Security engineer Job at PRIMUS Global Services, Inc, Dallas, TX

LzhYeC9ZRGNpbFJDVzkrR1hlU3BRaWtHS2c9PQ==
  • PRIMUS Global Services, Inc
  • Dallas, TX

Job Description

Security Engineer - SAST - Remote - 63096

One of our top clients has an urgent need for a Security Engineer - SAST to work remotely on a long-term contract.

Pay Rate : $50-$55/hr

  • SAST/SCA Experience – General experience working with Static Application Security Testing (SAST) and Software Composition Analysis (SCA) tools.
  • SAST/SCA (Veracode) Onboarding & ServiceNow Management – Ability to onboard applications into Veracode, configure scans, troubleshoot integration issues, and effectively manage Veracode-related RITMs within ServiceNow. This includes handling requests for adding/removing applications, teams, and API accounts, as well as reviewing mitigation submissions.
  • GitLab CI/CD Security Operations – Strong understanding of GitLab CI/CD pipelines and how security scanning tools, including Veracode, are integrated. Ability to troubleshoot security scan issues, analyze pipeline failures, and determine when to escalate to the engineering team for resolution.
  • Mitigation Assessment & Approval – Expertise in evaluating remediation plans and compensating controls to determine their effectiveness in addressing security risks. Ability to make informed approval or denial decisions based on industry best practices and organizational security policies.
  • What specific SAST and SCA tools should the candidate be familiar with?
    • Veracode, GitLab Ultimate
  • How much experience should they have with these tools?
    • The candidate should have a solid understanding of how these tools function and their purpose within the security framework. While deep expertise is not required, they should be comfortable navigating the tools and leveraging their capabilities effectively.
  • What will the candidate's responsibilities be when onboarding and managing applications in security tools?
    • Upon receiving a RITM (Request Item), the candidate must extract relevant details from the ticket and properly configure the team/application in Veracode with accurate data. They should ensure all necessary information from the ticket is correctly applied or take appropriate action based on the request.
  • What troubleshooting skills are crucial for resolving integration issues with security tools?
    • The candidate should be proficient in navigating Gitlab pipeline jobs and glean useful information from the command-line interface logs. Additionally, they should be able to navigate Veracode or other SAST platform tools when helping a dev or customer and know when to engage other appropriate teams for resolution if further support is required.
  • How should the candidate handle security-related tasks and requests in ServiceNow?
    • The process aligns with the responsibilities outlined in question 3. The candidate should review the request details, ensure accuracy, and take the necessary steps to fulfill the request appropriately.
  • What kind of experience should they have with integrating security scanning tools into CI/CD pipelines?
    • While they are not expected to develop integrations themselves, the candidate should have a working knowledge of how SAST and SCA tools integrate into GitLab. They must understand these integrations well enough to assess their functionality and troubleshoot basic issues.
  • How should the candidate evaluate and approve remediation plans and compensating controls?
    • The candidate should thoroughly review requests, ensuring all necessary details are included. If information is insufficient, they should engage with the requestor (e.g., developers) to obtain additional details. Once the full context is available, they must assess whether the proposed remediation or compensating control effectively mitigates the risk and take the appropriate action to approve or deny the request.
  • Will the candidate be involved in remediating issues found in scans? If so, to what extent?
    • No, the candidate will not be directly coding fixes. However, they will act as a consultant, working closely with developers to help them understand identified vulnerabilities and guide them in remediating their code effectively.

For Immediate Consideration, Please Contact

AISHWARYA

PRIMUS Global Services

Direct - (972) 798-2408

Desk - (972) 753-6500 Ext. 215

Email: [email protected]

Job Tags

Remote job, Full time, Contract work, Immediate start,

Similar Jobs

ROM LOGISTICS LLC

Amazon Delivery - Delivery Associate/Driver Job at ROM LOGISTICS LLC

 ...de la empresa ROM Logistics is an Amazon DSP focused on strict adherence to all safety...  ...and on-time attendance and quality deliveries 100% of the time. Descripcin del empleo...  ...have a non-provisional, unrestricted driver's license with a clean DMV record Must... 

Wells Fargo

MidCorp Portfolio Management Manager Job at Wells Fargo

 ...About this role: Wells Fargo is seeking a Mid-Corp Portfolio Management Manager for clients with annual revenue of $100MM+ as well as venture-backed Companies supporting Technology as part of the Commercial Bank. Learn more about the career areas and business divisions... 

Ernst & Young

Independence Consultant - CBS - Risk Management - Senior Associate - Multiple Positions - 1596637 Job at Ernst & Young

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. At EY, youll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to ...

UPS

Brokerage Rater-Night Shift Job at UPS

 ...la nostra gratificante cultura e lavora con team di talento che ti aiutano a migliorare ogni giorno. Sappiamo cosa serve per guidare UPS verso il futuro: persone con una combinazione unica di competenze + passione. Se hai le qualit e la motivazione per guidare te stesso... 

Get It - Healthcare

RN Triage Nurse - Remote | WFH Job at Get It - Healthcare

Are you an experienced Registered Nurse (RN) looking for a rewarding remote opportunity in a fast-paced, team-oriented environment...  ...with both pediatric and adult experience to join our growing telephone triage team. If you prefer weekend shifts and enjoy having...