Responsibilities
- Direct full-time information security, static code review, remediation, testing, software development, or software engineering.
- Knowledge of secure development of web applications and mobile applications.
- Hands on experience leading technical integration-heavy in modern security tools, especially; Checkmarx SAST, CheckmarxOne, NexusIQ, and/or Blackduck, Veracode, Snyk.
- Experienced in conducting end-to-end static analysis, using at least one commercial, application scanning tool.
- Experienced in application onboarding, triaging, remediation with application teams and verifying proposed findings.
- Hands-on development experience, working with, or developing RESTful APIs in a modern, automated development environment – including a deep understanding of CI/CD.
- Organize, maintain, and report on project workflows, statuses, and technical tasks.
- Identify, facilitate, and track on-going process and automation-based process improvements.
- Ability to quickly adapt to new technologies, tools and techniques.
- Ability to perform in a fast paced, dynamic work environment and meet aggressive deadlines.
- Ability to work with technical and non-technical team members.
- Strong technical writing and verbal communication skills.
Experience Qualifications
- 5+ years of experience SAST and SCA security tools; Checkmarx and CheckmarxOne, and Nexus IQ.
- 5+ years of experience developing new queries and customizing the existing security tools queries that are not out of the box to find new vulnerabilities.
- 5+ years of experience conducting end-to-end SAST and SCA analysis, using commercial application scanning tool.
- 5+ years of experience application onboarding, triaging, remediation with application teams and verifying proposed findings.
- 3+ years of recent, hands‑on development experience, working with, or developing RESTful APIs in a modern, automated development environment – including a deep understanding of CI/CD.
- 3+ years, with expert-level skills, in SDLC workflow management tools like Jira, Confluence, SharePoint or similar.
Cloud Hybrid is an equal opportunity employer inclusive of female, minority, disability and veterans, (M/F/D/V). Hiring, promotion, transfer, compensation, benefits, discipline, termination and all other employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, age, disability, national origin, citizenship/immigration status, veteran status or any other protected status. Cloud Hybrid will not make any posting or employment decision that does not comply with applicable laws relating to labor and employment, equal opportunity, employment eligibility requirements or related matters. Nor will Cloud Hybrid require in a posting or otherwise U.S. citizenship or lawful permanent residency in the U.S. as a condition of employment except as necessary to comply with law, regulation, executive order, or federal, state, or local government contract.
#J-18808-Ljbffr