6 to 8 Years Relevant Experience
We are seeking a highly experienced Security Operations Engineer with a strong background in application security, secure coding, and software engineering. The ideal candidate will have deep knowledge of secure development practices, proficiency in modern programming languages, and experience with secure code review and analysis tools. This role is essential in safeguarding applications against security threats by embedding security across the software development lifecycle.
Key Responsibilities:
- Conduct in-depth secure code reviews and provide actionable recommendations to development teams.
- Collaborate with software engineers to promote and implement secure development practices across the SDLC.
- Identify and remediate vulnerabilities related to common attack vectors such as XSS, CSRF, SQL injection, and others.
- Use and manage static and dynamic analysis tools (e.g., SonarQube, Semgrep, Fortify) to detect security issues in codebases.
- Work closely with DevOps and engineering teams to integrate security into CI/CD pipelines.
- Participate in threat modeling exercises and proactively assess application architecture from a security standpoint.
- Stay current with the latest security trends, vulnerabilities, and compliance requirements.
Required Skills & Qualifications:
- Minimum 7 years of experience in application security, secure coding, or software engineering roles.
- Strong understanding of secure development principles and common OWASP vulnerabilities.
- Proficiency in at least one of the following programming languages: Java, JavaScript, Node.js, or Kotlin.
- Experience performing code-level debugging and vulnerability remediation.
- Hands-on experience with static code analysis and secure code review tools such as:
- SonarQube
- Semgrep
- Fortify or similar
Preferred Qualifications:
- Familiarity with DevSecOps and integrating security practices in Agile and CI/CD environments.
- Relevant certifications such as OSCP, CISSP, CEH, or CSSLP.
- Understanding of secure design patterns and secure architecture principles.