NEWPosted 20 hours ago

Job ID: 3181812

Job Summary:

We are seeking a highly experienced and dedicated Application Security Specialist to join our dynamic team. This critical role focuses on enhancing the security posture of our web applications through the strategic implementation and optimization of Invicti for automated vulnerability scanning and continuous security testing. The ideal candidate will possess profound expertise in application security, comprehensive vulnerability management, and a deep understanding of secure Software Development Life Cycle (SDLC) practices. Hands-on experience in configuring, operating, and optimizing Invicti within robust CI/CD pipelines is essential. This is an onsite contract position with flexibility across multiple key locations: Iselin, NJ; Dallas, TX; and Charlotte, NC, offering a unique opportunity to contribute to a cutting-edge security environment.

Key Responsibilities:

  • Lead the onboarding of various applications onto the Invicti Enterprise Platform, ensuring consistent and comprehensive security scanning as an integral part of the CI/CD pipeline.
  • Expertly configure Invicti scans, including the development and utilization of pre-request scripts to tailor scanning processes to specific application needs.
  • Proactively troubleshoot and resolve any issues related to scan failures, authentication challenges, and coverage gaps, ensuring the continuous operation of security scans.
  • Diligently analyze, validate, and triage vulnerabilities identified by Invicti, accurately dispositioning defects as false positives when appropriate.
  • Collaborate closely with development teams to clearly explain security findings, provide actionable insights, and recommend effective remediation steps to address identified vulnerabilities.
  • Stay abreast of the latest emerging web application vulnerabilities, security threats, and industry trends to continuously enhance our security strategies and practices.
  • Contribute to the development and refinement of secure coding guidelines and best practices across the organization.
  • Participate in security reviews and architectural discussions to embed security early in the development process.
  • Generate detailed reports on scan results, vulnerability trends, and remediation progress for various stakeholders.

Required Skills & Qualifications:

  • Strong foundational understanding of web technologies, including HTTP protocols, headers, cookies, and various authentication mechanisms.
  • Proven experience in writing scripts, particularly with JavaScript, for automation and customization purposes.
  • Extensive hands-on expertise with Invicti (formerly Netsparker), including its configuration, operation, and integration into development workflows.
  • Solid understanding of industry-recognized security standards such as OWASP Top 10, CWE, and common web vulnerabilities.
  • Demonstrated experience with various authentication mechanisms, including OAuth, SAML, JWT, and cookie-based authentication.
  • Exceptional ability to meticulously analyze scan results, accurately distinguish between real vulnerabilities and false positives, and prioritize remediation efforts.
  • Strong communication skills, both written and verbal, enabling effective collaboration with developers, project managers, and other stakeholders.
  • Ability to work independently and as part of a team in a fast-paced, dynamic environment.

Preferred Qualifications:

  • Experience with other leading security tools such as Burp Suite, OWASP ZAP, Snyk, Checkmarx, or Fortify.
  • Additional scripting or programming knowledge in languages like Python, Java, or similar.
  • Practical experience with major cloud platforms, including AWS, Azure, or GCP.
  • Possession of relevant security certifications (e.g., CEH, GWAPT, OSCP, CSSLP).
  • Knowledge of compliance frameworks such as ISO 27001, SOC 2, or PCI DSS.
  • Experience with security automation and orchestration.

Work Environment & Career Growth:

This role offers an exciting opportunity to be at the forefront of application security, working with cutting-edge tools and contributing to the robust security posture of critical web applications. You will be part of a forward-thinking team that values innovation and continuous improvement. Alltech is committed to fostering a supportive environment where professionals can thrive and grow their expertise. While this is a contract position, it provides significant exposure to diverse projects and technologies. The onsite nature of the role in Iselin, NJ, Dallas, TX, or Charlotte, NC, encourages direct collaboration and knowledge sharing within the team. We are looking for proactive individuals eager to make a tangible impact on our security landscape.


Special Requirements

Onsite role with locations in Iselin, NJ, Dallas, TX, and Charlotte, NC. Candidates should be prepared for onsite work.


Compensation & Location

Salary: $145,600 – $228,800 per year (Estimated)

Location: Iselin, NJ


Recruiter / Company – Contact Information

Recruiter / Employer: alltech

Email: knikhil@alltechconsultinginc.com


Interested in this position?
Apply via Email

Recruiter Notice:
To remove this job posting, please send an email from
knikhil@alltechconsultinginc.com with the subject:

DELETE_3181812

to delete@join-this.com.