Advanced Application Security Training

Job ID: 40056917

Budget: $30 – $250 USD

• Extensive experience in application security, with a focus on secure software
development practices and techniques.
• Strong understanding of web application security vulnerabilities and mitigation
strategies, such as OWASP Top 10.
• Experience with security testing tools and technologies, such as SAST, DAST,
and IAST solutions.
• Experience with Penetration testing tools such as: (web/mobile: Qualys, Burp
Suite)
• Experience with cloud security, containerization, and DevSecOps practices is a
plus
• Proficiency in programming languages commonly used in web application
development, such as Java, Python, or JavaScript.
• Lead the design and implementation of application security policies, standards,
and best practices in alignment with industry standards and regulatory
requirements.
• Lead a team of application security engineers to develop and drive initiatives to
secure products.
• Foster a culture of security awareness within the team and across the
organization.
• Conduct comprehensive security assessments of applications throughout the
software development lifecycle (SDLC) to identify and mitigate security
vulnerabilities and weaknesses.
• Collaborate with software development teams to integrate security controls and
best practices into the SDLC, including secure coding standards, static and
dynamic code analysis, and security testing.
• Provide guidance and support to developers on secure coding techniques,
security architecture, and threat modeling.
• Manage and oversee application security testing activities, including vulnerability
scanning, penetration testing, and code reviews.
• Monitor and analyze security incidents related to applications, and coordinate
• incident response and remediation efforts as needed.
• Stay current with emerging threats, vulnerabilities, and industry trends in
• application security.
• Develop and deliver application security training and awareness programs for
• development teams and other stakeholders.
• Collaborate with cross-functional teams to ensure the security of third-party and
• open-source software components used in our applications.
• Develop and maintain documentation related to application security architecture,
• processes, and procedures.
• Secure development practices, and integration into broader engineering activities.
• Security design / architecture and threat modeling.
• Product and service architectures in modern, multi-tenant cloud environments (IaaS, SaaS, PaaS).
• Amazon Web Services (AWS), Microsoft Azure, and/or Google Cloud Platform (GCP).
• Secure operations practices, specifically in cloud environments.
• Authentication and Identity management (e.g. SAML, SSO, OIDC, SCIM, etc) security best practices.
• Application and infrastructure security testing methodologies and tools.
• Vulnerabilities (old and new), and options for defense / mitigation.
• Product vulnerability management lifecycle.
• Working with and/or supporting product engineering teams.
• Security audits, penetration tests, and/or bug bounty programs.
• Cryptography and cryptographic primitives.
• Strong written and verbal communication skills.
• Full SDLC Support for new product features being developed. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
• Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
• Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
• Work on DAST tools and related automation for auto-assessment and defect filing.
• Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.
• Prioritize security from a risk management perspective, rather than an absolute textbook version.
• Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general
• Experience with the Threat Modeling process and ability to find design problems based on a block diagram of data flow.
• Understanding on at least two of the following domains - Web Security, Cloud Security, Systems Security and Applied Cryptography.
• Proficient with one or more of Programming languages ( Python/Java/Scala/JavaScript) and ability to read code to identify security defects.
• Skilled in scripting and automation on exploits
• Fuzzing skills are good to have.
• Exploit writing skills is a positive and greatly required.