Pen Test Engineering

Austin, Texas

Advanced Technology Group, Inc
Job Expired - Click here to search for similar jobs

Do you guys do Pen Test Engineering within AppSec Groups? Heavy PYTHON.

I need a Pen tester, manual/auto mix, for DevSecOps / AppSec Eng group. Long term contract. Chicago preferred, or Dallas, or possible remote if stud.


Develop custom Docker containers to pull results from vulnerability management tools, verify results using custom rules, and print results into report(s)

  • Application Security Testing The use and maintenance of cloud and self-managed security scanning tools, manual source code reviews, and manual penetration assessments.
  • Vulnerability Management The cataloging, reviewing for false positives and mitigations, threat and risk assessments, and lifecycle management through remediation according to SLAs of application vulnerabilities.
  • Release Management Ongoing reviews of application releases to ensure only secure and reviewed code is pushed to prod, with automation tasks as necessary.
  • CI/CD pipeline Develop scripts to integrate Security tools into the Jenkins pipeline and assist development teams with interpreting results from pipeline vulnerability verification reports to facilitate vulnerability remediation.
  • Documentation Perform administrative and regulatory control activities including development of process and procedural documentation and gathering evidence for audits.
  • Process Improvement Continually enhance current practices, assess current toolset, and help implement new tools and processes to enhance current security coverage.
  • Perform application security manual penetration tests and with penetration testing tools such as Burp Suite, Kali Linux, Postman.

SKILL AND EXPERIENCE REQUIRED:

  • Gain an understanding of the system architecture and integrations.
  • Willingness to understand how the Security vulnerability management tools work and how reporting should be integrated
  • Programming knowledge and coding experience, particularly Python, JSON, JAVA, and Bash
  • Experience working with APIs
  • Experiencing parsing (HTML, XML, etc.)
  • Proficient in GitHub and Jenkins
  • Docker experience in automating deployments and testing

Date Posted: 09 May 2024
Job Expired - Click here to search for similar jobs