Application Security Engineer
Job Description
ARA is an employee-owned, international, research and engineering company recognized for providing technically superior solutions to complex and challenging problems.
ARA offers an excellent benefits package that includes:
- 401-K Retirement with employer matching contribution
- Employee Stock Ownership Plan
- Various insurance options including Flexible Spending Plan, Health Savings Account (HSA)
- Paid leave and holidays
Duties:
- Develop security training and guidance to internal and external development teams.
- Provide subject matter expertise on architecture, authentication, encryption, and systems security for support software applications developed in-house.
- Create and maintain artifacts in a protected repository established as the sole source of truth.
- Assess security tools and integrate tools as needed, particularly open-source tooling.
- Assist with assessment activities to improve the technology in use.
Technical:
- Familiar with common security libraries, RMF security controls, common security flows, and vulnerability assessments for C++ applications
- Ability to discover and patch database, GUI, authentication and authorization flaws, and other security vulnerabilities contained in the software applications.
- Experience with Atlassian tools and CI/CD pipeline integration of security assessment and remediation measures
- Experience with CheckMarx, SonarQube, and other application security analysis tools
- Heavy experience with SAST, DAST, OSA, and secure software supply chain is a must
Code Quality:
- Proactively identify and reduce security risks in the supported software applications developed in-house.
- Find and remove outdated and vulnerable code and code libraries.
Communication:
- Consult with other Developers and Product Managers to analyze and propose application security standards, methods, and architectures.
- Handle communications with independent vulnerability researchers and design appropriate mitigation strategies for reported vulnerabilities in collaboration with security teams.
- Educate other developers on secure coding practices.
- Ability to professionally handle communications with outside researchers, users, customers, and organizations.
- Ability to communicate clearly on technical issues.
General Requirements:
- You have a passion for security and open source.
- You have a passion for security software supply chain.
- You have an inquisitive nature for discovery of root cause.
- You have a proactive attitude towards challenges and technology.
- You have a drive and passion for technology and capabilities.
- You employ a flexible and constructive approach when solving problems.
- You're a recognized security expert in multiple specialty areas with cross-functional team experience.
- You provide actionable and contrastive feedback to cross-functional teams.
- You assist in making security architecture decisions for software applications.
- You implement security technical and process improvements.
- You have superior written and verbal communication skills.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
Date Posted
07/03/2023
Views
13
Similar Jobs
Software Architecture Engineering and Cloud Computing Engineer - The Aerospace Corporation
Views in the last 30 days - 0
The Aerospace Corporation is seeking a Senior Project Engineer with expertise in software architecture engineering and cloud computing The role involv...
View DetailsLead Technical Support Engineer - HERE Technologies
Views in the last 30 days - 0
This role Senior Technical Support Engineer at HERE Technologies involves supporting a diverse portfolio of products and services acting as a technica...
View DetailsPrincipal / Lead Software Engineer- RUST (Algorithmic and Mathematics) - m/w/d - HERE Technologies
Views in the last 30 days - 0
HERE Technologies is seeking a Principal Software Engineer to lead the development of extended services for their VRP solver Tour Planning The role in...
View DetailsSenior Software Engineer (Scala/Java) - HERE Technologies
Views in the last 30 days - 0
HERE Technologies is seeking an experienced backend engineer with strong Java or Scala skills to join the Map Processing Pipelines team The role invol...
View DetailsSoftware Engineering Manager - Cargill
Views in the last 30 days - 0
The Software Engineering Manager job involves setting goals for a team responsible for software project development and delivery ensuring quality stan...
View DetailsSales Development Representative - UK (Remote) - Dscout
Views in the last 30 days - 0
Dscout is a company that specializes in experience research solutions helping innovative companies like Salesforce Sonos Groupon and Best Buy to build...
View Details