Location: US-based, remote. Must accomodate Pacific time zone work hours.
TekStream, a Digital Resilience Consulting company, is seeking a skilled and collaborative Application Security Engineer to bridge the gap between our Information Security (InfoSec) team and development personnel. In this role, you will act as a security ambassador, helping developers understand vulnerabilities, automating security into our CI/CD pipelines, and driving remediation efforts to ensure our software is secure by design. The ideal candidate has consulting experience and is open to working west coast hours for our client.
Key ResponsibilitiesTechnical Liaison & Developer Support- Guide and assist development personnel in understanding security vulnerabilities and implementing remediation options.
- Collaborate with developers to ensure adherence to security best practices during development cycles.
- Utilize SAST and DAST tools for thorough security testing and validation of remediation efforts.
- Recommend efficient solutions for fixes to streamline the overall remediation process.
DevSecOps Integration- Build out capabilities of the DevSecOps Team, actively contributing to integrating security practices into CI/CD pipelines.
- Automate manual processes to improve the efficiency and speed of development workflows.
Vulnerability & Penetration Test Remediation- Analyze findings from penetration tests and propose concrete remediation tasks.
- Support assigned teams with the technical aspects of the remediation process.
- Monitor and track progress on remediation tasks to ensure timely completion.
Security Reviews & Assessments- Review False Positive (FP) submissions, providing clear guidance on resolution and ensuring proper justification and documentation.
- Evaluate Risk Acceptance Requests (RARs), providing mitigation recommendations and identifying cases requiring further review.
- Participate in architecture reviews of security products and architectures to identify potential improvements.
- Support security assessments, including scoping, report reviews, and remediation planning.
Process Improvement- Research and recommend optimization opportunities related to the team's organization, processes, procedures, and tools to improve efficiency and maturity.
Role Requirements & QualificationsTechnical & Development Experience- Cybersecurity Knowledge: Solid understanding of cybersecurity principles, including common threats and vulnerabilities.
- Development Experience: Proficiency in software development, preferably within a Microsoft .NET/C# code base.
- Cloud & On-Premises Familiarity: Familiarity with testing tools and techniques for both on-premises and cloud environments is highly valued.
- Tooling Proficiency: Experience with or knowledge of the following tools:
- SAST/DAST/Secrets: GitGuardian, Veracode, SonarQube, Qualys DAST, Wiz
- Languages: .NET, C#
Core Competencies- Analytical Skills: Ability to analyze risks associated with vulnerabilities and recommend appropriate resolutions or risk reduction strategies.
- Communication Skills: Excellent oral and written communication skills, with the ability to effectively translate technical details to both technical and non-technical stakeholders in a consulting capacity.
- Coordination & Collaboration: Proven ability to collaborate with various resources across IT and vendor populations to achieve security objectives while acting as a supportive team member.
- Documentation & Compliance: Proficient in collecting and synthesizing information into an accurate format suitable for audits. High attention to detail is essential.