Senior Security Engineer, Application Security

Full-time

United States, Georgia, Atlanta

Information Technology

07-Jun-2023

Ref # : 21016

LinkedIn Tag : #LI-MW1

How you'll help us Keep Climbing (overview & key responsibilities)

Do you enjoy solving advanced technical problems, and working with best-in-class security tools? Yearn for the opportunity to build a world class application security testing organization?

Enjoy building and maintaining successful relationships through direct interaction with peers, managers, and other technical teams?

Partnering with management to build a collaborative working environment while promoting high standards, exercising good judgment and professionalism?

If you do, then its sounds like you are just the person we are looking for to join our Information Security Team at Delta Air Lines.

The successful candidate can comprehend all aspects of Cybersecurity and apply technical application security testing expertise to assist in identifying application vulnerabilities.

As an analyst your responsibilities will include application security assessments, code reviews, container security, and manual API testing using tools like Burp Suite.

Experience implementing, deploying, and providing support for custom AWS Config Rules, CFN Hooks and CFN Guard Rules. Comfortable building and supporting applications in the Cloud (AWS, Azure, GCP).

Competence engineering software within an Amazon Web Services (AWS) cloud infrastructure. Experience integrating Open-source controls and tools into current enterprise architecture.

Have experience reviewing Open-source components to making recommendations to configuration or environmental changes that increase security or reduce risk. Key Responsibilities :

  • Conduct Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA) using VeraCode
  • Correlate findings from tools such as VeraCode Source Code Agent to identify presence of vulnerable methods in code
  • Research open-source community contributors and NIST NVD to understand residual risk and recommend course of action
  • Determine how frequently and quickly fixes should be delivered for open-source findings
  • Review SCA reports to track new and changes to SCA components in the environment
  • Experience working with tools such as Sonatype nexus firewall and lifecycle to track and block risk 3rd- party components
  • Work within the DevSecOps model to secure Containers, withing ROSA, Tekton and OpenShift pipelines
  • Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements.
  • Guide development teams in integrating new services and applications into the CI / CD pipeline, troubleshoot installations and build automated deployments of products into a high-security architecture.
  • Possess a knowledge of CI / CD orchestration tools such as Jenkins, Tekton, GitLab, or Bamboo.
  • Provide operational support for container security tools (Palo Alto Prisma, Aqua, Wiz or equivalent)
  • Perform Baseline Image validation of new container template images.
  • Evaluate scans results for container runtime environments to reduce security risk
  • Troubleshoot any connectivity or operational issues for clusters being evaluated in the Prisma tool.
  • Apply software development skills (e.g., Java, C#.NET, JavaScript) to recommend and apply secure coding practices
  • Validate and address vulnerability / threat findings from static and dynamic analysis tools
  • Characterizes threats and provides recommendations for remediation; manages remediation efforts to completion
  • Develops and presents finding and remediation reports to audiences including team members from all department areas and levels of the company
  • Perform security reviews of software designs and assist developers to ensure quality and robustness of our internal products
  • Conduct security assessments against web applications and APIs across a variety of technology stacks
  • Ensure adequate security requirements and privacy by design are built into all architecture / infrastructure / projects
  • Integrating threat modeling practices into the application testing lifecycle
  • Impart application security and ethical hacking subject matter expertise into team processes
  • Drive improvements in the security testing practice to include execution methodology and metrics
  • Drive awareness and knowledge of security in the developer community
  • Continually improve proficiency in application and API exploitation, tools, techniques, and countermeasures

Benefits and Perks to Help You Keep Climbing

Our culture is rooted in a shared dedication to living our values Care, Integrity, Resilience, Servant Leadership, and Teamwork every day, in everything we do.

At Delta, our people are our success. At the heart of what we offer is our focus on Sharing Success with Delta employees.

