Search jobs > Indianapolis, IN > Temporary > Information security

IN DWD - Information Security Analyst - Code and Vulnerability Analysis

Lorven Technologies
Indianapolis, Indiana, United States
$42 an hour
Full-time

Position : IN DWD - Information Security Analyst - Code and Vulnerability Analysis

Location : Remote

Contract

Pay Rate : $42 / hr on W2

Candidate can use their own equipment, as long as that equipment is able to run Amazon Workspaces for connection into the state network.

Please confirm if candidate will be using their own equipment or if they will need state equipment.

Only 1 Slot Open

Key Responsibilities :

  • Analyze code scan output from Veracode and SonarQube, along with remediation recommendations from these tools.
  • Assess security risks associated with code vulnerabilities and develop a prioritization strategy that mitigates the most critical issues efficiently.
  • Convert scan results and remediation recommendations into well-defined stories within Atlassian Jira, aligning with the Scaled Agile Framework (SAFe) for collaboration with development teams.
  • Draft policies, procedures, and best practices for publication in Atlassian Confluence to ensure consistent security practices across the organization.
  • Monitor and validate the completion of all remediation work through subsequent code scans.
  • Provide regular progress updates to the information security manager.
  • Collaborate with development teams to implement secure coding practices and address identified vulnerabilities.

Required Skills and Experience :

  • 2-5 years of experience in information security, with a focus on code and vulnerability analysis.
  • Strong knowledge of manual audit, code reviews, and remediation techniques.
  • Proficiency in using Veracode and SonarQube toolsets for code scanning and vulnerability assessment.
  • Expertise in Java programming language and familiarity with secure coding standards and guidelines such as OWASP Top Ten, CERT / CC, MITRE, Sun, and NIST.
  • Experience working with Atlassian toolsets, particularly Jira, Service Desk, and Confluence.
  • Understanding of authentication, authorization, session management, and secure communication mechanisms.
  • Familiarity with Windows and Linux operating systems.
  • Experience working with ORACLE and MSSQL databases.
  • Knowledge of third-party library security analysis and the ability to identify potential security leaks.
  • Excellent problem-solving and analytical skills, with the ability to translate technical findings into actionable tasks for development teams.
  • Strong communication and collaboration skills to effectively work with cross-functional teams.

Preferred Qualifications :

  • Relevant certifications such as CISSP, CSSLP, or CEH are a plus.
  • Experience with automated security testing tools and continuous integration / continuous deployment (CI / CD) pipelines.
  • Knowledge of additional programming languages such as Python, C++, or C#.
  • Familiarity with cloud security best practices and securing cloud-based applications.

Skill

Required / Desired

Amount

of Experience

Information security code analysis and review

Required

Years

Java and secure coding standards

Required

Years

Veracode

Required

Years

Atlassian toolset with focus on Jira, Service Desk and Confluence

Required

Years

SonarQube

Nice to have

Years

CISSP, CSSLP or CEH certifications

Nice to have

30+ days ago
Related jobs
Lorven Technologies
Indianapolis, Indiana

Position: IN DWD - Information Security Analyst - Code and Vulnerability Analysis. Proficiency in using Veracode and SonarQube toolsets for code scanning and vulnerability assessment. Expertise in Java programming language and familiarity with secure coding standards and guidelines such as OWASP Top...

Promoted
Eli Lilly and Company
Remote, Indiana, Remote, Indiana
Remote

The candidate who fills this position will be responsible for automating our deployment and infrastructure provisioning processes, improving our monitoring and alerting capabilities, and helping us to achieve continuous delivery of the tools of a sophisticated security incident response team. In thi...

S&P Global
Indianapolis, Indiana

Work with individual product teams to gain an understanding of products, supporting technologies, and existing compliance approaches and documentation. This position within the Cyber Risk and Compliance team is designed to provide support to the Market Intelligence division with internal and externa...

Promoted
Eli Lilly and Company
Indianapolis, Indiana

The BPKC is responsible for providing business process and SAP training, consulting, high-level problem resolution, process improvements, innovation, project implementations, and tool and process governance in an effort to leverage the use of SAP and related global tools to make the Security & C...

Elevance Health
Indianapolis, Indiana

Requires BS/BA in Information Technology or related field of study and a minimum of 10 years’ experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, system...

2018 ALISE annual conference
Indianapolis, Indiana

We seek candidates who will pursue the highest standards of academic excellence and whose research, teaching, and community engagement efforts contribute to welcoming, respectful, and inclusive learning and working environments for our students, staff, and faculty. Candidates will have the potential...

inSync Staffing
Fishers, Indiana

All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. ...

Global Pharma Tek
Indianapolis, Indiana

In addition, role will be the point of contact for one or more agencies the individual will be responsible for creating reports that assesses the agency’s current security posture across several subject areas including, but not limited to, policy compliance, asset/software management, vulnerability ...

Baptist Health System KY & IN
Indiana

Under general direction, responsible for application and integration of information technology in the healthcare setting. Baptist Health is looking for an Epic Application Analyst Intermediate to join our team. This includes data collection, workflow analysis, system configuration, testing, and supp...

nLeague
Indianapolis, Indiana

The position participates in all aspects of the technology audit and monitoring including the planning, control analysis, testing, issue development, and reporting phases. Resource will works as an Information Security Analyst responsible for auditing and monitoring systems containing confidential i...