architecturerisk assessmentcybersecuritysoftware development lifecycleappsecthreat modelingapplication securityssdlcsecure developmentsecurity auditssecurity code review
Загружаем источник...
Пожаловаться
60
Средняя вакансия
развернуть
Роль хорошо определена с ясными обязанностями, но работа в аутсорсинговой компании может указывать на возможные проблемы с нагрузкой и меньшую стабильность.
Кликните для подробной информации
Аутсорсинговая компанияЯсные обязанностиЗарплата не указана
Responsibilities: • Lead and coordinate Security Audits across the software development lifecycle: from Architecture, Process, Risk to Testing.
• Establish secure software development lifecycle (SSDLC) programs.
• Support software development teams in secure development methodologies, tools, and processes.
• Train Software Development teams in the areas of secure development.
• Building Secure Architecture and Design for the projects.
• Communicate with customers and teams, be able to convey the message about importance of Secure Software development Life Cycle, the ways of establishing it.
• Cooperate with all sub-teams: BAs, Developers, Qas; build consistent understanding of Security Requirements, main Threats, Mitigations implemented.
• Be able to communicate and coordinate work with other Security Teams - Cloud Security Engineers, Infrastructure Security Engineers or Penetration Testers.
Requirements: • Software Development or Security-focused university degree OR equivalent experience.
• Motivation to develop and grow in the field of Security.
• Familiarity in one or more Security Development methodologies (e.g. Microsoft SDL, OWASP OpenSAMM, BSIMM, etc.).
• Familiarity with Threat Modeling, hands-on experience with one or more Threat Modeling Tools.
• Understanding of main Security-related activities in development such as Security Requirements gathering, Risk Assessment, Security Code Review.
• Familiarity with of security threat, their implementation and their classification.
• Understanding of main security concepts and principles.
• Understanding of main areas of protection and levels of defense.
⚡
Показать контакты
#Офис #AppSec
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Текст вакансии взят без изменений
Источник - Telegram канал. Название доступно после авторизации