At a Glance
- Tasks: Ensure the security of code development processes and applications, focusing on AI-driven solutions.
- Company: Join a leading tech firm dedicated to robust security practices and innovation.
- Benefits: Comprehensive health plans, 401(k) match, paid time off, and professional development opportunities.
- Other info: Dynamic team environment with opportunities for growth and learning.
- Why this job: Make a real impact in securing cutting-edge technology and applications.
- Qualifications: Degree in IT or related field with experience in application security and testing tools.
The predicted salary is between 50000 - 60000 £ per year.
The AppSec / DevSecOps Engineer is responsible for ensuring the security of code development processes and applications, with a focus on both traditional and AI-driven solutions. This position will work closely with internal IT teams, internal customers, and external vendors, contributing to robust security practices and risk management across the organization.
Responsibilities
- Define and implement security testing strategies for AI solutions, utilizing both grey box and black box methodologies.
- Grey Box Testing: Conduct Static Application Security Testing (SAST), dependency scanning, secrets scanning, Infrastructure as Code (IaC) scanning, and configuration reviews.
- Black Box Testing: Perform Dynamic Application Security Testing (DAST), API fuzzing, authentication testing, and rate-limit tests.
- AI-Specific Security Tests: Execute prompt injection checks, jailbreaking resistance assessments, tool misuse evaluations, and leakage tests tailored for AI applications.
- Review remediation efforts and verify fixes prior to production deployment.
- Conduct thorough risk assessments of new and existing applications, identifying vulnerabilities and security gaps.
- Analyze and interpret security assessment findings, providing actionable recommendations to mitigate risks.
- Collaborate with software development teams to implement security best practices and ensure secure coding standards.
- Stay current with emerging threats, vulnerabilities, and industry trends, integrating this knowledge into risk assessment processes.
- Participate in security reviews to evaluate and validate the effectiveness of security controls.
- Provide technical guidance and support for incident response efforts related to application security incidents.
- Review and validate contracts, Statements of Work (SOW), and Data Processing Agreements (DPAs).
Qualifications
- Accredited four (4) year degree or global equivalent in applicable field of study and five (5) years of work-related experience or a combination of education and directly related experience equal to nine (9) years if non-degreed; some locations may have additional or different qualifications in order to comply with local requirements.
- Ability to communicate effectively with audiences that include but are not limited to management, coworkers, clients, vendors, contractors, and visitors.
- Job related technical knowledge necessary to complete the job.
- Ability to learn and apply knowledge of applicable local, state/province, and federal/national statutes and guidelines.
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Experience with security testing tools and methodologies (SAST, DAST, dependency scanning, API fuzzing, etc.).
- Familiarity with AI security concerns, including prompt injection and jailbreaking resistance.
- Strong understanding of secure coding practices and application risk assessment.
- Effective communication and collaboration skills for working with cross-functional teams and external partners.
- Ability to develop and maintain technical documentation, policy standards, and runbooks.
- Proven experience (5 years) as an IT Security Analyst or similar role, with a focus on application security, Azure Active Directory, conditional access policies, and single sign-on (SSO) configurations.
- Ability to effectively adapt to rapidly changing technology and apply it to business needs.
- Demonstrated strong technical and non-technical communication skills, both oral and written.
- Strong team-oriented interpersonal skills.
- Proficiency in scripting or programming languages (e.g., Python, JavaScript, Java) is a plus.
- Excellent communication skills to convey complex technical concepts to non-technical stakeholders.
- Strong problem-solving skills.
- Strong organizational skills and attention to detail, especially concerning note-taking when evaluating applications and attending meetings.
- Organize and prioritize a variety of projects and multiple tasks in an effective and timely manner, set priorities, and meet deadlines.
Benefits
Fluor is proud to offer a comprehensive benefits package designed to promote employee health, wellness, and financial security. Our offerings include medical, dental and vision plans, EAP, disability coverage, life insurance, AD&D, voluntary benefit plans, 401(k) with a company match, paid time off (personal, bereavement, sick, holidays) for salaried employees, paid sick leave per state requirement for craft employees, parental leave, and training and development courses.
IT Operations Specialist I - AppSec DevSecOps in Farnborough employer: Fluor Corp
Contact Detail:
Fluor Corp Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land IT Operations Specialist I - AppSec DevSecOps in Farnborough
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to AppSec and DevSecOps. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common security scenarios and challenges. Be ready to discuss your experience with SAST, DAST, and AI security concerns. Practice makes perfect, so consider mock interviews with friends or mentors.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace IT Operations Specialist I - AppSec DevSecOps in Farnborough
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with security testing tools and methodologies. We want to see how your skills align with the AppSec and DevSecOps focus of the role!
Show Off Your Communication Skills: Since you'll be working with various teams, it's crucial to demonstrate your ability to communicate complex technical concepts clearly. Use examples in your application that showcase your collaboration with cross-functional teams.
Highlight Relevant Experience: Don’t forget to mention any hands-on experience you have with AI security concerns, secure coding practices, and risk assessments. We love seeing candidates who can bring practical knowledge to the table!
Apply Through Our Website: We encourage you to submit your application through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any updates!
How to prepare for a job interview at Fluor Corp
✨Know Your Security Testing Tools
Make sure you’re familiar with the security testing tools mentioned in the job description, like SAST and DAST. Brush up on how they work and be ready to discuss your experience using them. This shows you’re not just a theoretical expert but someone who can apply this knowledge practically.
✨Understand AI Security Concerns
Since the role focuses on AI-driven solutions, it’s crucial to understand specific security issues like prompt injection and jailbreaking resistance. Prepare examples of how you’ve tackled these challenges in the past or how you would approach them. This will demonstrate your proactive mindset and technical expertise.
✨Communicate Clearly and Effectively
You’ll need to communicate complex technical concepts to various stakeholders. Practice explaining your past projects and security assessments in simple terms. This will help you stand out as someone who can bridge the gap between technical and non-technical teams.
✨Showcase Your Problem-Solving Skills
Be prepared to discuss specific instances where you identified vulnerabilities and implemented solutions. Use the STAR method (Situation, Task, Action, Result) to structure your answers. This will highlight your analytical skills and ability to think critically under pressure.