<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NFCU Job Opening: Application Security Engineer in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/NFCU-Job-Opening-Application-Security-Engineer/m-p/37581#M2690</link>
    <description>&lt;P&gt;Apply Today:&amp;nbsp;&lt;A href="https://nfcucareers.ttcportals.com/jobs/5403195-application-security-engineer" target="_blank" rel="noopener"&gt;Application Security Engineer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="fadeIn"&gt;&lt;DIV class="page-container-inner"&gt;&lt;DIV class="row"&gt;&lt;DIV class="small-12 column"&gt;&lt;DIV class="cs_block cs_template_content cs_template_content_job"&gt;&lt;DIV class="cs_container"&gt;&lt;DIV class="cs_content cs_cfix"&gt;&lt;DIV class="job-description"&gt;&lt;P&gt;&lt;STRONG&gt;Basic Purpose&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To drive embedding security seamlessly into the product development lifecycle, the Application Security Engineer will serve as a technical interface and subject matter expert working with ISD and Digital teams.&amp;nbsp; The engineer will collaborate with NFCU teams and vendors to determine security requirements and support all phases of product integration, operations, and maintenance to ensure a secure Navy Federal environment. He/She will be able to work independently or in a team environment.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Responsibilities&lt;/STRONG&gt;:&lt;BR /&gt;&lt;BR /&gt;•&amp;nbsp;Provide subject matter expertise on secure architecture, design and coding practices based on current knowledge of security threats and vulnerabilities that could impact the technology stack.&lt;BR /&gt;•&amp;nbsp;Support definition of Secure SDLC standard to include security architecture, design and coding requirements for infrastructure, application and data to align with application security maturity model and adopt a shift-left approach for security.&lt;BR /&gt;•&amp;nbsp;Evaluate various application security tools including SAST, DAST, SCA, IAST and Pen Testing and operationalize security tools for integration with CI/CD.&lt;BR /&gt;•&amp;nbsp;Perform application testing and review security test results from scans and penetration testing to identify viable vulnerabilities that may be exploited and propose remediation solutions or mitigation controls.&lt;BR /&gt;•&amp;nbsp;Develop security controls and processes for products and services developed and deployed for both on-prem and cloud environments.&lt;BR /&gt;•&amp;nbsp;Perform threat modeling, conduct security architecture reviews and provide training to architects and developers to enhance adoption of secure coding practice within the product development lifecycle.&lt;BR /&gt;•&amp;nbsp;Provide security related coaching and expertise to drive and elevate security expertise within the development teams.&lt;BR /&gt;•&amp;nbsp;Lead security innovation and best practices in product development through collaboration and learning from industry professionals and consortiums&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Qualifications and Education Requirements&lt;/STRONG&gt;:&lt;BR /&gt;&lt;BR /&gt;•&amp;nbsp;Bachelor’s Degree in Information Technology or the equivalent combination of education, training or experience&lt;BR /&gt;•&amp;nbsp;8 years or more experience in the field of cybersecurity and/or application security&lt;BR /&gt;•&amp;nbsp;Expert knowledge in security best practices, principles and common security frameworks such as OWASP, NIST and ISO&lt;BR /&gt;•&amp;nbsp;Experience building secure software based on frameworks such OWASP, BSIMM and SANS&lt;BR /&gt;•&amp;nbsp;Experience in software development including Java, Python, .Net and scripting languages&lt;BR /&gt;•&amp;nbsp;Knowledge of secure architecture and design patterns for Web, Mobile and Microservices&lt;BR /&gt;•&amp;nbsp;Knowledge of current and emerging threats and techniques for exploiting security vulnerabilities&lt;BR /&gt;•&amp;nbsp;Experience securing cloud infrastructure and applications&lt;BR /&gt;•&amp;nbsp;Experience with methodologies and security testing tools for threat analysis of complex applications and services including threat modeling, software fuzzing, static and dynamic analysis and penetration testing.&lt;BR /&gt;•&amp;nbsp;Advanced organizational, planning and time management skills&lt;BR /&gt;•&amp;nbsp;Advanced communication,&amp;nbsp; presentation&amp;nbsp; and analytical skills&lt;BR /&gt;•&amp;nbsp;Desired: Advanced degree in Information Technology, or the equivalent combination of education, training or experience&lt;BR /&gt;•&amp;nbsp;Desired: CISSP, CISM&amp;nbsp; or other related Information Security certifications&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Hours&lt;/STRONG&gt;: Monday - Friday, 8:00am - 4:30pm&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Location&lt;/STRONG&gt;: 820 Follin Lane, Vienna, VA 22180&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 24 Jul 2020 15:10:48 GMT</pubDate>
    <dc:creator>NavyFederal</dc:creator>
    <dc:date>2020-07-24T15:10:48Z</dc:date>
    <item>
      <title>NFCU Job Opening: Application Security Engineer</title>
