We need following candidate: Title: Offensive Security Specialist Duration: 12+ Months Remote Work Public trust clearance * Candidate MUST have either of ONE mentioned certification * Offensive Security Web Expert (OSWE) Offensive Security Certified Professional The Offensive Security Specialist plays a pivotal role in protecting mission-critical web applications, APIs and sensitive data. The objectives are to embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar.
The scope of work includes, but is not limited to, the following activities:
The Contractor shall provide a Offensive Security Specialist who meets the following specific requirements: Extensive hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. Proficiency in logs analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF) to defend against emerging threats. Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec) or secure software development life cycle (SSDLC) Strong understanding of Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities. Experience deploying, tuning, and maintaining Web Application Firewalls (WAFs) solutions tailored to custom-developed applications and traffic patterns. Strong track record in configuring and managing File Integrity Monitoring (FIM) solutions for web content directories, to detect and alert on unauthorized change. Familiar with security testing tools such as Wireshark, SIEM, IDS/IPS, NDR, or EDR Evaluates, recommends, and implements security controls for mobile device solutions and mobile-web interface. Ability to perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and their dependencies Proven ability to implement DevSecOps principles, seamlessly integrating security controls throughout the CI/CD pipeline Experience developing security metrics, managing compliance reporting, and auditing systems against established security baselines Collaborate effectively across multidisciplinary teams, and work independently as well as in a team Experience providing Tier II support for security operations and recommending continue security enhancements for existing infrastructure. Preferred In-depth experience at Federal cybersecurity frameworks (NIST SP 80053, FISMA, FedRAMP) authorization process Proven background in threat modeling, risk assessment, and designing resilient security architecture Advanced experience implementing secure DevOps/DevSecOps practices, specifically focus on CI/CD pipeline and automating security gates Knowledge of cloud security AWS and container security (Docker, Kubernetes)
For applications and inquiries, contact:[email protected]
By continuing you agree to our Terms & Privacy Policy.