At a Glance
- Tasks: Ensure the security of code development processes and applications, focusing on AI-driven solutions.
- Company: Join a leading tech firm dedicated to robust security practices and innovation.
- Benefits: Comprehensive health plans, 401(k) match, paid time off, and professional development opportunities.
- Other info: Dynamic team environment with excellent career growth potential.
- Why this job: Make a real impact in application security while working with cutting-edge technologies.
- Qualifications: Experience in security testing tools and methodologies; strong communication skills required.
The predicted salary is between 50000 - 60000 £ per year.
The AppSec / DevSecOps Engineer is responsible for ensuring the security of code development processes and applications, with a focus on both traditional and AI-driven solutions. This position will work closely with internal IT teams, internal customers, and external vendors, contributing to robust security practices and risk management across the organization.
- Define and implement security testing strategies for AI solutions, utilizing both grey box and black box methodologies.
- Grey Box Testing: Conduct Static Application Security Testing (SAST), dependency scanning, secrets scanning, Infrastructure as Code (IaC) scanning, and configuration reviews.
- Black Box Testing: Perform Dynamic Application Security Testing (DAST), API fuzzing, authentication testing, and rate-limit tests.
- AI-Specific Security Tests: Execute prompt injection checks, jailbreaking resistance assessments, tool misuse evaluations, and leakage tests tailored for AI applications.
- Review remediation efforts and verify fixes prior to production deployment.
- Conduct thorough risk assessments of new and existing applications, identifying vulnerabilities and security gaps.
- Analyze and interpret security assessment findings, providing actionable recommendations to mitigate risks.
- Collaborate with software development teams to implement security best practices and ensure secure coding standards.
- Stay current with emerging threats, vulnerabilities, and industry trends, integrating this knowledge into risk assessment processes.
- Participate in security reviews to evaluate and validate the effectiveness of security controls.
- Provide technical guidance and support for incident response efforts related to application security incidents.
- Review and validate contracts, Statements of Work (SOW), and Data Processing Agreements (DPAs).
- Develop and maintain Data Loss Prevention (DLP) policy standards, reusable templates, naming conventions, and engineering runbooks.
Basic Job Requirements
- Accredited four (4) year degree or global equivalent in applicable field of study and five (5) years of work-related experience or a combination of education and directly related experience equal to nine (9) years if non-degreed; some locations may have additional or different qualifications in order to comply with local requirements.
- Ability to communicate effectively with audiences that include but are not limited to management, coworkers, clients, vendors, contractors, and visitors.
- Job related technical knowledge necessary to complete the job.
- Ability to learn and apply knowledge of applicable local, state/province, and federal/national statutes and guidelines.
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- Experience with security testing tools and methodologies (SAST, DAST, dependency scanning, API fuzzing, etc.).
- Familiarity with AI security concerns, including prompt injection and jailbreaking resistance.
- Strong understanding of secure coding practices and application risk assessment.
- Effective communication and collaboration skills for working with cross-functional teams and external partners.
- Ability to develop and maintain technical documentation, policy standards, and runbooks.
- Proven experience (5 years) as an IT Security Analyst or similar role, with a focus on application security, Azure Active Directory, conditional access policies, and single sign-on (SSO) configurations.
- Ability to effectively adapt to rapidly changing technology and apply it to business needs.
- Demonstrated strong technical and non-technical communication skills, both oral and written.
- Strong team-oriented interpersonal skills.
- Proficiency in scripting or programming languages (e.g., Python, JavaScript, Java) is a plus.
- Excellent communication skills to convey complex technical concepts to non-technical stakeholders.
- Strong problem-solving skills.
- Strong organizational skills and attention to detail, especially concerning note taking when evaluating applications and attending meetings.
- Organize and prioritize a variety of projects and multiple tasks in an effective and timely manner, set priorities, and meet deadlines.
Benefits
Fluor is proud to offer a comprehensive benefits package designed to promote employee health, wellness, and financial security. Our offerings include medical, dental and vision plans, EAP, disability coverage, life insurance, AD&D, voluntary benefit plans, 401(k) with a company match, paid time off (personal, bereavement, sick, holidays) for salaried employees, paid sick leave per state requirement for craft employees, parental leave, and training and development courses.
We are an equal opportunity employer. All qualified individuals will receive consideration for employment without regard to race, color, age, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, genetic information, or any other criteria protected by governing law.
Market Rate Statement
The market rate for the role is typically at the mid-point of the salary range; however, variations in final salary are determined by additional factors such as the candidate’s qualifications, relevant years of experience, geographic location, internal pay equity, and prevailing market conditions for the specific role.
Notice to Candidates
Background checks are carried out as part of any conditional offer made, including (but not limited to & role dependent) education, professional registration, employment, references, passport verifications and Global Watchlist screening.
To be Considered Candidates
Must be authorized to work in the country where the position is located.
Salary Range
Salary Range: - #J-18808-Ljbffr
IT Operations Specialist I - AppSec DevSecOps in Farnborough employer: Flr Federal Solutions,LLC
Fluor is an exceptional employer that prioritises employee well-being and professional growth, offering a comprehensive benefits package that includes medical, dental, and vision plans, as well as generous paid time off and training opportunities. The collaborative work culture fosters innovation and teamwork, making it an ideal environment for IT Operations Specialists to thrive while contributing to cutting-edge security practices in a rapidly evolving technological landscape.
StudySmarter Expert Advice🤫
We think this is how you could land IT Operations Specialist I - AppSec DevSecOps in Farnborough
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at local meetups. We all know that sometimes it’s not just what you know, but who you know that can land you that interview.
✨Tip Number 2
Prepare for those interviews by practising common questions and scenarios related to AppSec and DevSecOps. We recommend doing mock interviews with friends or using online platforms to get comfortable with the process.
✨Tip Number 3
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those involving security testing tools and methodologies. This gives potential employers a taste of what you can do.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step to connect with us directly.
We think you need these skills to ace IT Operations Specialist I - AppSec DevSecOps in Farnborough
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with security testing tools and methodologies. We want to see how your skills align with the role of an AppSec / DevSecOps Engineer!
Show Off Your Communication Skills:Since this role involves collaborating with various teams, it's crucial to demonstrate your effective communication skills. Use clear examples in your application that showcase how you've successfully worked with others in the past.
Highlight Relevant Experience:Don’t forget to emphasise your experience in application security and risk assessment. We’re looking for candidates who can analyse security findings and provide actionable recommendations, so make that shine through in your application!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates during the process!
How to prepare for a job interview at Flr Federal Solutions,LLC
✨Know Your Security Testing Tools
Familiarise yourself with the specific security testing tools mentioned in the job description, like SAST and DAST. Be ready to discuss your experience with these tools and how you've applied them in past roles.
✨Showcase Your Collaboration Skills
This role involves working closely with various teams. Prepare examples of how you've successfully collaborated with cross-functional teams in the past, especially in relation to security practices and risk management.
✨Stay Updated on AI Security Trends
Given the focus on AI-driven solutions, make sure you’re up-to-date with the latest trends and threats in AI security. Bring insights or recent findings to the interview to demonstrate your proactive approach.
✨Prepare for Technical Questions
Expect technical questions related to secure coding practices and application risk assessments. Brush up on your knowledge and be ready to explain complex concepts in a way that’s easy to understand for non-technical stakeholders.