应用安全工程师(美国远程)
Application Security Engineer (Remote in the U.S.)
GuidePoint Security 提供值得信赖的网络安全专业知识、解决方案和服务,帮助组织做出更好的决策并降低风险。通过采用三层、全面的方法来评估安全态势和生态系统,GuidePoint 使一些国内顶尖组织,如财富 500 强公司和美国政府机构,能够识别威胁、优化资源并整合最适合的解决方案以降低风险。
职位职责:
- 运行客户端 SAST、DAST 和 SCA 工具,审查输出结果并提供建议
- 实现工具与流水线、工单系统等的集成
- 与开发人员协作,提供安全设计指导和修复策略
- 熟悉 CI/CD 系统(如 GitHub)并能将软件安全工具集成到开发流程中
- 对 Web 应用安全原则和最佳实践有深入理解
- 管理、维护和操作应用安全工具,包括配置、调优和自动化
任职要求:
- 3 年以上应用安全相关岗位经验。有软件开发经验者优先
- 熟悉多种 SAST/DAST/SCA 应用安全工具(Checkmarx、Veracode、Synk、Invicti、Semgrep、Blackduck 等)
- 熟悉手动测试工具,如 Burp Suite Pro
- 有将工具集成到开发流水线的经验
- 有理解和缓解应用安全相关漏洞的经验
- 有审查 JavaScript、Python、Java、C++、PHP 或 C# 编写的源代码的经验
- 熟悉集成开发环境(IDE)和持续集成/持续交付(CI/CD)流水线工具和流程(如 Azure Dev Ops、Jenkins、Bamboo 等)
- 熟悉安全开发生命周期,并有修复由 Web 应用扫描工具发现的技术漏洞的经验
- 有信息系统架构、安全控制设计和开发经验
- 愿意拥抱新兴技术,包括 AI 工具,以更高效地工作、解决问题并推动更好的业务成果
我们使用 Greenhouse Software 作为申请人跟踪系统,使用 Zoom Scheduler 进行人力资源初筛安排。有时您的电子邮件可能会阻止我们与您联系。请确保检查您的垃圾邮件文件夹,以免错过申请状态的更新。
为什么选择 GuidePoint?
GuidePoint Security 是一家快速成长、盈利且由私人持有的增值企业
查看英文原文
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
Role and responsibilities:
- Run client SAST, DAST, and SCA tools, review outputs and provide recommendations
- Implement integrations for tools into pipelines, ticketing systems, etc.
- Collaborate with developers to provide secure design guidance and remediation strategies
- Familiarity with CI/CD systems (i.e. GitHub) and integrating software security tools into the development workflow
- Strong understanding of web application security principles and best practices
- Manage, maintain and operate application security tooling, including configuration, tuning, and automation
Requirements:
- 3+ years of experience in an Application Security focused position. Prior experience in a software development role preferred.
- Experience with multiple SAST/DAST/SCA Application Security tools (Checkmarx, Veracode, Synk, Invicti, Semgrep, Blackduck, etc.)
- Manual testing tools such as Burp Suite Pro
- Experience with the integration of tools into development pipelines
- Experience understanding and mitigating Application Security related vulnerabilities
- Experience with reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#
- Integrated Development Environment (IDE) and Continuous integration / Continuous Delivery (CI/CD) Pipeline tools and processes (e.g. Azure Dev Ops, Jenkins, Bamboo, etc.)
- Secure Development Lifecycles and experience remediating technical vulnerabilities identified by web application scanning tools
- Information Systems architecture, security control design, and development experience
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?
GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.
This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option