Web Application Security Analyst
Dice is the leading career destination for tech experts at every stage of their careers. Our client, Kforce Technology Staffing, is seeking the following. Apply via Dice today!RESPONSIBILITIES:Kforce has a client in Doral, FL that is seeking a Web Application Security Analyst who will be researching, preventing, detecting, and remediating security vulnerabilities at the infrastructure and application layers. The Web Application Security Analyst supports developing and maintaining an integrated Secure Software Development Lifecycle, protecting the integrity, confidentiality, and availability of corporate applications.Responsibilities: Perform web application security testing (includes dynamic and static code scanning) to identify vulnerabilities and security risks on web applications and back-end databases and collaborate with diverse IT and business teams to assist in the remediation efforts in a risk-prioritized, effective, and efficient fashion Provide application vulnerability assessments to corporate applications, identifying weaknesses and vulnerabilities with the system and proposing countermeasures Conduct continuous security analysis on network, application, and infrastructure components; conduct causal analysis and work across IT and business teams to develop solutions that address root causes Re-test fixed vulnerabilities and publish test results in formal security reports and dashboards for teams and management Collaborate closely with the Security Operations, Web Development, DevOps, and other operations teams to ensure appropriate response to security findings Monitor Web Application Firewalls (WAF) to identify malicious activity and attack patterns and participate in the incident response process when suspicious activity is noted Support management and tuning efforts for on-premise and cloud-based web application firewalls (WAF) Function as a subject matter expert during security incidents. Interact with and assist investigative teams with time-sensitive, critical investigationsREQUIREMENTS: Bachelor's degree in Management Information System, Computer Science, or related work experience 10+ years of experience within web application security Extensive working knowledge of web applications and technologies: Understanding of application programming languages, application servers, web services, browser technology, common vulnerabilities, security best practices, automated assessment tools, and manual testing techniques specific to web applications Experience with application security testing tools such as IBM AppScan, HP Fortify (On Demand), Qualys Web Application Scanner (WAS), and BurpSuite Knowledge of and experience performing manual source code review for security vulnerabilities Knowledge of and experience testing on web, desktop-based, and mobile applications, performing information gathering, privileged escalations, input validation, single sign-on, web-based loopholes, and business logic flaws in source code Knowledge of and experience with cloud Web Application Firewalls (Akamai Managed KONA) Knowledge of and experience with applying Common Weakness Enumeration (CWE), Common Vulnerability Scoring System (CVSS), Common Vulnerabilities and Exposures (CVE) and Open Web Application Security Project (OWASP) processes and remediation recommendations Ability to influence and communicate effectively: excellent written and verbal communications skills, including an ability to communicate very technical findings to both technical and non-technical audiences, including project managers, systems engineers, developers, enterprise architects, and senior management Knowledge and experience with diverse IT architectures and enterprise IT data centers, large scale transaction processing environments, external hosted services and cloud computing environments Knowledge and experience with physical and virtual server configurations and implementationsThe pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.This job is not eligible for bonuses, incentives or commissions.Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.