Should have a strong proficiency in at least one of the following areas
Application Security Testing particularly with BurpSuite and/or ZAP; additional toolsets are expected, but highly dependent on the engineer’s experience
Web application security engineers must have line a. from the additional hardskill requirements below
DevSecOps practices (Hands on keyboard experience integrating security linting tools, SAST, or DAST into CI pipelines)
This area must be accompanied by some in depth knowledge of a language (c++, or JS / NodeJS, or Python), as well as line b from the additional hardskill requirements below
Cloud Security Posture Management engineering experience implementing automated solutions behind cloud resource security (e.g. designing and implementing a honeypot resulting in automation automatically blocking ingress traffic from malicious traffic).
Peripheral hard skill requirements
Strong understanding of AWS Cloud Technologies and Solutions
Strong understanding of vulnerabilities and the assessment thereof
Strong understanding of the Software Development Lifecycle (SDLC)
Ability to explain vulnerabilities in Engineering language, or Laman’s terms dependent on audience
Education:
Bachelor's or Master’s degree in Computer Science, Computer or Electrical Engineering, Mathematics, or a related field.
Any Graduate