SemanticBits is looking for a Security Engineer to keep our business, users, and data safe by assuring the security of our applications and platforms. This will be a highly collaborative position, in which the right candidate works to secure existing applications and platforms, makes platform and security enhancements, and helps to scale our security program through automation, process improvement, and tool creation.

The selected candidate will be required to work on multiple products and must be able to develop and present secure solutions and advice to technical teams as well as leadership. The candidate will further be required to assess risks and advise on security standards, best practices, and solutions. All this must be done by maintaining security quality and customer satisfaction.

Responsibilities



Collaborating with various teams to secure new platforms/applications



Implementing platform security and framework improvements



Implementing analysis and monitoring tools



Working with engineering and QA teams to build tools and scale security in a continuous deployment environment



Assessing the security of applications, APIs, and platforms via penetration testing and code reviews



Document System Security plan and Contingency Plans for related projects



Requirements



A Bachelor's degree or higher in Computer Science, Electrical Engineering, Information Assurance, Network Security Computer Engineering or a related field, or equivalent experience



At least 5 years of experience in the following;





NIST 800-53 security controls





Penetration Testing





System Hardening (blue team)





Programming/Scripting (java, node, python, etc)





Incident Response





Strong knowledge to perform below tests:





Penetration testing







Static Analysis/Static Application Security Testing







Vulnerability Assessment/Scanning







Dynamic Analysis/Dynamic Application Security Test (DAST)







Malicious Software Analysis







Strong foundation in one or more of the following:





Data management security





Authentication





Applied cryptography





Linux security





Network & Cloud security





Strong engineering background preferred



Application architecture experience preferred



Advanced knowledge of Linux platforms



Advanced knowledge of application mobile security tools



Strong technical acumen securing software and hardware



Understanding of software development and working experience with any one of the higher level programming languages or scripting



Familiarity and experience with security technologies such as security engineering, security architecture, cryptography, data security, risk management, identity and access management, communication and network security, security assessment and testing, software development security, security operations



Familiarity and experience with popular open source security projects such as OWASP ZAP and Snort



Thorough understanding of issues documents in the OWASP Top Ten and CWE Top 25



Demonstrated ability to exploit and mitigate application-level vulnerabilities



Strong understanding of cryptography as applied to web application security (encryption, hashing, PKI management), including analysis and implementation



Experience using Linux/Unix at the command line for tasks related to web application development and deployment (DevOps)



One or more of the following certifications is preferred;

OSCP, OSCE, OSWE, CISSP, GPEN, GXPN