Follow OWASP top 10 & Mars-E 2.0 health insurance compliance
Review vulnerabilities, collaborate with app dev team, remediate issues
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
Visa status: U.S. Citizens and those authorized to work in the U.S. are encouraged to apply.
Tax Terms: W2, 1099
Corp-Corp or 3rd Parties: Yes
Position title: Application Security Eng / Developer. Remote – can work anywhere in USA. 6+ Months Insurance client
Job Description:
The customer is an online insurance marketplace for state sponsored health insurance in the US.
They follow OWASP top 10 and Mars-E 2.0 health insurance compliance standard. There is more visibility for security engineering initiative now since state health insurance users brought it up in a user conference. They do get periodic tool based reports (using FOD) and is following process to have dev engineers look into this.
Candidate has to be a solid Security Engineering developer – Expectation is as below.
We need someone who can go to technical depth. For example, some questions will be around TLS 1.2, misusing XML to delete a file, protecting cookies, technical depth in XSS, etc.
He/she will have to review the vulnerabilities, reproduce the issue, collaborate with the application dev team and if required remediate the issue.
Experience in Burp Suite is desirable.
Desirable if the candidate has a Certified Ethical Hacker (CEH) Certification.
Required profile
Experience
Industry :
Information Technology & Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.