JOB SUMMARY:
Baylor Genetics is looking for an Application Security Analyst to assist in safeguarding software applications and infrastructure. The role is pivotal in driving security initiatives, from ensuring comprehensive vulnerability management to fostering a culture of security awareness among developers. This position involves close collaboration with development teams to embed security into every stage of the software development process. Key duties include creating security training programs, establishing, and enforcing security standards, performing detailed risk assessments, and conducting penetration tests.
Additionally, the Application Security Analyst will play a crucial role in enhancing our infrastructure security and staying ahead of the latest cybersecurity trends and threats.
MAJOR RESPONSIBILITIES:
·Develop, manage, and maintain the Application Vulnerability Management program.·Facilitate security code scans and tracking and remediation of vulnerabilities.·Collaborate with development teams to integrate secure coding practices into the SDLC. ·Establish a security awareness training program for developers.·Develop and maintain application security procedures and standards adhered to organizational goals and compliance requirements.·Perform risk assessments and document security findings and remediation strategies.·Conduct penetration testing on external facing applications and networks.·Assist with evaluating infrastructure security controls and implementing changes.·Stay up-to-date with the latest security threats, trends, and technologies.
REQUIRED JOB QUALIFICATIONS:
Education:
·Bachelor’s degree in cybersecurity or computer information systems.·Minimum of 5 years of related work experience. ·Relevant industry certifications such as OSCP or similar.
Experience:
·Experience with security scanning tools (e.g. SAST, DAST, IAST), penetration testing tools, and WAFs.·Knowledge of secure software development methodologies (e.g., Agile, DevSecOps) and SDLC processes.·Understanding of OWASP Top 10, common attack vectors, andcompliance frameworks and regulations (e.g., NIST, GDPR, HIPAA).·Familiarity with secure coding practices in programming languages (e.g., Java, Python, Reach, Angular, .NET).·Knowledge of authentication and authorization infrastructure (e.g., SAML, OpenID, OAuth).·Communication and interpersonal skills, with the ability to collaborate effectively with diverse teams.