What are the responsibilities and job description for the Application Security Engineer (SAST) position at Programmers.io?
Title: SAST (Application Security Engineer)
Location: Pittsburgh PA – onsite only
Duration: Contract/C2C/Fulltime/Permanent
Job description:
- This role is responsible for providing strong security and remediation services to meet project requirements.
- MUST have good experience in Java/ .Net and secure code review.
- Apply security best practices while designing and proposing solutions to enterprise customers.
- Solid competencies in information security processes, framework, and technologies, such as: Application Vulnerability Assessment, Penetration Testing, Ethical Hacking, OWASP Top 10, NIST, OSSTMM, OSINT etc.
- Good understanding of supported frameworks and cleansers functions
- Good understanding on core security mechanisms, crypto libraries, and server-side security
- Ability to understand vulnerabilities, interact and explain security risks/ impact to teams.
- Document vulnerabilities and collaborate with application team to help provide detail remediation along with code snippet.
- Experience in tools lie Fortify, Veracode
- Adopt risk-based approach to translate technology risk into actual business impacts and prioritized actions.
- Ability to listen and articulate ideas verbally and in written formats to a broad range of audiences; ability to ask probing questions and deliver presentations that have impact.
- Any security / technology related (Java/ .Net/ Python) certifications are a plus.
- Exposure to banking/ financial services domain is a plus.