Java Cybersecurity Engineer
Rensselaer, NY 12207
Blackstone Technology Group, an award winning technology consulting and staffing firm, is seeking an Java Cybersecurity Developer, to work at our client site in Rensselaer, NY.
The Application Security Engineer will be responsible for integrating security into the development of NYSoH’ s applications. The Application Security Engineer will work closely with the software development team to threat model, vulnerability scan, and pen test the early software, system, and network architecture and identify required control points in the application stack. The Application Security Engineer will also work closely with developers to diagnose, document, and remediate application security vulnerabilities. The Application Security Engineer will also be responsible for evaluating, recommending, and implementing application security related software in an automated continuous integration/deployment environment.
This is a new position and the first application security hire. You will help to establish risk frameworks, identify application vulnerabilities, perform risk assessments, and work cross functionally to remediate, mitigate, or accept the risk(s) of vulnerabilities. Secondarily you will be responsible for implementation and maintenance of security tools with a focus on improving automated testing processes and reporting.
You would get an opportunity to work alongside some of the most senior engineers at GDIT to support the programs comprehensive efforts to identify and remediate software security defects and maintain a high level of software quality for our client.
· Provide leadership and expertise in application security.
· Develop remediation plans to target cyber security vulnerabilities.
· Offer cyber security thought leadership and secure coding standards.
· Identify appropriate security check points in the systems development life cycle.
· Perform risk-based, technical assessments of applications, using dynamic and static scanning tools; Produce reports, and meet with development team.
· Work with appropriate stakeholders in app dev and management to develop a formal Application Security Verification Standard within our SDLC process.
· Perform application security audits ensuring compliance with industry standards, procedures, etc.
· Consult with application development and technical operations on security designs of applications, potential vulnerabilities, and remediation.
· Create documentation and training materials to educate development team and other stakeholders on key security concepts.
· Research new attack vectors and stay current with cybersecurity news and trends.
· Develop and maintain a balanced application security program based on a well-defined application security framework.
· Conduct application security assessments / penetration tests and implement tools for dynamic/automated code reviews.
· Work with Development Designers and Application Architects on application design and implementation best-practice with role-based and appropriate access standards, as well as integration with Identity and Access Management environments.
· Continuously evaluate the organization’ s existing application security practices, define and measure security-related activities, and demonstrate concrete improvements to the application assurance program within the organization.
· Consult with the Development leadership on application development training for developers
The ideal candidate would have a development background, as well as a strong background in Security principles as it relates to code.
- Bachelor’ s Degree in computer science or other relevant discipline.
- Eight (8) years of Information Technology experience
- Must have come up or be a current Java programmer with a strong secure coding background.
- Three (3) – five (5) years’ experience in a software development field such as Software Developer, Architect, Software Quality Assurance, or Application Security Engineer.
- 3+ years of experience working in Information Security with a focus on application security
- Experience conducting application security assessments, penetration tests and implementing tools for dynamic/automated code reviews
- Demonstrated experience with security tools. Experience with dynamic and static application scanning: (Veracode, Appscan, Fortify.
- Experience developing remediation plans to target cyber security vulnerabilities
- Experience performing application security audits ensuring compliance with industry standards
- Ability to communicate effectively in writing and verbally with an attention to detail
- Demonstrated collaboration and teaching abilities.
- Strong analytical problem-solving skills.
- CISSP, CEH, CISA, OSCP, OSCE, or OSWE Certifications are a major plus
Blackstone Staffing Services is a division of Blackstone Technology Group, a global IT services and solutions firm that implements digital transformation solutions across commercial industry verticals and the US Federal Government. Blackstone’ s global staff augmentation practice was founded in 1998. Blackstone Staffing Services has offices in San Francisco, Denver, Houston, Colorado Springs, and Washington, DC. We specialize in IT staffing and place both technical and creative talent across a variety of industries and sectors.
EOE of Minorities/Females/Veterans/Disabilities