Senior Application Security Engineer
Atlanta, GA
Contract
Up to $62.32/hr
Every year, nearly 200 million travelers trust our client to get them where they're going. Take your career to new heights by working for this longstanding leader in air travel that services more worldwide destinations than any other airline.
We are looking for a Senior Application Security Engineer to join our team for a long-term contract in Atlanta, GA (hybrid). You will use DevOps practices to support the enterprise in adapting its development and DevSecOps methodologies. You will be involved in building, administering, and supporting modern development tools to help the company’s cloud journey. You will apply secure coding best practices to find and address application vulnerabilities. You should be comfortable supporting applications across various cloud platforms, including AWS, Azure, and GCP.
Contract Duration: 12 Months
Required Skills & Experience
- B.S. preferably in a technical or scientific field with 7 years of software and development experience, with a minimum of 5+ years of hands-on experience working with DevSecOps Technologies.
- Minimum 5+ years hands-on experience working with Cloud technologies.
- Experience in API testing tools (Postman, BurpSuite or any comparable tools)
- Excellent understanding of DevSecOps techniques and processes, guide integration of various tools in DevSecOps processes (GitLab/GitHub, SonarQube, Jenkins, Selenium, Ansible, Docker, Kubernetes, and containerization).
- Should be well versed with the AWS well architected framework or TOGAF and able to apply those principles while designing a solution
- Experience building, engineering and supporting applications in the Cloud (AWS, Azure, GCP)
- Experience conducting vulnerability risk and impact assessment
- Understand how to integrate security capabilities in cloud and application lifecycle management platforms especially in a DevOps model
- Excellent written and verbal communication skills
- Strong sense of urgency and ownership
Desired Skills & Experience
- Extensive experience in application security and/or ethical hacking
- Extensive experience in software development
- Experience integrating secure coding techniques with product teams
- Professional certifications in Security, Cloud, Container or DevOps
What You Will Be Doing
- Leads projects to implement tools in CICD pipelines to implement automated Static Application Security Test (SAST), Dynamic Application Security Test (DAST) and Source Code Analysis (SCA).
- Works within the DevSecOps model to secure Containers, withing ROSA, Tekton and OpenShift pipelines
- Designs, develops, plans, implements, and supports Cloud DevSecOps processes across multiple business units, ensuring alignment with secure coding best practices.
- Possess extensive knowledge of CI tools such as Jenkins, Tekton, CircleCI, Gitlab, AWS CodePipeline etc.
- Test driven mindset with experience in automation with development tools
- Facilitates training on enterprise tools and best practices
- Collaborate with and across Agile teams to design, develop, test, implement, and support technical solutions in full-stack development tools and technologies
- Apply software development skills (e.g., Java, C#.NET, JavaScript) to recommend and apply secure coding practices
- Utilize programming languages like JavaScript, Java, HTML/CSS, TypeScript, SQL, Python, and Go, Open-Source RDBMS and NoSQL databases, Container Orchestration services including Docker and Kubernetes, and a variety of AWS tools and services
- Knowledge of OWASP secure coding standards.
- Experience with Agile methodologies.
- Experience with AWS and Kubernetes
- Consult with development Teams to perform security reviews of software designs and help developers to ensure quality and robustness of our internal products
- Conduct security assessments against web applications and APIs across a variety of technology stacks
- Performs technical design reviews and code reviews.
- Drive awareness and knowledge of security in the developer community
- Experience in implementing, deploying, and providing support for custom AWS Config Rules, CFN Hooks, and CFN Guard Rules
You will receive the following benefits:
- Medical Insurance - Four medical plans to choose from for you and your family
- Dental & Orthodontia Benefits
- Vision Benefits
- Health Savings Account (HSA)
- Health and Dependent Care Flexible Spending Accounts
- Voluntary Life Insurance, Long-Term & Short-Term Disability Insurance
- Hospital Indemnity Insurance
- 401(k) including match with pre and post-tax options
- Paid Sick Time Leave
- Legal and Identity Protection Plans
- Pre-tax Commuter Benefit
- 529 College Saver Plan
Motion Recruitment Partners (MRP) is an Equal Opportunity Employer, including Veterans/Disability/Women. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP’s Employment Accommodation policy. Applicants need to make their needs known in advance.