Analyst, Application Security
Job Purpose
An ICE IS AppSec Analyst, Engineer, or Senior Engineer is part of a team responsible for ensuring that ICE produces and maintains secure applications. The team member influences secure design, performs code analysis, identifies vulnerabilities through hands-on penetration testing, assists developers in remediation efforts, and communicates findings to developers, QA teams and management.
Responsibilities
- Application Identification and Review - Operates the Application Development Security Lifecycle from design review through automated and hands-on testing.
- Standards and Policies - Maintains and contributes to Application Development Security Policies and standards by keeping up with industry trends and publications from organizations such as NIST, OWASP, and SANS.
- Secure Design – Works with development teams to establish security requirements early in the SDLC and contributes security subject matter expertise during the development of new projects and releases.
- Tool Management – Focuses on automation while implementing, maintaining and integrating cutting-edge technologies to assess an application’s security with static code analyzers (SAST), dynamic testing (DAST) tools, open source security scanners, Web Application Firewall (WAF) and bug bounty programs.
- Developer Education – Keeps software engineers apprised of secure coding practices and builds strong rapport and respect with the ICE application development community via training sessions, one-on-one education, Intranet blogs and other opportunities.
Desirable Knowledge and Experience
- Software engineering experience in Java, C++, .NET and/or related languages
- Expert at deploying, configuring, and using SAST, DAST, and Open Source Security scanning tools in large environments
- Experience designing solutions to secure sensitive data and secrets by applying cryptography, proper access control, and utilizing hardware security modules (HSM)
- Familiar with blockchain, public/private key management, cryptocurrency, and/or experience securing enterprise implementations
- University degree in Computer Science, Engineering, MIS, CIS, or related discipline
Specific Technologies: Checkmarx, WebInspect, BurpSuite, JFrog Xray, Python, Django, Java, C++, HTML5, .NET, iOS & Android, MySQL, Oracle DB, Cloudfare, Akamai
Analyst, Engineer, and Sr. Engineer Distinction
Seniority is determined by experience and demonstration of exceptional competencies including:
- Documenting and effectively publishing technology guidance and repeatable processes
- Mentoring peers in groups and individually
- Improving processes and introducing superior technology
- Taking initiative to learn business goals, liaise with other departments, and identify ways to increase productivity in other ICE groups and offices
Recommended Jobs
Medical Biller - A/R and Denials
Randstad is looking for a dedicated, career-oriented Medical Biller with experience in Accounts Receivables and Denials Management. This isn't just a processing role; we are looking for a teammate wh…
Retail Merchandiser (Tallapoosa)
Company Description Pilot Company is an industry-leading network of travel centers with more than 30,000 team members and over 750 retail and fueling locations in 44 states and six Canadian provin…
Doorman / Concierge Safety Officer
Position Title: Concierge Safety Doorman/Doorman Location: DelBar Inman Park Reports To: Property Management & Valor Protection Safety Agency Leadership Status: Full-Time, Non-Exempt …
Field Nurse Practitioner - Hall County, GA
About Advantmed Advantmed is a leading provider of risk adjustment, quality improvement and value-based solutions to health plans and providers. We drive market leading performance with integrated…
Cable Technician-Low Voltage with MetroPower/CarolinaPower
MetroPower - Tucker, GA Office is currently seeking 4 Cable Technicians who are interested in getting into the electrical field at an entry-level position and possibly move into an apprenticeship. I…
Tax Manager - Real Estate
Description Are you looking for a firm that is committed to your professional growth and success? Do you have an interest in international tax work in the real estate area? We are currently seeking…
Commercial Construction - Controller
Commercial Construction - Controller To Apply Now – email your resume to [email protected] Who: A growing, multi-division specialty contracting organization is seekin…
RN - Home Infusion, PRN
Overview: Experience the advantages of real career change Join Piedmont to move your career in the right direction. Stay for the diverse teams you’ll love, a shared purpose, and schedule flexib…
Bartender
St Ives Country Club is seeking experienced full-time and part-time Bartenders to work in its clubhouse or other facility. A Bartender prepares and serves both alcoholic and non-alcoholic beverages. …