Information Security Specialist, Security Engineer
Sacramento, CA
Duration: Long term
Mandatory Qualifications
Ten (10) years or more of Security Engineer experience performing the following tasks:
Leading data classification and categorization effort and documenting the results in accordance with Data Classification and Categorization Standards;
Working with customers to identify and document business impacts and system security classification and data categorization ratings;
Performing SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) common tools and provide results and remediation execution approach to management, developers, business analyst, and tester;
Implementing ZeroTrust/Continuous authentication architectures;
Classifying issues identified via SAST and DAST tools based on risk and criticality;
a. Non-standard or low-security authentication methods for users, systems, and infrastructure
b. Reused or common credentials
c. User credentials in code
d. Unencrypted end-user passwords and Personal Identifiable Information (PII)
e. Missing security controls based on the data classification and categorization
Collaborating with Software Developers to identify and document approaches to remediate security issues, including plans to validate security fixes and improvements;
Collaborate with developers implementing an IAM (Identity and Access Management) solution.
Desirable Qualifications
Possession of a *Master’s Degree from an accredited university or equivalent in the fields of Computer Science, Information Technology, or Cybersecurity
Certified Information Systems Security Professional (CISSP) License;
Ten (10) years or more of Security Engineer experience using Mend and Invicti or similar tools
Minimum of five (5) years of experience supporting security practices in a cloud environment (AWS, Azure, etc).
Kiran Kumar
Key Business Solutions, Inc.
|| Office: 916 222 3188|| Fax: 916 646 2081