Test Engineering Services (TES) at Synapxe is embarking on a journey to constantly transform its services by exploiting state-of-the-art technologies and tools to enhance TES’ ability to offer specialized testing services to its stakeholders. TES is passionate about making an impact with lasting change and we aim to provide our stakeholders with automated and optimized testing solutions to not only help them speed-up testing but produce accurate, reliable, and repeatable results.
TES is planning to implement and roll out a Dynamic/Interactive Application Security Testing (D/IAST) solution. This will act as a control measure proposed for implementation in response to Secured-by-Design Framework v1.0 as recommended by CSA’s Cybersecurity Code of Practice (CCoP).
As an Application Security Testing Specialist, you will be responsible for:
• Leading the request for proposal from a technical perspective to procure a D/IAST solution.
• Defining and documenting technical product requirements and specifications for a D/IAST solutions, evaluating the solution proposals to perform fit/gap analysis, determining the detailed evaluation criteria and producing recommendations to prevent, detect and analyse security threats and weaknesses in the running application.
• Leading the implementation and roll out of the identified D/IAST solution; work with the senior manager and product vendor to plan, set-up, on-board, test and deploy the D/IAST solution.
• Automated application security using the D/IAST tool to perform application security testing, gather and understand reports, assess potential security vulnerabilities, work closely with the application developers/vendors to resolve any vulnerabilities, and present the risks to the business for acceptance or mitigation.
• Removing false positives from the reports and working closely with the development/test teams to automate test and embed security testing in the CI/CD pipe line.
• Developing comprehensive and accurate reports and presentations for both technical and management audiences and effectively communicating the findings and remediation strategies.
• Recognising and safely utilising attacker tools, tactics, and procedures
• Maintaining and performing routine maintenance on D/IAST monitoring servers, reports repository, agents, etc.
• 8 years of experience with SAST/DAST/IAST/RASP methodologies and technologies to catch security flaws in the software?
• Hands-on experience with a wide-range of security tools such as MF Fortify, WebInspect, Contrast Security Assess and Protect, IBM AppScan, Checkmarx, MS Threat Modeling, BurpSuite, etc.
• Eager to collectively learn, share and solve problems within the area of application security testing in the area of healthcare domain?
• Consistent attention to details and work under pressure to achieve agreed targets/goals
• Work with intra-teams, and building rapport with the stakeholders and be able to manage difficult people
• Think out of the box and carries the courage to try and implement unconventional approach to deliver solutions