INTERNSHIP - Deployment of Interactive Application Security Testing (IAST) tool for web applications
PRAHA
Thales
From Aerospace, Space, Defence to Security & Transportation, Thales helps its customers to create a safer world by giving them the tools they need to perform critical tasksThe goal is to deploy a well-known IAST tool (such as Black Duck Seeker or Contrast's IAST) in various types of web applications (Web Service and Web UI applications) dealing with biometrics (Face or Fingerprint recognition systems). The IAST tool needs to be integrated into the automated testing chain of the CI/CD (such as GitLab, for instance) of the respective product R&D teams. Another key responsibility of the role involves promoting and communicating the tools, security guidelines and hardening recommendations provided by these tools, as well as by renowned security organizations such as OWASP, ANSSI, and NIST.
The intern will have the opportunity to understand and compare the pros and cons of the IAST tool with other types of scanning tools such as Dynamic Application Security Testing (DAST) using, for instance, OpenText Fortify WebInspect, Burp Suite, or OWASP Zap, and Static Application Security Testing (SAST) tools using OpenText Fortify Static Code Analysis or Black Duck Coverity Static Analysis.
The student will contribute to write the baseline deployment guideline for the tool in the organization and support adoption of the tool by the product R&D teams.
The intern will join our technical governance team, which comprises experts in fields such as cybersecurity, automation testing, biometric systems, cloud computing, and software & system architecture. This team has several years of experience supervising students, generally several at the same time.
A background in software engineering or IT engineering with a major in cybersecurity is preferred.
Most of the communication will be in English
Technology skills:
• Programing Language: Java, JavaScript, Python
• Web Technology: HTML, CSS, WebServer (Node.js, Spring-Boot, Jetty)
• OS: Linux / Windows
• Network: HTTP(S), TCP/IP, SSH
• CI/CD: GitLab
• Security Tools: vulnerability scanners
• Deployment Environment: docker, Kubernetes
Tags: Application security Automation Banking Black Duck Burp Suite CI/CD Cloud Code analysis DAST Docker GitLab Governance IAST Internet of Things IoT Java JavaScript Kubernetes Linux NIST Node.js OWASP Python R&D SAST SSH TCP/IP Windows
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.