BlogPublicar vacante
Crea un CV

Buscar empleo

Limpiar filtros

Bolsa de trabajo director ecommerce tiempo completo Híbrido - OCC

2 resultados

Ordenar por: Relevancia

Relevancia

Fecha

Analista de Seguridad de Aplicaciones

Sueldo no mostrado por la empresa

Role description The Application Security Analyst is responsible for assisting Application Security Director in advising IT and business stakeholders on application security and controls, conduct t ...

Empresa confidencial
CDMX

Arquitecto de Datos - MTY

$45,000 - $50,000 Mensual

GETECSA Somos una empresa mexicana líder de gestión de capital humano y servicios tecnológicos que nació en 2005 en la ciudad de Monterrey, Nuevo León. Tenemos presencia en el mercado nacional e int ...

Getecsa
Monterrey, N.L.
  • 1

Hace 1 mes

Analista de Seguridad de Aplicaciones

Si el reclutador te contacta podrás conocer el sueldo

Empresa confidencial en
Empresa verificada

Sobre el empleo

Categoría: Tecnologías de la Información - Sistemas
Subcategoría: Desarrollo de software - Programador
Educación mínima requerida: Universitario titulado

Detalles

Contratación:

Permanente

Horario:

Tiempo completo

Espacio de trabajo:

Híbrido

Descripción

Role description

The Application Security Analyst is responsible for assisting Application Security Director in advising IT and business stakeholders on application security and controls, conduct testing and provide solutions for secure application development. The ideal candidate for this position can prove competency in secure application development strategies or application penetration testing with a deep understanding of methods and techniques to break and fix applications, and must have hands-on experience in at least two of these areas:


  • Scaling security within the SDLC by automation using tools sets such as source code analyzers, vulnerability scanners, configuration validation, and similar techniques.
  • Performing security testing and providing remediation guidance for application vulnerabilities.
  • Developing application security measures and controls that support risk assessments and the development of secure application platform.
  • Developing, testing and implementing advanced enterprise level application security standards, techniques and tools.
  • Using application vulnerability assessment tools for static and dynamic code analysis.
  • Conducting application security assessments and tests on web applications, cloud platforms, web services, and mobile applications.
  • Identifying and protecting against web application and web service security vulnerabilities including those found in the OWASP Top 10 and CWE/SANS Top 25 dangerous programming errors.
  • Application Penetration Testing

Utility development and scripting experience is a major plus.


Role Responsibilities

The key responsibilities of the role are as follows:


  • Performs security testing and code review to improve software security.
  • Investigates, identifies, validates, and drives remediation of security vulnerabilities, configuration issues, and flaws in application code.
  • Performs focused risks assessments of existing or new applications, software and technologies to ensure the protection of the organization's information assets and our customer information.
  • Works closely with application development teams and vendors to provide security expertise on encryption, data masking, authentication, security specific code, and governance.
  • Develops and deploys application security and risk management framework/tools.
  • Communicates risk assessment findings to stakeholders.
  • Identifies and implements appropriate application security controls to effectively eliminate and/or reduce application risks as needed.
  • Educate developers on secure development and coding best practices.
  • Partner with multiple teams across multiple locations with varying sets of priorities to ensure a timely delivery of the secure application solution.
  • Deliver with accountability on assigned tasks and project commitments.

Candidate Evaluation Criteria

Candidates will be evaluated based on their ability to demonstrate a proven track record of proficiency at the following competencies:


  • Must prove understanding of application design and common security vulnerabilities
  • A commitment to the crucial concept of promoting security as an enabler and not an inhibitor of business.
  • Contribute to building enterprise application management, governance, and compliance programs.
  • Strong organization, prioritization, rationalization, and analytics skills
  • An ability to cultivate and build collaborative working relationships with a broad range of enterprise stakeholders.
  • A well-developed understanding of and appreciation for business needs and a commitment to leading the information risk management team in delivering high-quality, prompt, and efficient service to the business.
  • A well-developed understanding of and appreciation for organizational mission, values, and goals and consistent application of this knowledge.
  • An ability to communicate complex and technical issues to diverse audiences.
  • Deep and thorough knowledge of advanced enterprise level application security standards, techniques, and tools.
  • Ability to assess code security vulnerabilities, implement security measure and mitigating controls.


Education and Experience

  • BS or higher degree in Computer science, Information Security, or equivalent experience
  • English level advanced (B2/C1)
  • 2+ years of professional experience in IT security engineering, software engineering, or computer science-based field.
  • 2+ years of hands-on development experience on the technologies and standards, such as: HTML, C++, C#, JavaScript, JQuery, Python, PHP, SQL, JSON, XML,
  • Understanding of SSL/TLS, REST, SAML, OAuth,
  • Experience using Confluence, Burp Suite, SAST/SCA tools and cloud-based code sharing platforms (i.e. GitHub, ServiceNow, etc.)
  • Experience with validation and testing of Vulnerabilities found during a penetration test and/or Bug bounty
  • Working knowledge of eCommerce platforms such as SalesForce Commerce Cloud a plus.
  • Experience with Agile/SCRUM and Classical (Waterfall) software development models, and thorough knowledge/understanding of enterprise SDLC process.
  • Knowledge of web related technologies (web applications, web services, and service- oriented architectures) and of network/web related protocols.
Recuerda que ningún reclutador puede pedirte dinero a cambio de una entrevista o un puesto. Asimismo, evita realizar pagos o compartir información financiera con las empresas.

ID: 20532367

Refina la ubicación de tu búsqueda

México

Ciudad de México, México

Nuevo León, México

VER MÁS

Refina la ubicación de tu búsqueda

México

Nuevo León, México

Ciudad de México, México

Monterrey, Nuevo León, México

Candidatos
Crea un CV
Inicia sesión
Preguntas frecuentes candidatos
ios
android
Empleos por clasificación
Vacantes por Estado
Vacantes por Ciudad
Vacantes por Categoría
Vacantes más buscadas
Vacantes por Contrato
Vacantes por Empresa
Buscar empleo en México y el mundo
Empresas
Busco talento / Publicar Anuncio
Ayuda para reclutadores
Preguntas frecuentes de reclutadores
OCC
Acerca de OCC
Blog
Trabaja en OCC
Ayuda

OCC D.R. © 1996-2025 Derechos reservados. Versión del sitio candy-serp@