3-5 years of experience in application security testing including DAST, SAST, and OSS testing., Bachelor’s Degree in a technical field or equivalent work experience., Relevant certifications such as EC-Council C|ASE or GIAC GWEB are preferred., Strong communication skills and a thorough understanding of the Software Development Life Cycle (SDLC)..
Key responsibilities:
Perform application security testing on various types of applications to identify vulnerabilities.
Collaborate with internal teams to define testing scope and methodology.
Create detailed reports on security issues and provide actionable recommendations.
Educate development teams on secure coding practices and communicate findings to stakeholders.
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
Clear Capital was founded with the core belief that making our customers successful opens the door to impact the mortgage industry for the benefit of all.
Since 2001, our willingness to adapt to changing industry needs, customer goals and evolving technology has allowed us to become a leader in property valuation management and data solutions, and we are not done yet. We provide technology platforms that speed up loan decisioning, analytics that give real time insight into the real estate market and valuation management solutions that provide professional expertise on the condition, quality and value of residential and commercial properties. But the real difference you will experience is our unwavering desire to solve your hardest problems.
Over the years we have built a team of passionate people that are committed to our customers’ success. We hire the nicest, most talented staff in the industry who embrace modern techniques and never back away from a problem. We have also been fortunate to partner with a nationwide network of independent real estate professionals (appraisers, brokers and real estate agents) that know their local market and have the experience to prove it.
As an Application Security Engineer, you will perform application security testing on web applications, mobile applications, microservices, infrastructure code, and open source code in order to expose weaknesses in their design and/or configuration that make them susceptible to exploitation.
You will work closely with development teams, product managers, and other members of the information security team to assess risks, conduct security reviews, and recommend steps for the remediation of identified vulnerabilities. You will educate development engineers on secure coding practices and contribute to overall application security awareness.
What You Will Work On
Collaborate with internal teams to define the scope of application security testing activities, including the number and types of applications to be tested, and the testing methodology.
Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in application code and weaknesses in secure coding practices.
Use test results to create reports that detail discovered security issues, assess risk levels, and provide actionable recommendations.
Assess discovered vulnerabilities and recommend solutions to reduce risk and mitigate security impacts to the application environment.
Communicate findings, risks, conclusions, and recommendations to stakeholders.
Consider the impact your testing will have on the business and its users.
Clearly articulate and convey the potential business or operational impact of unaddressed security vulnerabilities.
Who We Are Looking For
3-5 years of proven experience in application security testing, including Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), Open Source Security (OSS) testing, Software Composition Analysis (SCA)
Bachelor’s Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience
Experience testing web applications for OWASP Top Ten security vulnerabilities
A thorough understanding of the Software Development Life Cycle (SDLC)
Experience in promoting and implementing secure coding practices, and providing training and education to development teams on secure development practices
Strong verbal and written communication skills with the ability to clearly articulate technical concepts to both technical and non-technical audiences
Attention to detail, to plan and execute tests that meet all requirements
Ability to prioritize tasks and manage time effectively to meet deadlines
Ethical integrity to be trusted with a high level of confidential information
Ability to collaborate with team members and share knowledge
Exceptional analytical and problem-solving skills and the persistence to apply different techniques to get the job done
Ability to understand the business implications of identified weaknesses
Commitment to continuously update your technical knowledge base
What You Can Expect
Competitive compensation and immediate contribution!
Inclusive benefits package offerings 401k plans and customizable benefits including dental, vision, medical, etc. for you and your dependents.
An innovative culture that understands the importance of quality of work over quantity.
Company-supported and employee-driven ambassador groups that promote diversity, working on a hybrid schedule and philanthropy.
Learning and development programs to help advance your career and personal growth.
What We Value
Wherever it leads, Whatever it takes! We believe in making the impossible possible!
Thrive personally, grow professionally―be happy!
Innovate, learn, lead- Knowledge and growth is never ending!
We believe in hiring nice people because anything is possible when you have the team's support.
Improving the lives around us- A smile could change the entire world.
Be the most trusted, respected, and loved real estate valuation company in the world.
About Us
Clear Capital is a national real estate valuation technology company with a simple purpose: build confidence in real estate decisions to strengthen communities and improve lives. Our goal is to provide customers with a complete understanding of every U.S. property through our field valuation services and analytics tools, and improve their workflows with our platform technologies. Our commitment to excellence — wherever it leads, whatever it takes® — is embodied by team members.
Clear Capital is an equal opportunity employer.
To all recruitment agencies: Clear Capital does not accept agency resumes. Please do not forward resumes to our jobs alias, Clear Capital employees, or any other company location. Clear Capital is not responsible for any fees related to unsolicited resumes.
Required profile
Experience
Industry :
Financial Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.