Exploring a career at Delta gives you a chance to see the world while earning great compensation and benefits to help you keep climbing along the way :

  • Competitive salary, industry-leading profit sharing program, and performance incentives
  • 401(k) with generous company contributions up to 9%
  • Paid time off including vacation, holidays, paid personal time, maternity and parental leave
  • Comprehensive health benefits including medical, dental, vision, short / long term disability and life benefits
  • Family care assistance through fertility support, surrogacy and adoption assistance, lactation support, subsidized back-up care, and programs that help with loved ones in all stages
  • Holistic Wellbeing programs to support physical, emotional, social, and financial health, including access to an employee assistance program offering support for you and anyone in your household, free financial coaching, and extensive resources supporting mental health
  • Domestic and International space-available flight privileges for employees and eligible family members
  • Career development programs to achieve your long-term career goals
  • World-wide partnerships to engage in community service and innovative goals created to focus on sustainability and reducing our carbon footprint
  • Business Resource Groups created to connect employees with common interests to promote inclusion, provide perspective and help implement strategies
  • Recognition rewards and awards through the platform Unstoppable Together
  • Access to over 500 discounts, specialty savings and voluntary benefits through Deltaperks such as car and hotel rentals and auto, home, and pet insurance, legal services, and childcare

What you need to succeed (minimum qualifications)

  • Minimum 5+ years of professional experience in application security, penetration testing, security assessment, secure software development or related field
  • Hands-on experience working with Cloud and / or DevSecOps related technologies
  • Excellent understanding of DevSecOps techniques and processes, guide integration of various tools in DevSecOps processes (GitLab / GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization).
  • Should be well versed with the AWS well architected framework or TOGAF and able to apply those principles while designing a solution
  • Experience building and supporting applications in the Cloud (AWS, Azure, GCP)
  • Experience engineering software within an Amazon Web Services (AWS) cloud infrastructure
  • Troubleshoot and resolve problems with existing cloud controls
  • Extensive knowledge of the OWASP Top 10
  • Experience with vulnerability risk and impact assessment
  • Experience integrating security capabilities in cloud and application lifecycle management platforms especially in a DevOps model
  • Extensive knowledge with static analysis tools and flaw triage such as HP Fortify, IBM Rational, Veracode or Coverity, FindBugs, FindSecurityBugs, Brakeman and Open Source scanning tools such as Sonatype CLM
  • Excellent written and verbal communication skills
  • Strong sense of urgency and ownership
  • Consistently prioritizes safety and security of self, others, and personal data.
  • Embraces diverse people, thinking, and styles.
  • Possesses a high school diploma, GED, or high school equivalency.
  • Is at least 18 years of age and has authorization to work in the United States.

What will give you a competitive edge (preferred qualifications)

  • B.S. degree in Computer Science, Computer Engineering, Information Assurance or related field
  • Extensive experience in application security and ethical hacking
  • Extensive experience exploiting web, mobile and application security vulnerabilities
  • Extensive experience in software development
  • Extensive experience integrating secure coding techniques with product teams
  • Professional certifications such AWS practitioner, cloud security certification for AWS, and CISSP
Apply Now

Related Jobs

Senior Security Engineer, Application Security

Delta Air Lines Atlanta, GA
APPLY

United States, Georgia, Atlanta

Information Technology

07-Jun-2023

Ref # : 21016

LinkedIn Tag : #LI-MW1

How you'll help us Keep Climbing (overview & key responsibilities)

Do you enjoy solving advanced technical problems, and working with best-in-class security tools? Yearn for the opportunity to build a world class application security testing organization?

Enjoy building and maintaining successful relationships through direct interaction with peers, managers, and other technical teams?

Partnering with management to build a collaborative working environment while promoting high standards, exercising good judgment and professionalism?

If you do, then its sounds like you are just the person we are looking for to join our Information Security Team at Delta Air Lines.

The successful candidate can comprehend all aspects of Cybersecurity and apply technical application security testing expertise to assist in identifying application vulnerabilities.

As an analyst your responsibilities will include application security assessments, code reviews, container security, and manual API testing using tools like Burp Suite.

Experience implementing, deploying, and providing support for custom AWS Config Rules, CFN Hooks and CFN Guard Rules. Comfortable building and supporting applications in the Cloud (AWS, Azure, GCP).

Competence engineering software within an Amazon Web Services (AWS) cloud infrastructure. Experience integrating Open-source controls and tools into current enterprise architecture.

