Application Security and Secure-SDLC Expert
Herzliya, Israel
Applications have closed
CYE
CYE's continuous cyber exposure management solution enables you to quantify and mitigate your cyber exposure.
CYE is looking for a talented Application Security and Secure-SDLC Expert to be a part of our team. As an Application Security Expert, you will take an active role in security development lifecycle activities and penetration testing that will help evaluate our customers’ security level and improve it. A typical job could be breaking into a critical system of a Fortune 500 organization, analyzing the Secure-SDLC security gaps in a large department in a huge enterprise, and reverse engineering an application and encryption method in order to gain access to sensitive data.
Responsibilities
- Manage, evaluate, and improve the application security development lifecycle of our clients.
- Identify, communicate, and drive the resolution of vulnerabilities.
- Research and advocate for new application security solutions and technologies.
- Continue to drive security evaluation earlier in the cycles through iterative security testing.
- Operate as an incident responder for triage pertaining to web-based vulnerabilities.
- Ensure customers’ security by hands-on penetration testing, hypothesizing threats, helping development teams remediate risks upfront, and executing secure implementation efforts.
- Improve secure coding practices, application security requirements, automation, training, and metrics.
Qualifications
- 3+ years of experience in Application Security Secure-SDLC practices, standards, methodologies, and software team escorting; including standards such as Microsoft SDL, OWASP SAMM, and OWASP ASVS.
- Experienced with threat analysis processes.
- Deep understanding of OWASP Top 10 and CWE 25; with a proven track record and experience in implementing and integrating remediation strategies.
- Familiarity with a wide range of high-level programming languages (Java, JS, Python, etc.) and related secure Software Development Life Cycle (SDLC) activities.
- Significant advantage: hands-on experience in application penetration testing.
- Significant Advantage: Managerial experience.
- Advantage: Proven experience in high-level code auditing.
- Advantage: experience in CI\CD and CI\CD security.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
7
0
0
Category:
AppSec Jobs
Tags: Application security Audits Automation Encryption Java OWASP Pentesting Python Reverse engineering SaaS SAMM SDLC SSDLC Vulnerabilities
Region:
Middle East
Country:
Israel
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Security Operations Engineer jobsSystems Administrator jobsIT Security Analyst jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsSenior Security Analyst jobsSenior Information Security Analyst jobsCyber Security Specialist jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsSenior Product Security Engineer jobsInformation System Security Officer (ISSO) jobsChief Information Security Officer jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsIT Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior IT Auditor jobsSecurity Operations Analyst jobsCybersecurity Specialist jobsSenior Software Engineer jobsNetwork Engineer jobs
Java jobsBash jobsTS/SCI jobsEncryption jobsEDR jobsSDLC jobsSplunk jobsMalware jobsThreat detection jobsRMF jobsFinance jobsTerraform jobsTop Secret jobsForensics jobsIDS jobsCompTIA jobsSQL jobsITIL jobsIPS jobsActive Directory jobsSOC 2 jobsDocker jobsOWASP jobsClearance Required jobsGIAC jobs
Intrusion detection jobsCRISC jobsAnsible jobsVPN jobsTCP/IP jobsOSCP jobsHIPAA jobsDoDD 8570 jobsMITRE ATT&CK jobsData Analytics jobsZero Trust jobsJavaScript jobsSOAR jobsIT infrastructure jobsBanking jobsCCSP jobsSOX jobsIndustrial jobsUNIX jobsDNS jobsJira jobsNIST 800-53 jobsGCIH jobsKPIs jobsCISO jobs