DHHS- PSO IT Security Specialist - JuniorWe are looking for an Information Technology (IT) professional with a strong background in application security testing, utilizing tools such as BURP Suite, Fortify, and manual testing.NC DHHS - Privacy and Security Office (PSO) requiring services of an IT Security Specialist to perform application security testing, ethical hacking, and vulnerability management of MES applications.• Implement the security framework within the DevSecOps environment, leveraging security testing tools like BURP Suite, Fortify, and manual testing.• Work with a variety of application development frameworks, including.NET, Java, Spring Boot, and others.• Identify and assess OWASP top 10 vulnerabilities and provide guidance to the application development team for remediation.• Utilize vulnerability management tools, such as Qualys, to identify and promptly address vulnerabilities while collaborating with stakeholders.• Showcase expertise in operating systems such as Linux and Windows, as well as proficiency in Command-line interfaces.• Possess excellent troubleshooting skills and a strong aptitude for technical learning.• Conduct HIPAA Privacy & Security Risk Assessments to ensure compliance and data security.Risk Management - must be able to identify gaps through risk management, and assist in the development of mitigation strategies.Required: 2 years experience updating privacy and security policies based on gaps found through an assessment process.Required: 2 years discover, evaluate, assess, systems, networks, and components through the use of vulnerability scanning and risk assessment method.Required: 2 years experience documenting vulnerability assessment results in an accurate, clear, actionable, and available way to appropriate personnel.Required: 2 years experience in using application security tools such as BURP suite, Fortfy etc.Required: 2 years must be able to serve as a knowledge base for organizations as it relates to compliance requirements and mitigation strategies.Required: 2 years experience in conducting manual security testing.Required: 3 years experience with network mapping and vulnerability scanning tools such as NESSUS and NMAP.Required: 2 years experience with application development frameworks such as.net, java etc.