Have experience reviewing Open-source components to making recommendations to configuration or environmental changes that increase security or reduce risk. Key Responsibilities :

  • Conduct Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA) using VeraCode
  • Correlate findings from tools such as VeraCode Source Code Agent to identify presence of vulnerable methods in code
  • Research open-source community contributors and NIST NVD to understand residual risk and recommend course of action
  • Determine how frequently and quickly fixes should be delivered for open-source findings
  • Review SCA reports to track new and changes to SCA components in the environment
  • Experience working with tools such as Sonatype nexus firewall and lifecycle to track and block risk 3rd- party components
  • Work within the DevSecOps model to secure Containers, withing ROSA, Tekton and OpenShift pipelines
  • Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements.
  • Guide development teams in integrating new services and applications into the CI / CD pipeline, troubleshoot installations and build automated deployments of products into a high-security architecture.
  • Possess a knowledge of CI / CD orchestration tools such as Jenkins, Tekton, GitLab, or Bamboo.
  • Provide operational support for container security tools (Palo Alto Prisma, Aqua, Wiz or equivalent)
  • Perform Baseline Image validation of new container template images.
  • Evaluate scans results for container runtime environments to reduce security risk
  • Troubleshoot any connectivity or operational issues for clusters being evaluated in the Prisma tool.
  • Apply software development skills (e.g., Java, C#.NET, JavaScript) to recommend and apply secure coding practices
  • Validate and address vulnerability / threat findings from static and dynamic analysis tools
  • Characterizes threats and provides recommendations for remediation; manages remediation efforts to completion
  • Develops and presents finding and remediation reports to audiences including team members from all department areas and levels of the company
  • Perform security reviews of software designs and assist developers to ensure quality and robustness of our internal products
  • Conduct security assessments against web applications and APIs across a variety of technology stacks
  • Ensure adequate security requirements and privacy by design are built into all architecture / infrastructure / projects
  • Integrating threat modeling practices into the application testing lifecycle
  • Impart application security and ethical hacking subject matter expertise into team processes
  • Drive improvements in the security testing practice to include execution methodology and metrics
  • Drive awareness and knowledge of security in the developer community
  • Continually improve proficiency in application and API exploitation, tools, techniques, and countermeasures

Benefits and Perks to Help You Keep Climbing

Our culture is rooted in a shared dedication to living our values Care, Integrity, Resilience, Servant Leadership, and Teamwork every day, in everything we do.

At Delta, our people are our success. At the heart of what we offer is our focus on Sharing Success with Delta employees.

Exploring a career at Delta gives you a chance to see the world while earning great compensation and benefits to help you keep climbing along the way :

  • Competitive salary, industry-leading profit sharing program, and performance incentives
  • 401(k) with generous company contributions up to 9%
  • Paid time off including vacation, holidays, paid personal time, maternity and parental leave
  • Comprehensive health benefits including medical, dental, vision, short / long term disability and life benefits
  • Family care assistance through fertility support, surrogacy and adoption assistance, lactation support, subsidized back-up care, and programs that help with loved ones in all stages
  • Holistic Wellbeing programs to support physical, emotional, social, and financial health, including access to an employee assistance program offering support for you and anyone in your household, free financial coaching, and extensive resources supporting mental health
  • Domestic and International space-available flight privileges for employees and eligible family members
  • Career development programs to achieve your long-term career goals
  • World-wide partnerships to engage in community service and innovative goals created to focus on sustainability and reducing our carbon footprint
  • Business Resource Groups created to connect employees with common interests to promote inclusion, provide perspective and help implement strategies
  • Recognition rewards and awards through the platform Unstoppable Together
  • Access to over 500 discounts, specialty savings and voluntary benefits through Deltaperks such as car and hotel rentals and auto, home, and pet insurance, legal services, and childcare

What you need to succeed (minimum qualifications)

  • Minimum 5+ years of professional experience in application security, penetration testing, security assessment, secure software development or related field
  • Hands-on experience working with Cloud and / or DevSecOps related technologies
  • Excellent understanding of DevSecOps techniques and processes, guide integration of various tools in DevSecOps processes (GitLab / GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization).
  • Should be well versed with the AWS well architected framework or TOGAF and able to apply those principles while designing a solution
  • Experience building and supporting applications in the Cloud (AWS, Azure, GCP)
  • Experience engineering software within an Amazon Web Services (AWS) cloud infrastructure
  • Troubleshoot and resolve problems with existing cloud controls
  • Extensive knowledge of the OWASP Top 10
  • Experience with vulnerability risk and impact assessment
  • Experience integrating security capabilities in cloud and application lifecycle management platforms especially in a DevOps model
  • Extensive knowledge with static analysis tools and flaw triage such as HP Fortify, IBM Rational, Veracode or Coverity, FindBugs, FindSecurityBugs, Brakeman and Open Source scanning tools such as Sonatype CLM
  • Excellent written and verbal communication skills
  • Strong sense of urgency and ownership
  • Consistently prioritizes safety and security of self, others, and personal data.
  • Embraces diverse people, thinking, and styles.
  • Possesses a high school diploma, GED, or high school equivalency.
  • Is at least 18 years of age and has authorization to work in the United States.