      <link>https://community.isc2.org/t5/Career-Discussions/NFCU-Job-Opening-Application-Security-Engineer/m-p/37581#M2690</link>
      <description>&lt;P&gt;Apply Today:&amp;nbsp;&lt;A href="https://nfcucareers.ttcportals.com/jobs/5403195-application-security-engineer" target="_blank" rel="noopener"&gt;Application Security Engineer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="fadeIn"&gt;&lt;DIV class="page-container-inner"&gt;&lt;DIV class="row"&gt;&lt;DIV class="small-12 column"&gt;&lt;DIV class="cs_block cs_template_content cs_template_content_job"&gt;&lt;DIV class="cs_container"&gt;&lt;DIV class="cs_content cs_cfix"&gt;&lt;DIV class="job-description"&gt;&lt;P&gt;&lt;STRONG&gt;Basic Purpose&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To drive embedding security seamlessly into the product development lifecycle, the Application Security Engineer will serve as a technical interface and subject matter expert working with ISD and Digital teams.&amp;nbsp; The engineer will collaborate with NFCU teams and vendors to determine security requirements and support all phases of product integration, operations, and maintenance to ensure a secure Navy Federal environment. He/She will be able to work independently or in a team environment.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Responsibilities&lt;/STRONG&gt;:&lt;BR /&gt;&lt;BR /&gt;•&amp;nbsp;Provide subject matter expertise on secure architecture, design and coding practices based on current knowledge of security threats and vulnerabilities that could impact the technology stack.&lt;BR /&gt;•&amp;nbsp;Support definition of Secure SDLC standard to include security architecture, design and coding requirements for infrastructure, application and data to align with application security maturity model and adopt a shift-left approach for security.&lt;BR /&gt;•&amp;nbsp;Evaluate various application security tools including SAST, DAST, SCA, IAST and Pen Testing and operationalize security tools for integration with CI/CD.&lt;BR /&gt;•&amp;nbsp;Perform application testing and review security test results from scans and penetration testing to identify viable vulnerabilities that may be exploited and propose remediation solutions or mitigation controls.&lt;BR /&gt;•&amp;nbsp;Develop security controls and processes for products and services developed and deployed for both on-prem and cloud environments.&lt;BR /&gt;•&amp;nbsp;Perform threat modeling, conduct security architecture reviews and provide training to architects and developers to enhance adoption of secure coding practice within the product development lifecycle.&lt;BR /&gt;•&amp;nbsp;Provide security related coaching and expertise to drive and elevate security expertise within the development teams.&lt;BR /&gt;•&amp;nbsp;Lead security innovation and best practices in product development through collaboration and learning from industry professionals and consortiums&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Qualifications and Education Requirements&lt;/STRONG&gt;:&lt;BR /&gt;&lt;BR /&gt;•&amp;nbsp;Bachelor’s Degree in Information Technology or the equivalent combination of education, training or experience&lt;BR /&gt;•&amp;nbsp;8 years or more experience in the field of cybersecurity and/or application security&lt;BR /&gt;•&amp;nbsp;Expert knowledge in security best practices, principles and common security frameworks such as OWASP, NIST and ISO&lt;BR /&gt;•&amp;nbsp;Experience building secure software based on frameworks such OWASP, BSIMM and SANS&lt;BR /&gt;•&amp;nbsp;Experience in software development including Java, Python, .Net and scripting languages&lt;BR /&gt;•&amp;nbsp;Knowledge of secure architecture and design patterns for Web, Mobile and Microservices&lt;BR /&gt;•&amp;nbsp;Knowledge of current and emerging threats and techniques for exploiting security vulnerabilities&lt;BR /&gt;•&amp;nbsp;Experience securing cloud infrastructure and applications&lt;BR /&gt;•&amp;nbsp;Experience with methodologies and security testing tools for threat analysis of complex applications and services including threat modeling, software fuzzing, static and dynamic analysis and penetration testing.&lt;BR /&gt;•&amp;nbsp;Advanced organizational, planning and time management skills&lt;BR /&gt;•&amp;nbsp;Advanced communication,&amp;nbsp; presentation&amp;nbsp; and analytical skills&lt;BR /&gt;•&amp;nbsp;Desired: Advanced degree in Information Technology, or the equivalent combination of education, training or experience&lt;BR /&gt;•&amp;nbsp;Desired: CISSP, CISM&amp;nbsp; or other related Information Security certifications&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Hours&lt;/STRONG&gt;: Monday - Friday, 8:00am - 4:30pm&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Location&lt;/STRONG&gt;: 820 Follin Lane, Vienna, VA 22180&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 24 Jul 2020 15:10:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/NFCU-Job-Opening-Application-Security-Engineer/m-p/37581#M2690</guid>
      <dc:creator>NavyFederal</dc:creator>
      <dc:date>2020-07-24T15:10:48Z</dc:date>
    </item>
  </channel>
</rss>

