Security Specialist 1 – Application Security / Web Security - 26-13022

Compu-Vision - IT
  • Roseville, CA
    2 days ago

    Job Description

    Security Specialist 1 – Application Security / Web Security

    Duration: 12+ Months
    Location: West Sacramento, CA
    Work Model: Hybrid

    MUST HAVE :  Candidate must have professional cybersecurity certifications:- CISSP, PCI QSA and GWAPT

    Job Overview

    We are seeking a Security Specialist 1 with hands-on experience in Application Security and Web Security Testing. The ideal candidate will have a strong technical and analytical IT background, with experience assessing web applications, identifying vulnerabilities, analyzing security findings, and collaborating with development and security teams on remediation.

    Required Qualifications

    • 4+ years of technical/analytical IT experience performing hands-on technical responsibilities.
    • Bachelor’s degree in Computer Science, Engineering, or a related technical field.
    • Hands-on experience with application and/or web security testing.

    Highly Desirable Experience

    • 3+ years of combined experience with:
      • OWASP methodologies and OWASP Top 10.
      • Application security testing tools such as Burp Suite, Burp Suite Professional, Metasploit, or similar.
      • Web application programming technologies including JavaScript, HTML, and SQL.
    • Web application penetration testing and vulnerability assessment.
    • API security testing.
    • Authentication, authorization, and session security testing.
    • SQL Injection, XSS, input validation, and other common web application vulnerabilities.
    • Vulnerability analysis, remediation, and secure coding practices.
    • Secure SDLC and application security controls.

    Additional Preferred Skills

    • SAST/DAST and DevSecOps.
    • API penetration testing and Postman.
    • Git/GitHub/GitLab and CI/CD security.
    • Python, PowerShell, and Linux.
    • NIST, FIPS, PCI DSS, and California SAM/SIMM.
    • Government/public-sector security environments.
    • Cloud application security.
    • Security reporting, risk assessment, and POA&M.

    Key Responsibilities

    • Perform technical security assessments of web applications and APIs.
    • Identify, validate, analyze, and document application security vulnerabilities.
    • Apply OWASP methodologies and security testing techniques to evaluate applications.
    • Use tools such as Burp Suite, Metasploit, or comparable application security testing platforms.
    • Analyze application behavior, authentication, authorization, session management, input validation, and security controls.
    • Investigate vulnerabilities beyond automated scanner results and provide detailed technical findings.
    • Work with application developers and security teams to communicate vulnerabilities and recommend remediation.
    • Support secure SDLC and application security activities.
    • Prepare detailed security assessment reports and supporting documentation.
    • Maintain accurate evidence and documentation for security findings and remediation activities.
    • Support security standards, policies, risk assessments, and compliance requirements.
    • Collaborate with an established Information Security organization and other technical stakeholders.

    Numbers & Facts

    LocationRoseville, CA

    Skills

    • (XSS) Cross Site Scriptingunmatched
    • Access Authorizationunmatched
    • Analysis Skillsunmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Authenticationunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Documentationunmatched
    • Federal Information Processing Standards (FIPS)unmatched
    • Gitunmatched
    • GitHubunmatched
    • Governmentunmatched
    • HTML (HyperText Markup Language)unmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Injectionsunmatched
    • Internet Applicationunmatched
    • Internet Securityunmatched
    • Internet Technologyunmatched
    • JavaScriptunmatched
    • Linux Operating Systemunmatched
    • Mail Servicesunmatched
    • Metasploitunmatched
    • PCIunmatched
    • PCI-DSSunmatched
    • Penetration Testingunmatched
    • Python Programming/Scripting Languageunmatched
    • Regulatory Complianceunmatched
    • Risk Analysisunmatched
    • SQL (Structured Query Language)unmatched
    • Security Analysisunmatched
    • Software Developmentunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Software Testingunmatched
    • Test Toolsunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Web Analyticsunmatched
    • Web Programmingunmatched
    • Web Testingunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder