What are the responsibilities and job description for the Web Application Security Analyst position at Henry Ford Health - Careers?
GENERAL SUMMARY:
The Web Application Security Analyst is a key member of the Application Security Service Team. Although the position is technical by nature, champions policies, processes, and procedures to enable secure controls for implemented applications that meet best practice and regulatory standards. The Web Application Security Analyst reports to the Director ¿ Application Security Services. This position will work in a collaborative effort within the Information Privacy and Security Office and application developers to ensure software development life cycle policies, standards and controls are followed.
EDUCATION/EXPERIENCE REQUIRED:
- Bachelor's degree in business, Information Technology, Cybersecurity, or related field required.
- Minimum five (5) years experience Web Application development experience in designing and implementing software systems, building mission-critical and highly reliable software required.
- Exceptional understanding in mitigating OWASP Top 10 attacks on web applications/services, cryptography, key management, PKI, TLS/SSL, DDoS mitigation, authentication, authorization, and/or general web application security.
- Strong understanding of secure/rugged engineering concepts such as secure coding practices and secure code reviews used to identify, mitigate, and prevent threat vectors. Understanding of vulnerability management lifecycle and process.
- Strong understanding of security architecture and tools which can be leveraged for Application Security mitigation.
- Experience with Security Assessment Toolsets and manually test and validate reported vulnerabilities.
- Strong Knowledge of relational databases, structured query language, and client/server relationships in multi-tier environments.
- Ability to communicate clearly and concisely to drive change through verbal and written communication.
- Cyber security risk management experience, e.g., conducting assessments, identifying risks, and recommending solutions.
Additional Information