Hi


There is an urgent requirement of *Application Security Consultant @
Wilmington, DE.* If interested then please send your updated resume ASAP.



*Position : Application Security Consultant*

*Location: Wilmington, DE*

*Duration: 6+ Months*




*Job Description:*



This role will be responsible for the Application Risk Management.  The
individual will ensure the Security of all applications and systems.  This
includes understanding all existing web based (Java & .NET) and other third
party applications running in the environment, reviewing security
provisions of all new applications and major changes in the environment.
Penetration testing of various application systems on a regular basis is a
required skill along with managing and reviewing the work of other testers
including contract testers.  Reporting to Management on a regular basis
through welldefined metrics is required.  This individual should have
business acumen and detailed understanding of the Software development
lifecycle.  Work with application development team leads to ensure
application security is aligned with policy, security best practices and
business needs



*Essential Functions:*



·         Support projects within the SDLC and Agile environments with
applications security testing penetration testing and vulnerability
management functions.

·         Perform Web / Mobile application security assessments and
penetration testing on projects and/or releases; produce detailed risk
reports with identified vulnerabilities and remediation recommendations.

·         Conduct static and dynamic code analysis as needed to support
release cycles.

·         Work closely with development team during the envisioning and
development process to guide secure design and secure coding practices.

·         Manage web application firewall through log analysis, system
tuning and rule development.

·         Evaluate, track, and ensure compliance of high and critical
vulnerabilities; develop, maintain and update scorecards to reflect
vulnerabilities and communicate to end users.

·         Implement security solutions, and provide technical leadership
during the design, development, and testing phases of major initiatives.



*Knowledge, Skills, Education, Experience, and Competencies:*



·         Experience with performing manual and automated code review and
develop/propose /enforce secure coding standards and policies.

·         Knowledge of in the OWASP top 10 and related exploitation
techniques, including but not limited to crosssite scripting, SQL
injections, session hijacking and buffer overflows to obtain controlled
access to target systems.

·         Good Understanding of various web application architectures and
web technologies ( Java, MS .NET etc.)

·         Experience in application firewalls, and intrusion prevention
systems (e.g. Mod security) Experience with commercial application scanning
tools (DAST) like IBM's AppScan, HP’s WebInspect, etc.

·         Experience with commercial static analysis tools (SAST) like HP’s
Fortify, Klockworks etc.

·         Indepth knowledge of any proxying and/or fuzzing tools such as
Paros, Burp, WebScarab, OWASP ZAP etc.

·         Familiar with WebServices technologies like XML, SOAP, and AJAX.

·         Understanding of server and client side application development
, Middleware software’s (Oracle’s WebLogic, IBM’s WebSphere, Apache Tomcat )

·         Proficiency in utilization of information security tools such as
Nmap, Nessus, Burp Suite, Kismet, and Metasploit; manual techniques to
exploit vulnerabilities in networks and applications.



*Desired Certifications:*



·         Industry certifications preferred CEH, OSCP, GWAPT, LPT or ECSA

·         Additional certification desirable CSSLP and GSSP





Thanks & Regards



*Sumit Suman*

Saviance Technologies

16 Bridge St , Metuchen, NJ - 08840
Phone: +1 732-902-0866

Email : [email protected]

Web : www.saviance.com

*New Jersey I Seattle I Los Angeles I Atlanta I Houston *

-- 
You received this message because you are subscribed to the Google Groups 
"US_IT.Groups" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at https://groups.google.com/group/us_itgroups.
For more options, visit https://groups.google.com/d/optout.

Reply via email to