ApplicationsSecurity Specialist

A large financial Service Company based in Cape Town ,seeks a Application Security Specialist with:

Minimum requirements

  • Grade 12
  • An Appropriate IT Qualification (Diploma/Degree) will be advantageous.
  • Security Certification qualification essential (Industry accepted security standards) such as CISSP, etc.
  • Minimum 3 years previous experience in a similar role or equivalent
  • Familiarity with standard network security technology solutions: e.g. firewall, router, VPN
  • Experience& nbsp; with the use of standard security technology solutions and processes such as: access control, vulnerability management, anti-virus, single sign on, auditing, encryption
  • Programming experience essential
  • OWASP and Microsoft SDL experience (Practical  understanding.

 

Knowledge:

  • Systems analysis and design concepts
  • Good database knowledge
  • Knowledge of the latest threats and mitigating actions;

 

Competencies & nbsp:

  • Strong analytical & numerical ability
  • Problem solving skills
  • Strong judgement and decision making skills
  • Conceptual thinker
  • Good communication skills
  • Action / results orientated
  • Quality orientated
  • Knowledge seeking / learning orientated
  • Strong Interpersonal and people interaction skills
  • C#,Java, JavaScript, HTML, SQL Server, DB2, IIS, Tomcat, Websphere, Windows Server, Single-sign-on technologies, Web related vulnerabilities and exploits skills

Role Purpose:

  • Develop and implement   application security awareness initiatives
  • Act as the Lead on application risk within SPF IT

Responsibilities:

  • Oversee the security aspects in the SDLC:

Requirements

  • Establish security requirements
  • Create quality gates
  • Security and privacy risk assessment

Design

  • Establish design requirements
  • Analyse attack surface
  • Threat modelling

Implementation

  • Use approved tools
  • Static analysis (e.g. CatNet, FXCop, JSLint)

Verification

  • Dynamic analysis (e.g. HP Fortify – execution level analysis)
  • Fuzz testing (e.g. MiniFuzz, RegexFuzzer)
  • Attack surface review

Release

  • Incident response plan
  • Final security review
  • Report regularly to the Information Security Governance Forum
  • Participate in Enterprise Architecture forum
  • Implement Group application security Architecture policy and standards
  • Manage application security incidents and remedial recommendations and actions
  • Participate in investigations on suspected and actual breaches of security and undertake remedial action
  • Conduct security research in keeping abreast of latest security trends and practises

 

For more information please contact Bella 011 234 7679, alternatively email your updated CV to bella @ esmartgroup. co.za

If you do not receive a response within 2 weeks please consider your application declined.

Please be advised that we are currently experiencing technical problems receiving emails from Yahoo account, please use an alternative email address when communicating with us. If you do not have alternative address please contact the Recruiter (number above) for an alternative way to submit your application.

Our apologies for the inconvenience caused 

Leave a Reply

Your email address will not be published.