AppSec Expert
- Close collaborating with R&D teams to integrate and assure security at every stage in the software development lifecycle
- Regular security reviews and threat modeling of our applications
- Integrating security tools into processes and proactively introduce changes in case of any gaps
- Responding to security incidents
- Rise awareness among teams about application security (secure coding practices, security standards, security threats and countermeasures)
- Ensure applications are aligned with certifications requirements in scope of security (e.g. SAS SM, PCI DSS)
- Ensure teams are following internal and external security standards
- Experience in programming languages (Backend: Java, Scala, Kotlin, Frontend: Typescript, Angular)
- Knowledge of secure coding practices - to guide R&D teams how to avoid vulnerabilities and security flaws in code
- Experience with security frameworks and standards (OWASP Top Ten, ISO)
- Experience working with certifications requirements and supporting R&D team answer security related questions
- Good understanding of web application architecture but also of low levels communication protocols
- Proficiency with security tools and technologies (e.g. firewalls, intrusion detection systems, encryption, static analysis tools, dynamic analysis tools, and penetration testing tools)
- Experience in assuring security for cloud deployed applications and knowledge about security tools available in the cloud
- Good communication skills as you will be working with technical but also non-technical audience
- Problem-solving skills
- Critical thinking
- Continues learning and adaptability