Health Dialog Corporate Information Security Office (CISO) is seeking a highly motivated and experienced application security engineer to ensure security is built into our technology products. This position will act as the CISO liaison to the Application Development Team and PMO.Â This individual will provide critical security engineering services that include definition of security requirements and designs.Â He or she will perform vulnerability assessments, coordinate penetration testing, and other security testing with the CISO and IT Operations.Â The candidate will be expected to be a thought leader on how security should be viewed by developers and SQA personnel.Â A critical part of this job will include definition of approaches for code risk assessments and reviews from a security standpoint.Â After joining Health Dialog, this person will be expected to lead security code and design reviews, develop standards for security coding standards, and work with PMO on methods for inserting security into the SDLC.
Specific job duties include:
â€¢Â Attend Application Development design reviews.Â Actively lead discussions from a security standpoint.Â Provide written input for security based requirements.
â€¢Â Coordinate penetration tests and perform vulnerability assessment/threat modeling in order to test our technology applications.
â€¢Â Drive remediation and change as opportunities are uncovered.
â€¢Â Report and coordinate progress and plans to the Development Team, PMO and CISO management.
â€¢Â Develop and foster productive and collaborative relationships with software testers, engineers and operations staff
â€¢Â Communicate to cross functional teams the importance of application security.Â Help software engineers implement best practices in code development as it relates to security
â€¢Â Coordinate and oversee 3rd party risk assessments for code reviews and threat modeling
â€¢Â Define and develop application security design standards.Â Enforce these standards
â€¢Â Be a security advocate and evangelist.
â€¢Â 10 years experience as a software engineer with a mindset for security
â€¢Â Excellent verbal and written communication skills
â€¢Â Able to work with all levels of staff including senior management
â€¢Â Excellent problem solving, analytical skills and technical troubleshooting skills
â€¢Â Thorough understanding of penetration testing techniques and web applications
â€¢Â Proficient in Operating Infrastructure (Examples: Microsoft Windows 2000/2003, Red Hat Linux, Microsoft Internet Information Server, Apache web server)
â€¢Â Basic administrative knowledge of one or more major database, including Oracle, MS SQL Server
â€¢Â Basic networking skills, including OSI stack, routers, switches, and security devices.
â€¢Â Basic programming skills in C# .NET
â€¢Â Ability to work within cross-functional teams under strategic direction.
â€¢Â BSCS degree or equivalent.Â Applicable certifications a plus
|Location:||Bedford, NH |