GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security teams or simply need teammates who have a specialization in Application Security.
- Implement, operationalize, and/or improve the configuration of client application security tools
- Perform manual application/API assessments of customer applications
- Assist customers with questions relating to practical use of application security tools
- Experiential understanding of the Software Development Lifecycle (SDLC
- Practical understanding of cloud infrastructure environments such as AWS/Azure/GCP including “serverless” workflows
- Fundamental knowledge of software composition analysis and code/library dependencies
- Experience with testing tools such as: Burp Suite, Netsparker, Veracode, Checkmarx, Snyk, Invicti, etc.
- Deep understanding of a broad range of Application Security issues as well as their mitigation strategies
- Understanding of Application Security related vulnerabilities including cryptographic implementations
- Experience with reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#
- Written communication skills for written interactions with clients
- Strong communication skills that include the ability to clearly articulate thoughts and distill complex problems into stakeholder-friendly language
- Ability to manage time independently while handling multiple projects concurrently
- Significant knowledge of SAST, DAST, SCA, IAST, and/or RASP tooling preferred