Responsibilities
- Review code for security vulnerabilities and assist in remediation.
- Maintain accurate library dependency trees and correlate with CVE information.
- Support penetration testing efforts in the company, including coordinating customer-initiated penetration tests and remediation efforts.
- Provide primary support for private bug bounty or public bug bounty efforts and facilitate remediation with appropriate development teams.
- Investigate claims of application security incidents.
- Provide vulnerability remediation efforts and lead the vulnerability management program for the security team.
- Identify end of support (EoS) and vulnerable libraries and code components which need to be prioritized for remediation and lead efforts of documenting and scoping necessary work.
- Develop company-wide best practices for product and platform security.
- Research security enhancements and make recommendations to management.
- Stay up-to-date on application security trends and development standards.
Qualifications
- 4+ years combined in information technology/security with emphasis on application security.
- A BS/MS degree in a technical field such as information security or computer science can be considered as supplementary experience.
- Experience with scripting and development languages (e.g., JavaScript, Python, C++)
- Automation skills are required.
- Strong history in advising and executing red-teaming exercises and alerting the SOC for appropriate incident response.
- High degree of familiarity with web application security best practices and implementing secure enterprise web applications.
- Significant experience with SIEM and logging technologies.
- Knowledgeable with Threat Hunting practices.
- Experience with SDLC processes and creating code scanning automations and run books / play books.
- Experience with SAST scanning tools for code scanning and remediation processes.
- Experience with DAST scanning tools for application testing
- Experience with hardening web services, load balancers and web application endpoints.
- Experience with Configuring WAF solutions and ensuring rules are aligned with the OWASP Top 10 recommendations.
- Experience with AWS, GCP and Azure cloud infrastructure security.
- Working knowledge of security requirements for SOC 2 Type I & II, HIPAA, GDPR, CCPA and CJIS.
- Strong project management experience.
- A strong curiosity, initiative, persistence, and willingness to experiment to provide solutions to diverse technical challenges.
- Strong team player and work ethic are essential.
Preferred Qualifications
- Significant experience with software engineering, incident response and security operations best practice.
- Significant experience with orchestration and observability tools.
- CCIE certification or equivalent experience.
- CISSP certification or equivalent experience.
- OSCP/GPEN/GXPN certification or equivalent experience.
- GSEC certification or equivalent experience.
- CISM certification or equivalent experience.
Other Jobs from Filevine
Cloud Security Engineer
Fullstack Developer
Senior Site Reliability Engineer
Similar Jobs
Systems Engineer (Enterprise) - Korea
Site Reliability Engineer (pinot)
Delivery Manager - Network Engineering (Gurugram)
Software Engineer II (DotNet Fullsatck Developer)
Java Developer - Entry
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 401 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say