We are seeking a highly experienced Security Operations Engineer with a strong background in application security, secure coding, and software engineering. The ideal candidate will have deep knowledge of secure development practices, proficiency in contemporary programming languages, and experience with secure code review and analysis tools. This role is essential in safeguarding applications against security threats by embedding security across the software development lifecycle.
Key Responsibilities:
Conduct in-depth secure code reviews and provide actionable recommendations to development teams.
Collaborate with software engineers to promote and implement secure development practices across the SDLC.
Identify and remediate vulnerabilities related to common attack vectors such as XSS, CSRF, SQL injection, and others.
Use and manage static and energetic analysis tools (e.g., SonarQube, Semgrep, Fortify) to detect security issues in codebases.
Work closely with DevOps and engineering teams to integrate security into CI/CD pipelines.
Participate in threat modeling exercises and proactively assess application architecture from a security standpoint.
Stay current with the latest security trends, vulnerabilities, and compliance requirements.
Required Skills & Qualifications:
Minimum 7 years of experience in application security, secure coding, or software engineering roles.
Solid understanding of secure development principles and common OWASP vulnerabilities.
Proficiency in at least one of the following programming languages: Java, JavaScript, Node.js, or Kotlin.
Experience performing code-level debugging and vulnerability remediation.
Hands-on experience with static code analysis and secure code review tools such as:
SonarQube
Semgrep
Fortify or similar
Preferred Qualifications:
Familiarity with DevSecOps and integrating security practices in Agile and CI/CD environments.
Relevant certifications such as OSCP, CISSP, CEH, or CSSLP.
Understanding of secure design patterns and secure architecture principles.