Security Engineer

New York, New York

Crescens
Job Expired - Click here to search for similar jobs
Job title: Security Engineer
Location: New York, NY (Hybrid)
Duration: 12+ Months


NOTES:

Normal Business Hours, Monday through Friday (not including a mandatory unpaid meal break after 6 hours of work), 35 work hours per week. If the consultant works more than 35 hours per week, the consultant must request overtime in the Agency's timekeeping system and the project manager must approve those hours worked above the weekly maximum.

Job Description:

SCOPE OF SERVICES

My City is a single portal for all City services and benefits. The vision is a simple, seamless, and intuitive experience interacting with City government digitally. It is designed with New Yorkers at the center of the process to prioritize features by conducting user research. My City produces value for New Yorkers, early and often through phased releases. There are several phases within the My City portal workstream (Childcare, Business Portal, Workforce Development Services and others). The Cyber Command is looking for additional support as the cyber threat landscape continues to evolve and Citywide cybersecurity solutions are deployed in large, complex networked environments. The needed resource skill set is specialized in: providing guidance at various stages of planning and implementing security design, processes and solutions, testing and validation, and pivot between numerous technical projects communicating status at various leadership levels. The resource will have significant interaction with Cyber Command leadership, its engineering, architecture, and application security teams, incident response and other cyber security practitioners.

Required Experience:

• 12 years of experience in application security, with a proven track record of conducting vulnerability assessments, penetration testing, and secure code reviews.

• Extensive experience in secure application development, including knowledge of security frameworks like OWASP Top 10, and the ability to guide development teams in implementing secure coding practices.

• Proficiency in Software Composition Analysis (SCA) tools (e.g., Veracode, AppSec) for identifying and managing vulnerabilities in open-source libraries and third-party components.

• Advanced knowledge of static and dynamic application security testing (SAST/DAST) tools (e.g., Veracode, AppSec, Burp Suite) and integrating these tools into CI/CD pipelines for automated security checks.

• Strong cloud security expertise, including securing applications and workloads on AWS, Azure, or GCP, and experience with Web Application Firewalls (WAF) and cloud-native security services.

DESIRABLE SKILLS/EXPERIENCE:
Advanced cloud security experience: Experience securing cloud environments
(AWS, Azure, GCP) with tools like Web Application Firewalls (WAF), and
implementing IAM, encryption, and monitoring tools.

• Experience with scripting and automation, using Python, Bash, or PowerShell, to automate security tasks, integrate security testing tools, and improve the efficiency of security operations.

• Strong communication skills: Ability to effectively explain complex security concepts and risks to both technical teams and non-technical stakeholders, ensuring alignment on security measures.

• Leadership and mentoring skills: Experience leading security teams or initiatives, mentoring junior engineers, and fostering a culture of security awareness within the organization.

• Collaboration and cross-functional teamwork: Proven ability to work effectively with development, DevOps, and IT teams to integrate security into all aspects of the business, ensuring security goals align with business objectives.

• Highly flexible/willing to learn new technologies.

• Highly organized with excellent analytical, problem solving and decision-making skills.

Additional Qualifications:

• Certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Cloud Security Professional (CCSP), or GIAC Web Application Penetration Tester (GWAPT) are highly preferred.

• Knowledge of compliance standards like NIST, PCI-DSS, and GDPR and how they apply to application security.
Date Posted: 28 February 2025
Job Expired - Click here to search for similar jobs