Secure Application Development Opportunity
Our organization is seeking an experienced Cybersecurity Expert to join our team.
As a key member of our security group, you will play a vital role in ensuring the security and integrity of our applications.
- Collaborate with internal teams to implement security controls, address vulnerabilities, and improve security practices across platforms & services.
- Conduct penetration testing on web applications, mobile applications, APIs, networks, and systems, coordinating with external partners as needed.
- Identify, document, and process vulnerabilities, threats, and risks according to our risk management policies.
- Participate in security incident resolution and help develop, maintain, and evaluate the Incident Response Plan.
- Monitor internal alerting systems and ensure timely resolution of security events.
- Participate in audits, including user access reviews, and ensure remediation of findings within agreed timelines.
- Enhance security awareness within technical teams through educational materials and campaigns.
- Review and update internal security policies and controls regularly.
Required Skills and Qualifications:
- Bachelor's degree in Computer Science, Information Security, or related field.
- 2+ years in application development.
- 3-5 years of experience in information security or similar roles.
- Proven experience as a Security Analyst, Engineer, Penetration Tester, or similar.
- Experience with security frameworks like ISO 27001, NIST, and Data Protection.
- Understanding of securing corporate environments and applications.
- Knowledge of hosting platforms, cloud services, and enterprise networking.
- Technical understanding of backend architectures.
- Familiarity with secure coding practices and vulnerability management frameworks (OWASP).
- Strong knowledge of identity and access management practices.
- Experience with security technologies such as firewalls, IDS/IPS, vulnerability scanning tools.
- Proficiency in programming languages like Python or C++.
- Understanding of network protocols and encryption algorithms.
- Knowledge of compliance standards like PCI DSS, GDPR.
- Excellent communication skills and analytical problem-solving abilities.
- Willingness to stay updated with emerging threats and technologies.