with Vulnerability management tools such as Tenable, Rapid7, or Qualys, Twistlock
- Ability to develop and communicate recommendations to management
- Ability to translate technical security vulnerabilities into business risk
- Strong problem-solving and conceptual thinking abilities
- Strong ability to reverse engineer tools, exploits and open-source applications and ability to develop them
- Experience looking for application security vulnerabilities such as Cross Site Scripting, SQL Injection, Cookie Manipulation, Buffer Overflows, etc.
- In-depth familiarity with Windows and Unix Operating Systems