Application Security
Application Security (Fortify & Web inspect)
Client: Client
Bill Rate 60/hr
Location: Alpharetta, GA
Total Positions: 6
Mandatory Skills (Pls. detail as much as possible)
"* 8+ years of experience with Application Security domain performing App and Infra Scans.
* Hands on experience with security testing tools including Fortify, WebInspect, SonarType.
* Hands on Threat Modeling experience for web and mobile applications utilizing OWASP, NIST, SANS and other industry standard frameworks.
* Vulnerability management and reporting.
* Experience with DevSecOps is a plus "
Preferred Skills (Pls. detail as much as possible)
At least of one of CISSP, CompTIA Security+, GIAC Certification is preferred.
Job Roles/Responsibilities (Pls. detail as much as possible)
"* Will be leading a team of application security analysts and be responsible to perform app scans using FOP, FOD, WebInspect and SonarType.
* Responsbile to build DevSecOps and integrate it to the CI/CD pipleline.
* Utilize automated tools like Fortify, WebInspect, SonarType and implements processes to conduct system vulnerability scans and determine security postures of systems.
* Analyze security scans of information systems to identify and assess vulnerabilities.
* Coordinate with delivery teams, operations teams, and Chief Security Office, to identify and mitigate or remediate security vulnerabilities, implement security controls and/or frameworks
* Manual source code audit for critical business functionality & Execute business functionality security test cases.