Cybersecurity Application Security Engineer
Tampa, FL
The on-site Continuous Integration /Continuous Delivery (CI/CD) application cybersecurity engineer will specialize in implementing security analysis tools and security gates into all stages of the CI/CD pipeline. Primary function is to work with agile development teams to review application risks, provide remediation recommendations, and help prevent future risks by cultivating secure coding practices. The ideal candidate is someone with a developer background, has DevSecOps experience, and has performed application cybersecurity testing in a prior role. Must also have excellent attention to detail, strong analytic, and communication skills, as well as a working knowledge and understanding of application cybersecurity toolsets used in the CI/CD DevSecOps pipelines. In addition, the contractor will provide application cybersecurity engineer expertise, collaborate with agile development teams, and integrate DevSecOps pipeline solutions, defining a security baseline per product to ensure proper cybersecurity and compliance.
Typical Duties Include: Provide cybersecurity guidance and direction in the design, development and implementation of automated solutions, based on a set of standards and processes that enable CI/CD developers to easily apply cybersecurity and compliance services. Responsible for, support of, and coordinating with other Engineers, Architects, and teams in implementing a comprehensive cloud and application cybersecurity program in a DevOps environment. Automate cybersecurity testing using a variety of architectures and cutting-edge technologies. Design, execute, and maintain automated cybersecurity testing for web applications (apps), mobile apps, and application programming interfaces (APIs). Actively review and implement improvements to drive continuous improvement of the efficiency, speed, and quality of the CI/CD DevSecOps environment. Leverage DevSecOps tools to build, harden, maintain and instrument a comprehensive cloud-based cybersecurity orchestration platform to be used in product CI/CD pipelines. Integrate cybersecurity practices across the continuous delivery pipeline to provide a comprehensive automated cloud and application cybersecurity solution. Perform risk and vulnerability assessments of CI/CD IT and IS platforms for authorization; prepare risk assessment reports for submission to the SCA and AO in accordance with DoD, USCYBERCOM, USSOCOM policies, procedures, and regulations. Coordinate, manage and facilitate CI/CD application cybersecurity compliance processes with internal and external stakeholders to provide timely deliverables and rapid remediation. Support the development of standards by creating templates and patterns for ease of use and increase the productivity of the cybersecurity program Foster,and build a community of practice for collective learning of the cybersecurity tools, practices, and systems across all disciplines. Maintain application cybersecurity toolsets used in the development pipelines. Work hand in hand with developer teams to implement testing into their pipelines. Professional curiosity that leads to learning and staying current with business best practices. Work with leadership to identify and revise cybersecurity testing approaches. Able to work on multiple projects and prioritize accordingly.
Knowledge, Skills and Abilities: Experience with CI/CD DevSecOps integration with tools such as Jenkins, JIRA, GitLab, and Bitbucket Strong experience in cloud and application cybersecurity domains. Experience with OR knowledge of supporting Cloud based platforms (Google, Microsoft, Amazon Web Services (AWS), and Military Cloud (MilCloud)). Experience with OR knowledge of Open Containers Initiative (OCI) compliant containers and OpenShift Container Platform technology utilizing Kubernetes orchestration technology. Strong and evolving competence in one or more programming languages and scripting using Python, Personal Homepage (PHP), Just Another Virtual Architecture (JAVA), JAVA Script, Power Business Intelligence (BI) and .Net Core. Experience with container cybersecurity solutions such as Twistlock and Claire to scan for vulnerabilities within OCI containers. Have used source control (github/gitlab) to manage code. Experience working in a Linux or Universal Network Information Exchange (UNIX) based environment. Extensive experience in implementing and enforcing application cybersecurity and vulnerability management. Thorough understanding of release strategies that minimize or eliminate application downtime. Experience with Change Management and Ticketing Systems (Remedy). A good understanding of the Software Development Life Cycle (SDLC) and Agile software development methodology Experience with OR knowledge of the Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs) and NIST regulations Active TS/SCI clearance requiredMinimum of 8 years of experienceDoD 8570 IAT II (CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP)BA/BS degree
Halvik offers a competitive full benefits package including:Company-supported medical, dental, vision, life, STD, and LTD insuranceBenefits include 11 federal holidays and PTO.401(k) with company matchingFlexible Spending Accounts for commuter, medical, and dependent care expensesTuition AssistanceCharitable Contribution matching
To comply with the guidance provided by the Safer Federal Workforce Task Force (Task Force) for Federal Contractors and Subcontractors, Halvik is requiring COVID-19 vaccinations for all their employees except where an employee is legally entitled to an accommodation.
Halvik Corp is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile APIs Application security AWS Bitbucket CI/CD Clearance Cloud Compliance DevOps DevSecOps DoD DoDD 8570 GICSP GitHub GSEC Java Jira Kubernetes Linux NIST PHP Python Risk assessment Risk Assessment Report Risk management Scripting SDLC Security analysis SSCP TS/SCI Twistlock UNIX Vulnerabilities Vulnerability management
Perks/benefits: Career development Health care
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Cyber Security Engineer jobs
- Open Product Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cyber Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Cybersecurity Analyst jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Information Security Engineer jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Specialist jobs
- Open IT Security Analyst jobs
- Open Chief Information Security Officer jobs
- Open Security Researcher jobs
- Open Security Specialist jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Cyber Security Specialist jobs
- Open Information System Security Officer (ISSO) jobs
- Open Agile-related jobs
- Open ISO 27001-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open CISM-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open CISA-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Java-related jobs
- Open Kubernetes-related jobs
- Open Security Clearance-related jobs
- Open EDR-related jobs
- Open Malware-related jobs
- Open IDS-related jobs
- Open APIs-related jobs
- Open CEH-related jobs
- Open CI/CD-related jobs