Search

Application Security Analyst $58/hr

PublishedPublished: 6/14/2022
Real Estate

Job Description

Job Description

Application Security Analyst


Location: Phoenix, AZ

Contract-To-Hire

Hybrid Work Schedule

Pay: $58/hr W2


Job Summary

Seeking an Application Security Analyst who would support Client's Security Program with a primary focus of integrating AppSec tools into CI/CD pipelines, managing application security vulnerabilities and partnering with development teams to prioritize security in their practices. This role plays a key part in maturing our DevSecOps culture, reducing Client's overall attack surface and strengthening the Client's Information Security Program.


Essential Duties & Responsibilities

• Support and monitor the enterprise information security system as directed by management.

• Manage daily operations and support for Application Security products, including incident and ticket resolution.

• Provide expertise during incidents, document findings and help improve protocols.

• Maintain and upgrade application security related platforms.

• Tune application security related policies and rulesets.

• Collaborate with business and IT partners to integrate security tools (SAST, DAST, etc.) and platforms into CI/CD pipelines and workloads.

• Contribute to and perform security reviews of Terraform configurations and reusable modules supporting Client’s Infrastructure as Code (IaC).

• Validate Terraform changes for security, compliance and alignment with established cloud architecture standards.

• Monitor code platforms and resources for security threats, investigate and respond to security incidents and findings.

• Write SIEM queries and perform analysis of results.

• Respond to security tool findings and collaborate with business and IT partners for remediation.

• Implement, configure, manage and support Web Application Firewalls (WAFs), including the tuning of rulesets and policies.

• Contribute to various application security related projects and initiatives.

• Perform special projects as needed.

Qualifications

• 3+ years of hands-on experience in an Application Security, Product Security, DevOps or DevSecOps role.

• Experience working in cloud platforms (Azure, AWS, GCP, OCI).

• Experience with CI/CD and developer workflow automation such as GitHub Actions, Azure DevOps Pipelines.

• Experience developing or reviewing Terraform used to deploy Azure infrastructure, including reusable modules.

• Experience managing and tuning Web Application Firewall (WAF) policies, specifically for Azure Front Door.

• Experience triaging and remediating vulnerabilities identified by GitHub Advanced Security (GHAS) or Microsoft Defender for Cloud platforms, including CodeQL, Secret Scanning and Dependency Review.

• Demonstrated proficiency in using PowerShell for administration and automation purposes.

• Proven ability to communicate effectively and interact professionally at all organization levels.

• Strong project management capabilities.

• Ability to consistently deliver an exceptional standard of customer service.

\nCompany Description

GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.

Company Description

GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...