Title: AppSec Consultant
Location: Richfield, MN (Day 1 Onsite)
Job Description -
- Excellent understanding of different application security vulnerabilities and their mitigation - OWASP, SANS etc.
- Scan the source code of Web and mobile applications and manually triage the results. Correlate these results and conduct follow-on tests as needed.
- Good understanding of common CVEs and exploits.
- Experience with writing custom rules in various tools and good understanding on how these scanners work.
- Perform analysis, design, and configuration of CI/CD tools and integration with different systems.
- Integrate CI/CD tools with existing security tools like Checkmarx, Veracode, Fortify, Blackduck etc.
- Excellent understanding on how dependencies are handled by applications and how each build tool works.
- Collaborate with application teams and onboard applications to various tools.
- Excellent understanding of different programming languages like Java, Groovy, Javascript and web frameworks like Spring, Node JS, React etc.
- Scripting with Shell/Python highly desired.
- Continuously advise development teams on how to remediate issues, including coding proof-of-concept solutions and advise dev teams on secure coding practices for addressing findings.
- Working knowledge of various dev tools like bitbucket, Jira, confluence etc.
Thanks & Regards,
Bikesh Kumar
Crox Consulting Inc.
Email:- bikesh.kumar@croxconsulting.com
LinkedIN:- https://www.linkedin.com/in/bikesh-kumar-a97ab614a/
- Contact – 9295657868 ext - 246