Search jobs > Atlanta, GA > Temporary > Sr information security

Sr. Security Engineer - Information Technology

Innova Solutions Inc.
Atlanta, Georgia, US
Full-time

Sr. Security Engineer - Information Technology

Atlanta, Georgia

Ready to apply Before you do, make sure to read all the details pertaining to this job in the description below.

Contract

Added - 10 / 16 / 24

Job Description

Innova Solutions has a client that is immediately hiring for a Sr. Application & Cloud Container Security Engineer.

Position type : Contract with possible extension.

Duration : 12+ Months

Location : Atlanta, GA 30354 (Hybrid)

As a Sr. Application & Cloud Container Security Engineer, you will :

  • Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Source Code Analysis (SCA) using Veracode.
  • Correlate findings from tools such as the Veracode Source Code Agent to identify the presence of vulnerable methods in code.
  • Research open-source community contributors and the NIST National Vulnerability Database (NVD) to understand residual risk and recommend a course of action.
  • Determine how frequently and quickly fixes should be delivered for open-source findings.
  • Review SCA reports to track new components and changes to existing SCA components in the environment.
  • Have experience working with tools such as Sonatype Nexus Firewall and Nexus Lifecycle to track and block risks associated with third-party components.
  • Work within the DevSecOps model to secure containers using ROSA, Tekton, and OpenShift pipelines.
  • Design, develop, plan, implement, and maintain Cloud DevSecOps processes across multiple technical organizations, instantiating security testing for internally developed systems, applications, and infrastructure against business requirements.
  • Guide development teams in integrating new services and applications into the CI / CD pipeline, troubleshoot installations, and build automated deployments of products into a high-security architecture.
  • Possess knowledge of CI / CD orchestration tools such as Jenkins, Tekton, GitLab, or Bamboo.
  • Provide operational support for container security tools (e.g., Palo Alto Prisma, Aqua, Wiz, or equivalent).
  • Perform baseline image validation of new container template images.
  • Evaluate scan results for container runtime environments to reduce security risk.
  • Troubleshoot any connectivity or operational issues for clusters being evaluated in the Prisma tool.
  • Validate and address vulnerability and threat findings from static and dynamic analysis tools.
  • Characterize threats and provide recommendations for remediation; manage remediation efforts to completion.
  • Develop and present findings and remediation reports to audiences, including team members from all department areas and levels of the company.
  • Perform security reviews of software designs and assist developers to ensure the quality and robustness of our internal products.
  • Conduct security assessments against web applications and APIs across a variety of technology stacks.
  • Ensure adequate security requirements and privacy by design are built into all architecture, infrastructure, and projects.
  • Integrate threat modeling practices into the application testing lifecycle.
  • Impart application security and ethical hacking expertise into team processes.
  • Drive improvements in the security testing practice, including execution methodology and metrics.
  • Promote awareness and knowledge of security within the developer community.
  • Continuously improve proficiency in application and API exploitation, tools, techniques, and countermeasures.

The ideal candidate will have :

  • A B.S. degree in Computer Science, Computer Engineering, Information Assurance, or a related field.
  • Professional experience in application security, penetration testing, security assessment, secure software development, or a related field.
  • Hands-on experience working with Cloud and / or DevSecOps-related technologies.
  • An excellent understanding of DevSecOps techniques and processes, with the ability to guide the integration of various tools in DevSecOps processes (GitLab / GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization).
  • Familiarity with the AWS Well-Architected Framework or TOGAF and the ability to apply those principles while designing a solution.
  • Experience building and supporting applications in the Cloud (AWS, Azure, GCP).
  • Experience engineering software within an Amazon Web Services (AWS) cloud infrastructure.
  • The ability to troubleshoot and resolve problems with existing cloud controls.
  • Extensive knowledge of the OWASP Top 10.
  • Experience with vulnerability risk and impact assessments.
  • Experience integrating security capabilities in cloud and application lifecycle management platforms, especially in a DevOps model.
  • Extensive knowledge of static analysis tools and flaw triage tools such as HP Fortify, IBM Rational, Veracode, Coverity, FindBugs, FindSecurityBugs, Brakeman, and open-source scanning tools like Sonatype CLM.
  • Excellent written and verbal communication skills.
  • A strong sense of urgency and ownership.

Qualified candidates should APPLY NOW for immediate consideration! Innova Solutions is an Equal Opportunity Employer and prohibits any kind of unlawful discrimination and harassment.

J-18808-Ljbffr

9 hours ago
Related jobs
Innova Solutions Inc.
Atlanta, Georgia

Security Engineer - Information Technology. Application & Cloud Container Security Engineer. Application & Cloud Container Security Engineer, you will:. Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Source Code Analysis (SCA) using Verac...

Georgia Institute of Technology
Atlanta, Georgia

The Information Systems Engineer develops technical designs and provides support of the organization’s end-user computing environment. The Information Systems Engineer is responsible for the day-to-day operational activities of the end-user computing environment, including but not limited to Windows...

Children's Healthcare of Atlanta
Brookhaven, Georgia

Network Security Protocols and Methodologies, Information Security & IT controls, security penetration and vulnerability assessments. Certified or willingness to obtain certification within one year of hire in the following area(s): Certified Information Systems Security Professional (CISSP), GIAC C...

Georgia Tech
Atlanta, Georgia

This job requires advanced knowledge and skill in the installation and maintenance of information technology hardware and software at all layers; a full understanding of industry practices and campus policies and procedures; advanced skills in problem solving, decision making, customer service, syst...

BlueSky Technology Solutions
Atlanta, Georgia

Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or other similar credentials. Strong ability to facilitate an information security gove...

City Of Atlanta
Atlanta, Georgia

Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field; or equivalent work experience. Collaborate with the cybersecurity team to ensure robust security measures and compliance with industry standards. Familiarity with other email security solutions and cybe...

GDIT
Decatur, Georgia

The ISSE employs best practices when implementing security requirements within an information system including software engineering methodologies, system/ security engineering principles, secure design, secure architecture, and secure coding techniques. Transform technology into opportunity as an In...

Tata Consultancy Services
Atlanta, Georgia

Interacting with development teams to articulate security requirements and processes while collaborating on architecture and engineering design options, implementation, testing, and user acceptance. Overview of current threats, risks, information security techniques, and controls to mitigate them. W...

Highmark Health
GA, Working at Home, Georgia

The Principal Information Security Architect - Healthcare Delivery Technology serves as the most senior security architect and advanced technology analyst for healthcare delivery systems and IOT in the company. The Open Group Architecture Framework Certification (TOGAF), Certified Information Securi...

Z1 Discovery Communications LLC
Atlanta, Georgia

Relevant certifications such as AWS Certified Security - Specialty, Google Professional Cloud Security Engineer, or Microsoft Certified: Azure Security Engineer Associate are highly desirable. Ensure the security of containerized applications by implementing best practices for Kubernetes and microse...