Agile Defense · 8 hours ago
Software Assurance SME
Maximize your interview chances
Information ServicesInformation Technology
Growth OpportunitiesH1B Sponsor Likely
Insider Connection @Agile Defense
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Perform code reviews to identify flaws in the development of custom applications that handle sensitive IP data, particularly those involving complex data transformations, encryption, or proprietary algorithms.
Drive configuration auditing through review of system and network configurations for misconfigurations or insecure settings that could lead to exploitation.
Execute access controls to validate and assess whether internal access controls effectively enforce the principle of least privilege and prevent unauthorized access to IP data.
Generate reports that highlight security weaknesses uncovered during white-box testing and provide actionable remediation steps.
Ensure that critical issues are resolved before new software releases or system updates go live, especially if they affect data-sharing processes or BII systems.
Research, test, build, and coordinate the conversion and/or continuous integration pipelines and toolchains based on client requirements.
Design and develop new software products or major enhancements to existing software to support security operations.
Address problems of systems integration, compatibility, automation and orchestrations.
Assesses cloud security architectures and provide recommendations to improve overall infrastructure security and methods to automate security testing of applications moving through the CI/CD pipeline.
Consult with project teams and end users to identify application requirements.
Perform feasibility analysis on potential future projects to management.
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
CISSP (or equivalent), GCSA or possess a willingness to pursue certifications after hire
Bachelor’s degree/University degree or equivalent experience
3+ years of relevant experience with most of the requirements below:
Security Architecture reviews
DevSecOps CI/CI pipelines standards and best practices
Application Programming Interface (API) development and testing
Extensive experience working with White-Box testing methodologies and techniques
Static Application Security Testing tools. e.g., SonarQube, Veracode, Fortify
Dynamic Application Security Testing tools. e.g., OpenText Fortify WebInspect, Veracode, Invicti
Experience leveraging the MITRE ATT&CK Framework
Vulnerability Assessment tools. e.g., Nessus, Qualys, Rapid7
Exploitation frameworks, e.g., Metasploit, CANVAS, Core Impact
Deep understanding of OSI model
Security devices, i.e. Firewalls, VPN, AAA systems
OS Security. e.g. Unix/Linux, Windows, OSX
Understanding of common protocols. e.g. HTTP, LDAP, SMTP, DNS
Web application infrastructure. e.g. Application Servers, Web Servers, Databases
Demonstrated ability to collaborate with a variety of analytical groups and service delivery organizations
Advanced analytical and problem-solving skills
Consistently demonstrates clear and concise written and verbal communication
Proficient in interpreting and applying policies, standards and procedures
Demonstrated ability to remain unbiased in a diverse working environment
Preferred
Web development and programming languages. e.g. Python, Perl, Ruby, Java, .Net
Company
Agile Defense
Agile Defense is an information technology company located in Reston.
H1B Sponsorship
Agile Defense has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2021 (1)
Funding
Current Stage
Late StageTotal Funding
unknown2022-11-16Acquired· undefined
Recent News
2024-10-31
PRNewswire
2024-04-29
2024-04-07
Company data provided by crunchbase