Volpe Information Technology Group Secure Software Engineer Remote · Full time

Perform code review and audit application source code scans for security vulnerabilities

About Volpe Information Technology Group

Volpe Information Technology Group (VITG) is a Baltimore, MD based small business providing information technology (IT) consulting services to commercial and federal government customers. VITG is customer centric, focusing on the specific needs of our customers and tailoring our services to match their business. With a core focus on cyber security, VITG delivers next generation IT solutions that remain resilient in today’s dynamic threat environment. Our management team averages 20 plus years of industry service. VITG believes that our proprietary processes, technology, and technical discipline along with our experienced, highly skilled employees are the driving factor behind client satisfaction and the performance of our portfolios. The typical technical employee is well educated, often with an industry certification, and has experience in systems engineering and project management. VITGs’ services include Secure Software Development, Cyber Security Consulting, and Information Security Program Development and Support.

Description

Required Skills:

  • 2+ years of software development experience with any one of the object oriented programming languages like Java, Ruby, C#.
  • Git and Linux/Unix Commands.
  • Knowledge and understanding of Secure Code practices.
  • Perform code review and audit application source code scans for security vulnerabilities, and identify True Positives and False Positives.
  • Providing guidance to development community for resolving the vulnerabilities. Should be able to interact on daily basis with development community on the security issues of their applications.
  • Understanding of source code vulnerabilities such as Cross-Site Scripting, SQL Injection, Heap Inspection, DOM Injection, SSRF (Server-Side Request Forgery), XSRF (Cross-Site Request Forgery) etc.
  • Should be able to research on third party library vulnerable and non-vulnerable packages from different sources like NIST, OWASP and provide upgrade guidance on recent non-vulnerable components.
  • Understanding of Jenkins Pipeline.
  • Understanding of relational databases and experience in writing SQL queries.


Required Education:

  • Bachelor Degree at a minimal is required to be considered for this position.


Tools:

Checkmarx, blackduck, Nexus IQ, Blackduck, Eclipse, SQL Server Management Studio

Desired but not required:


Desired Experience:

  • Ability to take a product through the entire lifecycle of analysis, design, coding, testing and implementation and support.
  • Experienced with implementing all aspects of an application design – high performance design, coding, caching mechanisms, security, encryption, state management, error logging, debugging, scalability, code reviews, development environment configuration, and testing.
  • Experienced with performing unit and system level testing on web applications.
  • Proven track record of designing scalable, web based distributed software applications
  • Experience developing software in the government sector (a plus).
  • Experience or knowledge of Jenkins, Cloud, and Maven
  • Experience with collaboration tools such as SharePoint
  • Experience with integrating SCA code scanning into the build process
  • Code scanning experience - Manual/Automated/Static/Dynamic
  • Experience/exposure in major programming languages such as JAVA EE, .NET,
  • COBOL, ColdFusion, etc.

Salary

$75,000 - $95,000 per year