Application Security Engineer
Category: Software Development/ Engineering
Main location: United States, ALL
Alternate Location(s): United States, Maryland, Baltimore
United States, Louisiana, Lafayette
United States, Texas, Belton
United States, Tennessee, Knoxville
Position ID:J0523-2221
Employment Type: Full Time
Position Description:
CGI Federal’s Healthcare and Social Services Practice is seeking a highly motivated Application Security Engineer to join their Cyber Security team. The candidate will join a multi-disciplinary team of security specialists, engineers, project managers and delivery professionals responsible for supporting a CMS Healthcare Marketplace system and potentially other CMS and non-CMS contracts.
**Strong preference for hybrid (2 days/week onsite) near any CGI Federal Office**
Candidates not within 50 miles of an office can still be considered for this role; Must reside in the United States.
Your future duties and responsibilities:
• Application security testing techniques using automated tools and manual testing
• Creation of exploit proofs of concept
• Discovery of application security weaknesses, and written recommendations for remediation and/or prevention
• Analysis and response of discovered vulnerability and consultation regarding inquiries from vulnerability reports
• Research new threats and demonstrate the exploitation of attack vectors in controlled environments as they relate to web applications and infrastructure
• Assess new and existing applications and system deployments for vulnerabilities and design flaws, and prioritize remediation efforts based on risk level
• Demonstrate subject matter expertise with tools such as BurpSuite, Snyk, OWASP ZAP, Fortify, Checkmarx, Nessus, and Kubernetes
• Demonstrate the ability to adjust to working in a fast pace environment using multitask skills and independently switching between priorities
• Demonstrate the ability to learn new technologies, security trends and help build new capabilities and services
• Support and consult with product and development teams on matters related to application security
• Serve as subject matter expert for secure coding practices, penetration testing, mobile platform security and all aspects of application and product security
• Collaborate with team members on a daily basis, while being part and contributing to the same project.
• Follow team’s established processes and procedures, adhere to due dates and deliverable
• Support DevSecOps activities, which include but not limited to:
• Consultation pertaining to the implementation/enhancement of SAFe DevOps strategies (certification will be given preference)
• Research and benchmarking of technologies used in CI/CD pipeline
• Automation of security processes using DevSecOps tools in the CI/CD pipeline
• Integration of new technologies
• Documentation of processes and procedures
Required qualifications to be successful in this role:
• Web Application development and security assessment experience will be required to perform the role well
• Knowledge of secure development principles for both Microsoft.NET and API development solutions
• Experience with OWASP static/dynamic application security analysis and common security tools
• Minimum 6 years of experience in system development in technologies like JavaScript, Angular, Python, .Net, Node.js, Amazon Web Services, etc.
• Strong knowledge of security-related best programming practices for Microsoft .NET, Angular 13 and Node.js
• Experience in DevSecOps tools such as Jenkins, SonarQube, Ansible, Terraform, Github, Synk, Docker and Cloud computing.
• Experience designing and executing web application security evaluations, solo and as part of a team
• Knowledge of the SDLC and experience working with software development teams (waterfall, Agile, etc.)
• Ability to document and explain risks and vulnerabilities to technical and non-technical stakeholders
• Knowledge of Micro services and Container based technology such as Kubernetes, Docker, etc.
• Excellent and professional communication skills (written and verbal) with ability to articulate complex topics in clear and concise matter
CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to: skill set level; experience and training; and licensure and certifications. CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $84,000 – $146,900
#CGIFederalJob
#HSS
#DICE
#LI-RJ1
Skills:
- Security Assessment
- .NET
- Database
- Jenkins
What you can expect from us:
Insights you can act on
While technology is at the heart of our clients’ digital transformation, we understand that people are at the heart of business success.
When you join CGI, you become a trusted advisor, collaborating with colleagues and clients to bring forward actionable insights that deliver meaningful and sustainable outcomes. We call our employees “members” because they are CGI shareholders and owners and owners who enjoy working and growing together to build a company we are proud of. This has been our Dream since 1976, and it has brought us to where we are today – one of the world’s largest independent providers of IT and business consulting services.
At CGI, we recognize the richness that diversity brings. We strive to create a work culture where all belong and collaborate with clients in building more inclusive communities. As an equal-opportunity employer, we want to empower all our members to succeed and grow. If you require an accommodation at any point during the recruitment process, please let us know. We will be happy to assist.
Ready to become part of our success story? Join CGI – where your ideas and actions make a difference.
Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, pregnancy, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status, political affiliation, genetic information, or any other legally protected status or characteristics.
CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at US_Employment_Compliance@cgi.com. You will need to reference the requisition number of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a requisition number will not be returned.
We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members.
All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.
CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI’s legal duty to furnish information.