Description :
Business Initiative / Purpose : (Goal, Business Impact, Accomplishments from the work)
- Intake management, onboarding support, coordination and consulting with development teams, maintaining scanning schedules and monitoring scan failures.
Bachelor Degree : (Required, Preferred or Not Required)
Preferred.Role Responsibilities : (what they will be doing)
DAST(), API(), Container()Manage new API security intake requests, ensuring proper documentation and risk assessment.Coordinate with development teams to gather additional technical details for security testing.Track and ensure timely responses between security and development teams for remediation and clarifications.Maintain and optimize application security scanning schedules for APIs, containers, and applications.Perform and validate DAST (Dynamic Application Security Testing) scans, analyze results, and drive remediation.Perform and validate Container scans, analyze results, and drive remediation.Oversee container security assessments, ensuring compliance with organizational standards.Document findings, create actionable reports, and communicate risks effectively to technical and non-technical stakeholders.Support knowledge transfer from outgoing consultants and ensure continuity of security processes..Must Have Skills / Prior Experiences : (Vendor should not submit any candidate that does not have these skills / prior experience.)
Hands-on experience with API security testing and vulnerability management.Strong knowledge of DAST tools (, Burp Suite, OWASP ZAP).Familiarity with container security (, Docker, Kubernetes, image scanning tools like Anchore or Trivy).Proven ability to manage security intake processes and coordinate across multiple development teams.Solid understanding of secure coding practices, OWASP Top , and application-specific and API-specific security risks.Excellent communication and stakeholder management skills for cross-team collaboration.Ability to work independently and hit the ground running in a fast-paced environment.Plus / Nice to Have Skills / Prior Experiences : (Hiring Manager DOES NOT require these skills / prior experience. However candidates with any of these will be looked at first.)
Experience with CI / CD pipeline integration for security tools.Knowledge of cloud-native security (AWS, Azure, GCP) and API gateways.Familiarity with threat modeling and risk assessment methodologies.Exposure to DevSecOps practices and automation of security testing.Certifications such as CISSP, GWAPT, or API Security Specialist.EEO