
Sr. Software Security Engineer
- Cork
- Permanent
- Full-time
- Perform operational support for AWS WAF configurations – updating whitelists and creating security automation web ACLs to protect Internet facing endpoints and applications.
- Perform operational support for Azure WAF configurations
- Automate Dynamic Application Security Testing (DAST) in the CI/CD pipeline.
- Perform manual penetration tests on web applications
- Maintain Cloudflare DDOS protections and WAF configurations.
- Attend enterprise architecture reviews to standardize and secure new deployments
- Bachelor’s degree in computer science or engineering field or equivalent combination of education and relevant 3 – 5 years of experience
- Experience with GitHub, Perforce, GitLab
- Experience with SonaType, JFrog
- Good working knowledge in scripting language, Python, PowerShell, etc.
- Strong understanding of Linux/UNIX and Windows based operating systems and networks.
- A passion to learn and educate others on how to build secure software.
- Experience with CVE and CVSS vulnerability scoring
- Experience with Jira IT ticketing systems.
- US and EU Cybersecurity regulations
- Ability to work in a group setting and independently
- Certified Information Systems Security Professional (CISSP)
- SANS GIAC certifications
- Amazon Web Services, Azure, Google Cloud Platform
- Experience in OWASP Top 10 and usage of common AppSec testing tools.
- Experience of Secure by Design concepts and threat modeling
- Knowledge of common security libraries, security controls, and common security flaws.
- Experience in application penetration testing techniques and tools
- Knowledge of application technologies including Web applications, Web services, XML, SOA, AJAX, JSON, and Web scanning tools
- Open Source Security (OSS) - Software Composition Analysis (SCA)
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Security Architecture Review - Threat Modeling
- AWS and Azure WAF Configuration and whitelisting
- Cloudflare DDOS configuration and operation
- Manual Penetration Testing
- Penetration testing with 3rd party vendors
- Host level vulnerability Scanning
- Web application security training course development and delivery
10% domestic travel”).We’re doing work that matters. Help us solve what others can’t.