✨ AI Summary
Dicetek LLC is seeking a Software Engineer specializing in Security to design, implement, and maintain secure software architectures. This role involves conducting security code reviews, vulnerability assessments, and developing security controls throughout the SDLC. The engineer will also investigate security incidents, perform root cause analysis, and implement preventative measures.
Key responsibilities include working with application security (web, mobile, API), penetration testing, DevSecOps, threat modeling, cloud security (AWS, Azure), Kubernetes security, and security automation using Python, Bash, and PowerShell. The role requires strong stakeholder management and communication skills, with a minimum of 8-15 years of information security experience, including hands-on experience in application, infrastructure, and cloud security. Expertise in penetration testing, DevSecOps implementation, security automation, and container security is crucial. Experience with security architecture reviews, vulnerability management, and the banking/financial services domain is also required.
Design, implement, and maintain secure software architectures, ensuring security is a core component from the outset.Conduct thorough security code reviews and vulnerability assessments to identify and remediate potential weaknesses.Develop and integrate security controls and mechanisms into the software development lifecycle (SDLC).Investigate security incidents, perform root cause analysis, and implement preventative measures.
Requirements
Application Security (Web, Mobile & API Security)
Penetration Testing & Vulnerability Assessment
Secure Code Review
DevSecOps & CI/CD Security
Threat Modeling & Risk Assessment
Cloud Security (AWS & Azure)
Kubernetes & Container Security
Security Architecture & Design Review
Security Automation & Scripting (Python, Bash, PowerShell)
Incident Response & Vulnerability Management
Strong stakeholder management and communication skills
Required Experience / Knowledge Areas *
8-15 years of Information Security experience.
Hands-on experience in application, infrastructure, and cloud security.
Expertise in penetration testing methodologies (OWASP Top 10, OWASP API Security Top 10, Mobile Security Testing).
Experience with DevSecOps implementation and security automation.
Strong understanding of Kubernetes, Docker, container runtime security, and microservices security.
Experience conducting security architecture reviews and secure design assessments.
Knowledge of vulnerability management lifecycle and remediation practices.
Familiarity with security frameworks including NIST, CIS Controls, and ISO 27001.
Banking/Financial Services domain experience.
Skills
Application Security
DevSecOps
Threat Modeling
Description
Design, implement, and maintain secure software architectures, ensuring security is a core component from the outset.Conduct thorough security code reviews and vulnerability assessments to identify and remediate potential weaknesses.Develop and integrate security controls and mechanisms into the software development lifecycle (SDLC).Investigate security incidents, perform root cause analysis, and implement preventative measures.