Application Security Specialist
Full-time
Description
<span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><h2><span><span><span><b>Job Title</b></span></span></span></h2></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>Application Security Specialist<span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><h2><br><span><span><span><b>Location(s)</b></span></span></span></h2></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>India - Remote<p></p><p><b><span>About Us</span></b></p><p></p><p><span>Revvity is a developer and provider of end-to-end solutions designed to help scientists, researchers, and clinicians solve the world’s greatest health challenges. We pair the enthusiasm of an industry disruptor with the experience of a longtime leader. Our team of 11,000+ colleagues from around the globe are vital to our success and the reason we’re able to push boundaries in pursuit of better human health.</span><span> </span></p><p></p><p>Find your future at Revvity </p><p></p><p><b>Job Description:</b></p><p>As an Application Security Specialist, you will play a pivotal role in securing our applications and protecting our infrastructure from potential threats. Your responsibilities will include:</p><p></p><ul><li>SAST and DAST Testing: Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), review their outputs, and assist the development team with remediation strategies.</li><li>GitHub Security: Configure and manage security tools such as Checkmarx and leverage GitHub's native security features to scan vulnerabilities in the codebase and dependencies.</li><li>CI/CD Pipeline Security: Ensure integration of security scans within our CI/CD pipelines to identify vulnerabilities early in the development process.</li><li>Container Security: Implement and enforce security best practices for containerization within AWS ECS and ECR environments, focusing on secure configurations, image scanning, and robust access control measures.</li><li>Vulnerability Management: Lead the coordination and management of vulnerability scanning and remediation efforts across the application stack, encompassing the codebase, containers, and AWS infrastructure.</li><li>Penetration Testing: Conduct thorough penetration testing on products and systems, including web applications and services, to identify and exploit security flaws.</li><li>Cross-functional Collaboration: Participate in triage calls with cross-functional teams and effectively communicate vulnerability details, risks, and potential impacts to stakeholders.</li></ul><p></p><p><b>Requirements:</b></p><p></p><ul><li>Over 3-5 years of hands-on experience in application security.</li><li>Advanced proficiency in tackling technical challenges independently.</li><li>Basic understanding of AWS cloud technologies and environments.</li><li>Familiarity and experience with tools like Snyk, Veracode,Gitleaks and Burp Suite will be an added advantage.</li><li>Strong knowledge of web application frameworks (such as OWASP) and CI/CD frameworks.</li><li>Experience with scripting languages (e.g., Python, JavaScript, PowerShell, Ruby, PHP) to develop custom scripts.</li><li>Familiarity with shift-left tools and application security workflows.</li><li>Excellent collaboration skills to work with cross-functional teams towards shared goals.</li><li> Excellent written and verbal communication skills.</li><li>Bachelor’s degree in information technology, Computer Science, or equivalent practical experience.</li></ul>