Web Application Security Engineer Job at Direct Staffing Inc, San Francisco, CA

YzZ1a3EvYjdVRmd6Um1XUy9oODBxaVRkRlE9PQ==
  • Direct Staffing Inc
  • San Francisco, CA

Job Description

Visa candidates are welcome to apply Shopping has changed more in the past five years than in the past five decades, and going forward, retailing will require investing more in people and technology. With the rapid changes in retail, it is critical that technology be a strategic enabler for our company to accelerate delivery, be adaptive to market changes, and effective in rapidly delivering solutions to meet the needs of our customers. The Web Application Security Engineer works as a member of the Information Security team. Primary Responsibilities:

  • Performs static/dynamic code testing, manual code inspection, threat modeling, design reviews and penetration testing of internal web applications and external partner applications to identify vulnerabilities and security defects.
  • Supports the implementation and enforcement of secure design principles according to policies, standards, and patterns of Information Security.
  • Serves as a Subject Matter Expert (SME) in web application security for enterprise projects during development phases to provide Information Security consulting and recommendations, ensuring the implementation of approved security requirements.
  • Develops and implement manual and automated web application security testing of e-commerce web applications to enforce security standards.
  • Works with security product vendors and service providers to evaluate security offerings, including product evaluations, proof of concept and pilot installations
Qualifications:
  • Bachelor's degree in Computer Science, Software Engineering or related field or equivalent combination of education and experience
  • 5-7 years of experience in performing penetration testing, secure code review, static, dynamic and manual source code review.
  • Experience in identifying and remediating common web application vulnerabilities such as OWASP Top 10.
  • Experience in use of various commercial and open source penetration testing tools and methodologies and performing penetration testing of web applications and operating systems.
  • Familiarity with APT attack and kill chains.
  • Experience with various code repositories including GitHub and Apache Subversion (SVN)
  • Experience with continuous integration servers such as Jenkins and ElectricCommander
5+ to 7 years experience

SCREENING QUESTIONS

Do you have experience performing penetration testing? Do you have experience identifying vulnerabilities within a web application? Are you ok working in SF or Pleasanton? Do you have examples consulting enterprise level development projects? Are you ok taking a 75 question assessment? Additional Information All your information will be kept confidential according to EEO guidelines. #J-18808-Ljbffr Direct Staffing Inc

Job Tags

Similar Jobs

Nurse First

Travel Nurse RN - Neuro ICU Job at Nurse First

 ...Job Description Nurse First is seeking a travel nurse RN Neuro ICU for a travel nursing job in Louisville, Kentucky. Job Description & Requirements ~ Specialty: Neuro ICU ~ Discipline: RN ~ Start Date: 02/10/2025~ Duration: 13 weeks ~36 hours per week... 

Corporate Office Properties Trust

Building Technician IV Job at Corporate Office Properties Trust

 ...POSITION SUMMARY Specialist responsible for leading day-to-day building/portfolio technicians with troubleshooting all building system problems,...  ...providing work direction to others. Computer Skills Basic PC skills and ability to learn company specific software.... 

BMWC Constructors

Project Safety Manager Job at BMWC Constructors

Project Safety Manager Evansville, IN Driven by Vision | Industrial-Strength Construction| Powered by Passion OVERVIEW Are you looking to work for a successful, stable, and growing company that rewards employees with annual bonuses and exceptional benefits...

Mawer Capital

Appointment Setter Job at Mawer Capital

 ...who will reach out to new and existing leads in order to book appointments for the sales team. They will do this through various forms of...  ...~1-2 years experience with lead generation and appointment setting realm ~ Fluent English Preferred Education and Experience... 

General Dynamics Information Technology

Integration Test Engineer | Secret clearance Job at General Dynamics Information Technology

 ...Development Job Qualifications: Skills: Integration Testing, Software Development, Test Engineering Certifications: None...  ...components, and applications as required. Redline Intrepid Tiger II user manuals based on observed IT II EW system operation in the lab...