Job Responsibilities:
- Triage potential vulnerabilities identified by the application security program, contextualizing them with application and business knowledge.
- Review and analyze source code for business logic flaws and ensure security compliance prior to production release.
- Identify false positives, track and remediate vulnerabilities, and manage exception processes as required. Articulate cybersecurity standards applicable to technology and coding workflows to relevant stakeholders.
- Collaborate with teams to promote secure development practices and integrate security into the SDLC.
- Partner with DevSecOps engineers to enhance security measures using existing technologies and workflows.
- Review the performance of various controls, including but not limited to:
- Software Composition Analysis (SCA)
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Runtime Application Self-Protection (RASP)
- Secrets Scanning and Container Security
- Secure Code Reviews and CI/CD Pipeline Security
- Conduct cyber governance activities, including risk assessments, system security reviews, and creating security plans for industrial control systems.
- Identify gaps in implemented controls, track remediation efforts, and provide updates to the risk register.
- Perform penetration testing and red teaming exercises to identify vulnerabilities in applications and environments.
- Provide actionable recommendations for remediation and track remediation progress.
- Draft, review, distribute, and maintain cybersecurity policies, standards, and standard operating procedures (SOPs).
- Ensure consistent and regular attendance, as it is a critical aspect of the role.
Job Requirements:
- Expertise in secure coding practices and their application across the software development lifecycle.
- Hands-on experience with security testing tools (e.g., SAST, DAST, SCA, container scanning tools).
- In-depth knowledge of application security frameworks and standards (e.g., OWASP, NIST, ISO 27001).
- Familiarity with CI/CD pipeline security and deployment environment security measures.
- Strong analytical and problem-solving skills, with the ability to identify and remediate security vulnerabilities effectively.
- Experience conducting risk assessments, developing security policies, and providing governance oversight.
- Strong communication skills to convey cybersecurity concepts to both technical and non-technical stakeholders.
To apply, simply click the "Apply" button or send your updated profile to [email protected]
EA Licence No.:18S9405 / EA Reg. No.:R1330864
Percept Solutions is expanding and actively seeking talented individuals. We encourage applicants to follow Percept Solutions on LinkedIn at https://www.linkedin.com/company/percept-solutions/to stay informed about new opportunities and events.