Role Title: Software Security Developer 12+ months Contract Remote W2 Candidates Only Education: Bachelors degree in science, technology, engineering, or math (STEM) field. Required Skills: Nine (9) years IT security (Cybersecurity) experience; or seven (7) years with a Masters; or four (4) years with a PhD. Experience can be considered in lieu of degree. Need at least one Certification from *each* of the bullets.
- Certified Application Security Engineer (CASE) Certification or Certified Secure Software Lifecycle Professional (CSSLP) Certification; and
- Certified Ethical Hacker (CEH) Certification or Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP); and
- WS Certified Solutions Architect Professional or AWS Certified DevOps Engineer Professional.
Experience with DevOpsSec pipeline tools including configuration management, requirements (e.g. JIRA), automated testing, automated deployments, blue green deployments, and branching strategy and implementation. Experience in cloud computing including concepts, capabilities, and applications as they relate to storage, processing, and dissemination and overall security. Demonstrated experience working with multi-disciplinary teams to fulfill stakeholder requirements. Professional experience using a programming language such as Java, Python, JavaScript, or equivalent to build and design complex software applications. Professional experience designing, developing, testing, and deploying software to include full stack web-based applications using industry standard DevOps tools. Experience in applying agile development methodologies to develop software. Experience building web application programming interfaces (API) using standards established in NIST SP 800-204. Demonstrated experience with the complete software development lifecycle (SDLC). Experience applying software security techniques, controls, and best practices to engineer software to mitigate vulnerabilities and risk against malicious attacks and ensure continued operations. Demonstrated expertise in developing and managing IT or software governance policy (e.g. software development standards, best practices in building and maintaining software). Experience with performing Security Control Assessment in compliance with NIST SP 800- 37, NIST SP 800-53, NIST SP 800-53A, and other NIST 800 guide series. Day-to-day Responsibilities: The Software Security Developer has the overall responsibility to developing so??ware applications, services, and systems (e.g., user-facing and back-end services). Manage source code using industry version control best practices. Research new techniques and technologies to stay current in software development methodologies and tools. Utilize code validation tools to ensure that source code is valid, is properly structured, meets industry standards, is secure, and is compatible with browsers, devices, or operating systems. Collaborate with stakeholders to define needs and/or specifications and develop proposed solutions. Test and integrate developed software applications into the operational baseline. Perform test driven development utilizing strong unit testing techniques to include test cases mimicking external interfaces and addressing all browser and device types. Modify or enhance existing software to correct errors, to adapt it to new hardware, or to upgrade interfaces and improve performance. Create technical models, architectural artifacts, and/or prototypes that include physical, interface, logical, or data models (e.g., model view controller (MVC) programming practices). Share actionable/valuable information with colleagues and leadership and engage with community as resident expert. Prepare reports and consult with customers or other stakeholders to advise on technical issues, provide operational support, respond to questions, and offer status updates. Develop DevOpsSec (CI/CD) pipelines and incorporate security protocols while deploying infrastructure as code (IaC).
aws-devops DevOps SDLC Jira Agile API Python Java JavaScript Certified Ethical Hacker (CEH) Certified Information Systems Security Professional (CISSP)