Application Security Assessor

Zelis
Remote, MA, US
Remote
Full-time

Zelis is hiring an Application Security Assessor to work in collaboration with the corporate application development teams.

The position will be accountable for application security of corporate applications. You’ll work with Application Development teams to identify application assets, data flows, threats, and required cyber security controls, as well as with Application Security Testers to measure the effectiveness of identified cyber security controls.

Location and Workplace Flexibility : We have offices in Atlanta GA, Boston MA, Morristown NJ, Plano TX, St. Louis MO, St.

Petersburg FL, and Hyderabad, India. We foster a hybrid and remote friendly culture and all of our employee's work locations are based on the needs of the position and determined by the Leadership team.

In-office work and activities, if applicable, vary based on the work and team objectives in accordance with Company policies.

Responsibilities :

  • Partner closely with corporate stakeholders to understand regulatory, industry, and organizational security requirements
  • Provide security requirements with acceptance criteria to application development teams using the Agile and Waterfall methodologies
  • Conduct threat modeling exercises to identify potential security vulnerabilities in corporate applications
  • Analyze application's components, data flows, and external dependencies to anticipate and mitigate threats
  • Review the architecture of software applications to ensure that security is integrated at every layer, including network, infrastructure, and application levels
  • Implement security controls and best practices to address identified risks and vulnerabilities, including encryption, authentication, access controls, input validation, and other security mechanisms
  • Perform security code reviews to identify and remediate security vulnerabilities in application code. Look for common security flaws such as injection attacks, cross-site scripting (XSS), and insecure configurations
  • Provide guidance and training to development teams on secure coding practices, security principles, and relevant security tools and technologies
  • Evaluate and implement security tools and automation solutions to enhance the security posture of applications and streamline security processes

Qualifications

  • Bachelor’s degree in Cyber Security (or) related degree and experience
  • 8+ years of experience in Cyber Security
  • 2+ years of experience in Agile and writing user stories
  • 2+ years of experience in Application Security and Threat Modeling, as well as application development or application secure code review
  • Understanding of API and Web security vulnerabilities
  • 2+ years of experience using Octave or Stride
  • Experience working within a DevSecOps environment

Preferred Qualifications

  • Experience in security coding, source code management, and / or build and deployment technologies
  • Experience with web application firewalls
  • Familiarity with OWASP Top 10 API, Web, and Mobile Application Security Risks
  • Familiarity with MITRE CWE Top 25 Most Dangerous Software Weaknesses
  • CDP, CISSP, E CDE or other relevant certifications
  • Familiarity with regulatory controls and industry best practices such as HIPAA, PCI, CIS, HiTrust, ISO 27001, NIST, etc.)
  • 30+ days ago
Related jobs
Zelis
Remote, MA, US
Remote

You’ll work with Application Development teams to identify application assets, data flows, threats, and required cyber security controls, as well as with Application Security Testers to measure the effectiveness of identified cyber security controls. Evaluate and implement security tools and automat...

Promoted
Accenture Federal Services
Boston, Massachusetts

Accenture Federal Services’ National Security Portfolio (NSP) is seeking a highly motivated Requirements Analyst to support the integration, testing, deployment, and sustainment of a Command, Control, Communications, Computers, Intelligence, Surveillance and Reconnaissance (C4ISR) system to provide ...

Promoted
Chipton-Ross
Chelmsford, Massachusetts

Chipton-Ross is seeking a Senior Configuration Analyst for a hybrid contract opportunity in Chelmsford, MA. The Senior Configuration Analyst will have the opportunity to work with our top, industry leading multi-disciplined design professionals. The Analyst will have the opportunity to design, devel...

Promoted
Draper Labs
Cambridge, Massachusetts

The Contractor Program Security Officer I is an experienced security professional who performs the duties as the primary Contractor Program Security Officer (CPSO) and/or primary Contractor Special Security Officer (CSSO). In addition, the Security Analyst will monitor classified information systems...

Promoted
Zelis Healthcare, LLC
Boston, Massachusetts

You'll work with Application Development teams to identify application assets, data flows, threats, and required cyber security controls, as well as with Application Security Testers to measure the effectiveness of identified cyber security controls. Evaluate and implement security tools and automat...

Promoted
UFP Technologies, Inc.
Newburyport, Massachusetts

The Cyber Security Analyst leads the firm's vulnerability management program, manages the annual cybersecurity assessments and penetration tests, and researches and reports on emerging threats to help the firm take pre-emptive risk mitigation steps. The Cyber Security Analyst is tasked with providin...

Commonwealth of Massachusetts
Boston, Massachusetts

Bachelor’s degree from an accredited college or university in Computer and Information Science, Computer Engineering, Computer Systems Analysis, Information Cybersecurity and five (5) years of progressive information security experience across various information security/information technology risk...

Qlik
Waltham, Massachusetts
Remote

TheApplication Security Engineer / Penetration Tester. Championing Security Best Practices:Inspire and promote software security best practices and guidelines, contributing to a culture of security awareness and excellence. Your role involves promoting and inspiring software security best practices,...

Athenahealth
Boston, Massachusetts

The Information Security group at athenahealth is looking for a security analyst to join our Cyber Security Operations Center (CSOC) team. IT security experience, with some exposure to information security (also known as cyber security). Completion of the Security+ certification, GIAC Certified Inci...

Partners HealthCare
Somerville, Massachusetts

The Information Security Analyst II will provide extensive support to the evolution and improvement of the existing Digitial Information Security Policy Portfolio. The Information Security Analyst II independently operates existing processes to operate security controls within their domain. The Info...