What will give you a competitive edge (preferred qualifications)

  • B.S. degree in Computer Science, Computer Engineering, Information Assurance or related field
  • Extensive experience in application security and ethical hacking
  • Extensive experience exploiting web, mobile and application security vulnerabilities
  • Extensive experience in software development
  • Extensive experience integrating secure coding techniques with product teams
  • Professional certifications such AWS practitioner, cloud security certification for AWS, and CISSP
Full-time
APPLY

Security Compliance Analyst - Vendor Security

Flexport Atlanta, GA
APPLY

The Opportunity

We are looking for a Vendor Security Analyst to Conduct detailed vendor risk assessments, working closely with key external and internal partners, to identify and evaluate risks before establishing or continuing operations with third-party vendors.

You Will

  • Ensure vendor due diligence is conducted for all New and renewing Vendors
  • Annual reassessment for all Critical Risk Vendors
  • Participate in regulatory, risk and audits issues
  • Engage with business process owners, members of Procurement, Finance, Legal and Security Operations teams to review contracts / service agreements adding necessary Vendor Security Addendum and Data Processing requirements
  • Coordinate the communication between vendors and Flexport business owners
  • Work with Key Procurement Stakeholders, IT and Legal to define and review contractual clauses pertaining to security
  • Participate in other compliance, Privacy and security projects on an ad hoc basis.
  • Enforce the IT common control framework to ensure alignment with IT policies, standards, and regulatory requirements

You Should Have

  • 3+ years experience in related vendor oversight field
  • Knowledge of FedRamp, ISO 2700, NIST 800-53, SOX and SOC
  • BS / BA / MBA / Graduate, preferably in accounting / finance, information systems, business administration, economics, or technology perferred
  • Understanding of Operational Risk and Controls frameworks
  • Understanding of procurement & Risk Processes
  • Track record for demonstrating initiative and motivation, working independently and being held accountable for high levels of performance with minimal supervision
  • Strong organizational skills with the ability to prioritize multiple task
Full-time
APPLY

SR SECURITY ADMINISTRATOR

Mohawk Industries, Inc. Atlanta, GA
APPLY

SENIOR SECURITY ADMINISTRATOR

Find your more with Mohawk!

At Mohawk Industries, we’re committed to more more customer solutions, more process improvements, more sustainable manufacturing and more opportunities for our people.

As a Fortune 500, global flooring leader with some of the best-known brands in the industry, Mohawk is a great place to start or develop your career with an emphasis on more of what’s important to you.

Come find your more with Mohawk!

What we need :

Mohawk is looking for a Senior Security Administrator who can do more for all Mohawk global brands across residential, distributor, and builder multifamily divisions.

The Senior Security Administrator will be managing our incident response, system monitoring, and analysis.

What you’ll do :

Support business units and users with direct interaction with Sr Directors and with BU CIO(s)

Direct Interaction with all IS Vendors along with some management of vendors

Senior level opportunity for someone very experienced with Security Operations Centers (SOCs), Incident Management, Detection Engineering and Threat Hunting

Participates with development, maintenance, and testing of security alerts covering a wide range of operating systems, services, and applications

Analyze, triage and lead security incidents

Provide a technical resource and escalation point for Tier 1 and Tier 2 analysts

Performs activities including planning, providing technical leadership, and tracking projects and key task dates

Uses security monitoring tools to investigate, respond to, and recommend appropriate corrective actions for data security incidents

What you have :

Bachelor’s degree in Cybersecurity / Information security or related discipline.

Master’s preferred or an equivalent combination of education and training that provides the required knowledge, skills and abilities to perform the essential functions of the job

Certification and Training : GSEC, GISF, GISP, GSNA, CISSP, CISM

At least 8+ years of information security experience

Expertise in incident response and system monitoring and analysis.

Experience with system monitoring and analysis.

Knowledge of multiple computing platforms, including Windows, Linux, Unix, networks, and endpoints.

Experience with vulnerability and penetration testing engagements.

Experience with change and project management.

