SECURITY SPECIALIST 1 - application-security / web-security testing roleProfessional ExperienceMinimum 4 years of general information technology experience performing technical and/or analytical tasks.
The resume needs to demonstrate actual technical/analytical IT responsibilities, not merely four years working within an IT organization.
EducationBachelor's degree in:- Computer Science
- Engineering
- or a related technical program
A copy of the bachelor's degree MUST be provided.- This is an explicit mandatory requirement. CA DMV IT CMAS RFO #ISD26-4861 …
HIGHLY DESIRABLE EXPERIENCE
DMV identifies the following as a scored desirable qualification:
Minimum 3 years of experience in any combination of:- OWASP methodologies
- Application security testing software, including Burp Suite, Metasploit or similar tools
- Web application programming languages, including JavaScript, HTML and SQL
This desirable qualification is important because it is worth
up to 100 evaluation points.
Therefore, I would
not recruit this as simply "four years of IT experience."
The target should be someone with four-plus years of IT experience who also has
three-plus years of demonstrable application security/web security experience.
Technical Skills to Search
Recruiters should search for combinations of:
- Application Security
- AppSec
- Web Application Security
- Web Application Penetration Testing
- Vulnerability Assessment
- Vulnerability Testing
- OWASP
- OWASP Top 10
- Burp Suite
- Burp Suite Professional
- Metasploit
- Web Security Testing
- JavaScript
- HTML
- SQL
- API Security
- HTTP/HTTPS
- Authentication Testing
- Authorization Testing
- Session Security
- SQL Injection
- XSS
- Input Validation
- Security Testing
- Vulnerability Remediation
- Secure Coding
- Secure SDLC
- Security Controls
- Technical Security Analysis
Good-to-Have Skills
While not mandatory for Security Specialist 1, I would prioritize candidates with exposure to:
- NIST cybersecurity/security controls
- California SAM/SIMM
- PCI DSS
- FIPS
- Government security environments
- Public-sector IT
- Secure coding standards
- SAST/DAST
- API penetration testing
- Postman
- Git/GitHub/GitLab
- CI/CD security
- DevSecOps
- Python
- PowerShell
- Linux
- Security reporting
- Risk assessment
- POA&M
- Cloud application security
Again, these are recruiting enhancements, not additional RFP-mandated requirements.
Soft Skills Required- Strong analytical ability: Candidate must investigate technical issues rather than simply run automated scanners.
- Attention to detail: Security testing and vulnerability evidence need to withstand review.
- Technical communication: Must explain security issues to both security professionals and application-development personnel.
- Documentation: DMV places significant importance on formal documentation and standardized work products.
- Team orientation: This person will be part of an existing Information Security organization, not an independent red-team engagement.
- Learning agility: Should be capable of absorbing DMV-specific standards, processes and security requirements.
- Professional judgment and confidentiality: The consultant may have access to security-sensitive information and PII.
IMPORTANT CANDIDATE SUBMISSION REQUIREMENTSRecruiters Should Collect This BEFORE Finalizing Either Candidate
This part is particularly important because
DMV does not just want a resume.
For each relevant experience used to satisfy a mandatory or desirable qualification, DMV requires:
- Company name
- Project name
- Exact project start date - MM/DD/YYYY
- Exact project end date - MM/DD/YYYY
- Candidate's role
- Detailed description of relevant experience
- Reference contact name
- Reference company
- Reference phone number
- Reference email
Total duration of qualifying experience
DMV uses a very specific
full-time month equivalent methodology when calculating qualifying experience. It defines a full-time month around at least 20 workdays and 140 hours and requires part-time experience to be prorated. CA DMV IT CMAS RFO #ISD26-4861 …
Security Specialist 3 - Documents We Need From Candidate
Before submission, obtain:
- Copy of valid CISSP
- Copy of valid PCI QSA
- Copy of valid GWAPT
And importantly, we need evidence that
each has been held for the required minimum five years.
If applicable:
- Copy of GCPN certification
- Copy of GMOB certification
Also collect detailed project histories proving:
- 5+ years NIST/FIPS
- 5+ years California SAM/SIMM
- 10+ years Web Application Assessment/Penetration Testing
- 5+ years PCI DSS / IRS 1075 / state-local government financial protection / ISO 27000
- 3+ years developing in-person AND self-paced secure-coding/web-security training
- Security Specialist 1 - Documents We Need From Candidate
Obtain:
- Copy of bachelor's degree in Computer Science, Engineering or related technical field
- And detailed project histories establishing:
- 4+ years general IT technical/analytical experience
- For maximum desirable scoring, document:
- 3+ years across OWASP, application-security testing tools such as Burp Suite/Metasploit, and/or JavaScript/HTML/SQL.
The RFO expressly requires copies of required degrees and certifications to accompany the CMAS classification qualification documentation. CA DMV IT CMAS RFO #ISD26-4861 …