Secure Code Analyst

  • Full-time

Company Description

MUST BE A U.S. CITIZEN

A3T, a fast growing firm, specializes in Defensive Cyber Security Services, Enterprise Information Technology (IT) Solutions, and Professional Services driven by customer requirements. Our client’s customers are the focal point of all decisions and actions. A3T provides customer-centric services
and focus resources to meet operational requirements, exceed expectations, and sustain organizational growth while mitigating risk.  

Join A3T and watch your career soar! A3T is a small, agile, company looking for incredible talent to support the United States Government in many important national security roles.  A3T is looking to bring on an experienced Secure Code Analyst with “Next-Level Thinking” who is ready to take their career to a new level with A3T.



Job Description

To support continued growth as the US Army HRC transforms into one of 4 CONUS based Enduring Data Centers, we are looking for the right person to join our Cyber Security team who can ensure applications and software products are vulnerability-free so that our customers can reliably build, deploy, and leverage applications that are safe from outside attack. This includes all forms of security analysis and testing as well as the development of security analysis tools to assist with mission critical applications. The right person will be embedded into SDLC process(es) and perform application security assessments to assist development team(s) in delivering secure code.

In this role you will: 

- Run periodic and ad hoc vulnerability assessments against both existing and emerging products Validate Developer mitigation notes on all findings.

- Present test results to key stakeholders.

- Ensure that security best practices are followed throughout product development.

- Assist with internal and external information security assessments and reviews.

- Work closely with cross-functional teams and develop strong liaison relationships.

- Maintain current working knowledge technological trends and developments related to application and web application security issues.

- Provide recommendations regarding secure development best practices.

- Provide and meet time estimates for assigned deliverables.

Core Characteristics:

- Technical Aptitude – Ability to comprehend complex technical topics and specialized information. Systems Analysis – Ability to determine how a system should work and how changes in conditions, operations, and environment will affect outcomes.

- Problem Solving – Ability to find a solution for or to deal proactively with work-related problems. Deductive Reasoning – Ability to apply principals of logical or critical thinking to a wide range of intellectual and practical problems. Analytical Thinking - Ability to use thinking and reasoning to solve a problem.

- Oral Communication - Ability to communicate effectively with others using the written and spoken word.

- Work Under Pressure - Ability to complete assigned tasks under stressful situations.

- Customer Oriented – Ability to take care of the customers’ needs while following all regulations, policies, and command directives.

- Organized - Possesses the trait of being organized or follows a systematic method of performing a task.

- Integrity – Ability to protect confidential information. Works to prevent mistakes and, if mistakes are made, takes responsibility and acts quickly to correct.

- Diligence – Focuses clearly on the necessary tasks. Steady, earnest, and energetic in all tasks. Honors commitments in a timely, efficient and effective manner.

- Customer Focus – Helps customer achieve stated goals. Anticipates customer needs and finds ways to serve them better. Creates customized solutions.

- Collaboration – Shares information and expertise. Willing to coach and to be coached. Puts personal agendas aside to achieve the larger goal.

- Knowledge – Consistently improves understanding of the mission. Thinks ahead to anticipate changes.

- Self-Discipline – Consistently sets and achieves individual goals. Shows self-discipline in all conduct and communication.

- Resourcefulness – Continually thinks creatively to identify the most effective and efficient way to accomplish tasks. Ingenious and inventive.



Qualifications

Required Qualifications:

- US Citizen with good interpersonal skills and able to work in a large team environment. Must Currently Possess a current active SECRET clearance 

- Current certifications demonstrating DOD 8570.1M compliance for IAT level II certification or higher. 

- Bachelor’s Degree in Software Engineering or related degree and 5+ years of related experience or a Master’s degree and 3+ years’ experience. 4 additional years of related experience will be considered in lieu of a Bachelor’s degree. Also, a PHD and zero years’ experience will be considered as well.

- Excellent PC skills (Excel, Word, PowerPoint).

- Good understanding of security controls and components of a Secure Software Development Lifecycle (SSDLC) (e.g., Requirements, Design, Development, and Test in Agile/Scrum/Waterfall). Experience with software security assessment tools and products (e.g. Fortify, Veracode, Burp Suite, WebInspect) Knowledge of NIST SP 800-63/64 guidelines and security best practices for Secure Software Development.

- Understanding of web application architecture and security issues (e.g. OWASP) Familiarity with operating systems and development tools such as Visual Studio IDE.

- In depth knowledge of at least one programming language.


Desired Skills:


- Security professional must be able to take an analytical approach that can look beyond the immediate to identify potential future weakneses


- Proficient developing in C# and VB.NET languages or Java preferred.

- Proficient developing in C and C++ languages a plus Knowledge of the HTTP protocol and client-side programming including HTML, JSP, JavaScript, JSON a plus Familiarity with Java security, J2SE and JAAS Database familiarity and experience using MS SQL, Oracle, DB2 a plus Cryptography knowledge a plus



Additional Information

Agil3Tech (A3T) offers a competitive benefits package to include: paid holidays, paid time off, medical, dental, vision, company paid long and short term disability and life insurance, referral bonuses, certification reimbursement program, etc.

It is the policy of A3T to provide equal opportunity in recruiting, hiring, training, and promoting individuals in all job categories without regard to race, color, religion, national origin, gender, age, disability, genetic information, veteran status, sexual orientation, gender identity, or any other protected class or category as may be defined by federal, state, or local laws or regulations.

We maintain a drug-free workplace and perform pre-employment substance abuse testing to include background checks.

All your information will be kept confidential according to EEO guidelines.

eVerify Employer