Security Specialist 1 – Application Security / Web Security
Duration: 12+ Months Location: West Sacramento, CA Work Model: Hybrid
MUST HAVE : Candidate must have professional cybersecurity certifications:- CISSP, PCI QSA and GWAPT
Job Overview
We are seeking a Security Specialist 1 with hands-on experience in Application Security and Web Security Testing. The ideal candidate will have a strong technical and analytical IT background, with experience assessing web applications, identifying vulnerabilities, analyzing security findings, and collaborating with development and security teams on remediation.
Required Qualifications
4+ years of technical/analytical IT experience performing hands-on technical responsibilities.
Bachelor’s degree in Computer Science, Engineering, or a related technical field.
Hands-on experience with application and/or web security testing.
Highly Desirable Experience
3+ years of combined experience with:
OWASP methodologies and OWASP Top 10.
Application security testing tools such as Burp Suite, Burp Suite Professional, Metasploit, or similar.
Web application programming technologies including JavaScript, HTML, and SQL.
Web application penetration testing and vulnerability assessment.
API security testing.
Authentication, authorization, and session security testing.
SQL Injection, XSS, input validation, and other common web application vulnerabilities.
Vulnerability analysis, remediation, and secure coding practices.
Secure SDLC and application security controls.
Additional Preferred Skills
SAST/DAST and DevSecOps.
API penetration testing and Postman.
Git/GitHub/GitLab and CI/CD security.
Python, PowerShell, and Linux.
NIST, FIPS, PCI DSS, and California SAM/SIMM.
Government/public-sector security environments.
Cloud application security.
Security reporting, risk assessment, and POA&M.
Key Responsibilities
Perform technical security assessments of web applications and APIs.
Identify, validate, analyze, and document application security vulnerabilities.
Apply OWASP methodologies and security testing techniques to evaluate applications.
Use tools such as Burp Suite, Metasploit, or comparable application security testing platforms.