Software Guidance & Assistance, Inc., (SGA), is searching for a Remote Cybersecurity Engineer (API / Web App Security) for a CONTRACT assignment with one of our premier Healthcare Services clients for a Remote position.
Top Skills Needed : Azure / Entra ID
Scripting (Powershell or Python)
API Security frameworks
OWASP top
Responsibilities :
We are seeking an experienced Cyber Security Engineer to join our team, responsible for ensuring the security of our applications and APIs. This role will focus on collaborating with cross functional teams, including developers, UI developers, and API developers, to identify and remediate security vulnerabilities. The ideal candidate will have expertise in API security, UI security, as well as secure coding practices, with the ability to balance security with business needs and enable rapid and secure deployment of applications.
- Collaborate with developers throughout the software development lifecycle to ensure security best practices are integrated into application design and development
- Review scan findings and work with developers to remediate security vulnerabilities and implement fixes within their applications
- Work with application owners to enable single sign on via standards such as SAML or OAuth
- Work with application owners to manage access control via conditional access policies
- Partner with developers to ensure secure coding practices and mitigate security risks
- Provide security guidance and recommendations to development teams to ensure compliance with security standards and regulations
- Develop and maintain security documentation, including threat models, risk assessments, and security requirements
- Stay current with emerging security threats and technologies, applying this knowledge to improve our overall security posture
- Enable the business to rapidly and securely deploy applications balancing security with business needs
Required Skills :
Related Bachelor's degree or additional related equivalent work experienceyears related work experienceyears in Cybersecurityyears Information Technology Infrastructureyears of experience in cyber security, with a focus on secure development and deploymentCybersecurity Engineer Defense and Threat Operations : SSCPCybersecurity Engineer Enterprise Cybersecurity Services : SSCPStrong understanding of secure coding practices, threat modeling, and risk assessmentExperience with Azure / EntraIDExperience with Single Sign On using SAML or OAuthExperience with security tools such as Postman, Burp Suite, etc. and vulnerability managementExperience with scripting languages such as PowerShell or PythonExcellent communication and collaboration skills, with the ability to work with technical and non-technical stakeholdersStrong problem-solving skills, with the ability to analyze complex security issues and develop effective solutionsFamiliarity with API security frameworks and protocols (OAuth, JWT), as well as UI development frameworks and toolsExperience with the OWASP Top and remediation strategiesExperience with the creation of both technical and non-technical documentationPreferred Skills :
Experience with agile development methodologiesExperience with CI / CD pipelines and tools such as Jenkins