Senior Application Security Analyst
Position : IT Security Analyst - Application Security
Duration : 4-5 months (Potential extension)
Type : Hybrid (1-2 days a month)
Must Have Skills / Requirements :
1) 10+ years of Experience as an IT Security Analyst
2) A strong understanding of multi-tier Web Applications, web API, and related vulnerabilities and potentials threats. Staying abreast of information provided by recognized organizations such as OWASP (Open Web Application Security Project) and CVE (Common Vulnerabilities and Exposures).
3) Must have a comprehensive understanding of the HTTP protocol, Secure Software Development Lifecycle (SDLC) and Web Programing for multi-tier web applications and web services.
For example, experience with multiple of JavaScript, SQL, HTML, XML, ASP.net , VB.net , Java, PHP, Python, PowerShell, or Ruby is essential.
4) Must have a comprehensive understanding of the OWASP Application Security Verification Standard (ASVS), and have proven working experience applying the ASVS.
5) Experience performing source code and / or application security assessments, including risk assessments, and penetration testing.
The ability to demonstrate exploitation of vulnerabilities is essential, as would experience with vulnerability testing and scanning tools such as Checkmarx, BurpSuite, Acunetix, NetSparker, WebInspect, AppScan, SQLMap, ZAP, and Fortify.
Nice to have Skills :
1) Prior Financial Institutional Experience
2) An understanding of gateway technologies and network devices such as Load Balancers, Proxies, IPS, WAF, API Gateway.
3) The ability to generate reports and tailor your communication strategy for various levels of technical staff, executive management, and business clients.