Search by job, company or skills

A

Lead Cybersecurity - Application Vulnerability Security Tester

3-7 Years
new job description bg glownew job description bg glownew job description bg svg
  • Posted 18 days ago
  • Be among the first 40 applicants
Early Applicant
Quick Apply

Job Description

Roles and Responsibilities:

  • Perform SAST/SCA/DAST scans using industry vulnerability scanner
  • SAST/SCA Veracode, using supplied compiled binary, configure scan platform to correct scan for both static code CWE s as we'll as SCA derived CVEs. Work will include coordination with app owner to ensure all branches of code are included in compiled binary file.
  • DAST Work begins with crawling the target application to identify existing directory and file structure. Once identified, execute DAST scan using HCL product to identify dynamic issue only visible during code execution.
  • During testing process, tester MUST ensure application is not degraded and/or taken out of service due to scanning activities
  • Tester must ensure results from scanner are present in VM reporting platforms and visible to approved app users

Validation - Supplier will perform manual validation and false-positive analysis on the automated scan results.

Remediation Support: The remediation support will analyze the top-rated vulnerabilities along with provide support to application teams on remediation strategies from identified risks.

Scan Retest: Supplier will perform revalidation tests of previously identified critical and high severity vulnerabilities as requested by the client application teams.

  • Complex application testing and remediation/mitigation recommendation author
  • Technical leadership of group of less experienced testers.
  • Adversary based approach to test plan development
  • Attempt to access unauthorized data
  • Attempt to make unauthorized changes
  • Bypass business logic, authentication, user privileges, etc.
  • Hijack accounts (Does not include social engineering methods)
  • Attempt to exploit OWASP Top 10 vulnerabilities
  • EcoSystem Testing
  • All forms of application security testing, attempt to exploit
  • All forms of device security testing, attempt to exploit
  • All forms of database security testing, attempt to exploit
  • Full Stack review, weakness enumer

About Company

We understand that our customers want an easier, less complicated life. We’re using our network, labs, products, services, and people to create a world where everything works together seamlessly, and life is better as a result. How will we continue to drive for this excellence in innovation With you. Our people, and their passion to succeed, are at the heart of what we do. Today, we’re poised to connect millions of people with their world, delivering the human benefits of technology in ways that defy the imaginable. What are you dreaming of doing with your career Find stories about our talent, career advice, opportunities, company news, and innovations here on LinkedIn. To learn more about joining AT&T, visit: http://www.att.jobs We provide in some of our posts links to articles or posts from third-party websites unaffiliated with AT&T. In doing so, AT&T is not adopting, endorsing or otherwise approving the content of those articles or posts. AT&T is providing this content for your information only.

Job ID: 118197371