Application Security Developer
Updated on 5/11/2023
Locations
New York, NY, USA
Experience Level
Entry
Junior
Mid
Senior
Expert
Desired Skills
Agile
AWS
Docker
Google Cloud Platform
JavaScript
Git
Linux/Unix
Microsoft Azure
Rust
Terraform
Kubernetes
Python
TCP/IP
Requirements
- A highly motivated, self-starting individual with keen interest in enabling security development practices
- 3+ years of experience in a similar role, including previous experience implementing and/or managing SDLC security tools (e.g., SCA, SAST, DAST, etc.)
- Familiarity and ability to explain common security flaws and ways to address them (e.g. OWASP Top 10)
- Development or scripting experience and skills. Familiarity with Python, JavaScript and/or Rust is preferred
- A basic understanding of network and web related protocols (eg: TCP/IP, UDP, HTTP, HTTPS)
- Intermediate to advanced knowledge of: Linux, Git, Docker and CI/CD pipelines
- Excellent communication skills (written and verbal) and the ability to translate both technical and business needs into security requirements
- Bachelor's degree or equivalent work experience in computer science or a related technical field
Responsibilities
- Embed with agile development teams to design, implement, and automate security guardrails across all phases of the software development lifecycle (SDLC)
- Assist teams in triaging, analyzing and prioritizing remediation of application security vulnerabilities
- Manage security technologies, including but not limited to application security testing (SAST), dynamic application security testing (DAST), container security and software composition analysis (SCA) tools, to integrate security guardrails into the continuous integration/continuous development (CI/CD) pipeline
- Perform security focused code and architecture reviews
- Assist in development of security processes and automation that prevent classes of security issues
Desired Qualifications
- Knowledge of cloud (AWS, GCP, Azure) and Kubernetes security best practices
- Proficiency in Terraform, Pulumi or any Infrastructure as Code platform
- Experience performing application security penetration tests, participating in bug bounty programs or red team operations
- Accredited IT (including cloud) and/or information security certifications
Agriculture & climate insight platform
Company Overview
Gro's mission is to illuminate the interrelationships between the Earth’s ecology and our human economy, the company allows users to see the big picture and act on the small details. From assessing the impact of climate change in real time to optimizing agricultural supply chains, Gro’s data, analytics, and forecast models provide the honest answers to what on earth is going on.
Benefits
- Equity
- Generous PTO policy
- Health, vision, & dental insurance
Company Core Values
- Teach
- Ask
- Listen
- Always learn