Application Security Engineer
Brak informacji o wynagrodzeniu
SeniorFull-time·B2B
#436926·Dodano dziś·1
Źródło: emagineTech Stack / Keywords
DefectDojoGitLabSonarQubeSCAPower BIJiraConfluenceJavaAngularPython
Firma i stanowisko
The project is in the telecommunication industry with a duration of 12 months contracts plus prolongations. The working language is English, and the work mode is 100% remote. The assignment type is B2B.
Wymagania
- Experience with vulnerability management tools (DefectDojo or equivalent).
- Knowledge of DevSecOps practices and CI/CD pipelines.
- Knowledge of secure secrets management procedures.
- Proficiency with GitLab and its security features.
- Familiarity with SCA and SAST tools (SonarQube).
- Reporting and data visualization skills (Power BI).
- Experience using Jira/Confluence.
- Experience with Agile Scrum methodology.
- Experience with OWASP security recommendations and NIS2 compliance.
- Proven experience with major development languages: Java, Angular, Python, Drupal.
Nice to have:
- Strong analytical and synthesis skills.
- Ability to collaborate with diverse technical teams.
- Ability to communicate security topics to non-experts.
- Autonomy and proactivity.
Obowiązki
- Analyze the current state component by component using DefectDojo.
- Collaborate with development teams on vulnerability mitigation.
- Present a remediation plan in coordination with Tech Leads and security profiles.
- Drive the execution of the remediation plan.
- Provide technical support to the DevOps team.
- Define and implement secrets management procedures.
- Leverage GitLab Ultimate security features.
- Contribute to the deployment of SCA solutions (SonarQube).
- Set up Power BI dashboards for high-level security reporting.
- Produce reports for the security team and developers.
- Ensure visibility on the evolution of the security posture.
emagine
648 aktywnych ofert