What you’re good at :

Good oral, written, presentation, and interpersonal communications skills; ability to effectively interact with internal and external customer and team members

Ability to perform in a high-pressure environment and / or crisis situation and render good decisions to resolve problems, maintain safety, and ensure adherence to the Corporate Code of Conduct.

Good Understanding of overall business functions and ability to support an incident response function

Able to mentor coworkers to develop & apply creative solutions to solve problems

Able to assist business units to establish and prioritize remediation efforts and drive toward accomplishing those priorities

Able to be a technical skills mentor to team members to help them become proficient in technology and issue resolution, thinks outside the box

Takes ownership of larger or multiple projects and provides innovative solutions

Able to mentor and motivate team

Contributes to building and managing relevant portions of project plans, managing time and attention based on what is most important to achieve key objectives

Team Leader and capable of bringing the team together to achieve the common goal

Full-time
APPLY

Security Guard

Jackson Protection Agency Atlanta, GA
APPLY

Jackson Protection Agency is looking for a well qualified security agent who is highly trained in all areas of executive protection.

We are looking to build a roster of unarmed & armed guards who can be "on call" for potential assignments. Assignments could range from days to a few weeks.

Pay can range from $25-40 a hour, depending on the contract being filled. Qualifications : Security license (required) CCW permit (required for armed work) Prior experience for at least 3 years Prior experience as a security / military employee is preferred Primary medical training preferred Personal requirements : Good communications skills Service oriented attitude Physically fit for the job requirements Organized, focused and able to follow in detail given instructions Powered by JazzHR

Temporary
APPLY

Security Engineer

Beazer Homes Atlanta, GA
APPLY

Overview The Security Engineer ensures the organization's computer systems, networks, and data are protected against potential cyber-attacks and other security threats.

This position is responsible for designing, implementing, and maintaining security measures to protect computer systems, networks, and data from cyber threats.

Company Overview : Beazer Homes is committed to employee wellbeing and life-work balance, offering development opportunities, a flexible time-off program, and an industry leading parental leave policy.

Primary Duties & Responsibilities Conducts regular security assessments and audits to identify vulnerabilities and threats.

Develops and implements security policies, procedures, and standards. Designs, architects, manages and monitors security tools such as firewalls, intrusion detection systems, and antivirus software.

Develops and implements security measures and controls to protect computer systems, networks, and data from unauthorized access, misuse, or modification Works with cross-functional teams to identify security requirements and implement security measures in new systems and applications.

Investigates and responds to security incidents and breaches. Stays current with the latest security trends, threats, and vulnerabilities.

Participates in security incidents and response management. Configures, manages, and monitors Firewalls. Designs, implements, and deploys security automation and services capable of identifying security threats and vulnerabilities Manages cloud-based security.

Manages vulnerability assessment tools. Develops security threat models and provides security assessments Education & Experience Bachelor's degree in Computer Science, Information Security or a related field.

At least 6 years of experience as a Security Engineer or in a similar role. Strong understanding of security principles, protocols, and technologies.

Strong experience with cloud security and network security. Experience with security tools such as firewalls, intrusion detection systems, and antivirus software.

Experience with penetration testing and vulnerability assessment tools. Skills & Abilities Experienced with working in a complex environment.

Excellent communication skills, both verbal and written. Must have an eye for detail to ensure that compliance requirements are met consistently and accurately.

Ability to work effectively in a team environment and collaborate with other IT teams. Must have the ability to analyze complex information, identify patterns and trends, and develop solutions to address compliance issues.

Excellent problem-solving skills Must have a clear understanding on how compensating controls are used to protect the organization.

Experienced with MSWord, Excel, and PowerPoint Physical Requirements Typical office environment. Additional Responsibilities The above statements are intended to describe the general nature and level of work being performed.

They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required. All employees may be required to perform duties outside of their normal responsibilities from time to time, as needed.

Additionally, an employee's job duties may change at any time, in the company's sole discretion. Personal Information Collection Notice for Job Applicants In order to process your application, we will ask you to create an account and provide us with certain personal information, including your identification data (e.

g. name, date of birth, driver’s license number, contact details), education information, and professional and employment history.

If you have any questions about our privacy policy or would like to learn more, please visit Beazer.com / privacy, which includes a link to an additional notice for California residents and which link can also be visited directly at Beazer.

com / Californiaprivacy. Equal Opportunity Employer

Full-time
APPLY