At a Glance
- Tasks: Ensure the security of code development processes and applications, focusing on AI-driven solutions.
- Company: Fluor, a leading government contractor with a collaborative culture.
- Benefits: Comprehensive benefits package including health plans, 401(k) match, and paid time off.
- Other info: Dynamic work environment with opportunities for professional growth.
- Why this job: Join a team that builds innovative solutions and makes a real-world impact.
- Qualifications: Degree in relevant field and experience in application security testing.
The predicted salary is between 50000 - 60000 € per year.
At Fluor, we are proud to design and build projects and careers. We are committed to fostering a welcoming and collaborative work environment that encourages big‑picture thinking, brings out the best in our employees, and helps us develop innovative solutions that contribute to building a better world together. If this sounds like a culture you would like to work in, you’re invited to apply for this role. Fluor is a leading government contractor with a proven track record of delivering high‑value technical solutions around the world to U.S. government agencies such as the DOE, NNSA, the Department of Defense and the Intelligence Community.
The AppSec / DevSecOps Engineer is responsible for ensuring the security of code development processes and applications, with a focus on both traditional and AI‑driven solutions. This position will work closely with internal IT teams, internal customers, and external vendors, contributing to robust security practices and risk management across the organization.
- Define and implement security testing strategies for AI solutions, utilizing both grey box and black box methodologies.
- Conduct Static Application Security Testing (SAST), dependency scanning, secrets scanning, Infrastructure as Code (IaC) scanning, and configuration reviews.
- Perform Dynamic Application Security Testing (DAST), API fuzzing, authentication testing, and rate‑limit tests.
- Execute prompt injection checks, jailbreaking resistance assessments, tool misuse evaluations, and leakage tests tailored for AI applications.
- Review remediation efforts and verify fixes prior to production deployment.
- Conduct thorough risk assessments of new and existing applications, identifying vulnerabilities and security gaps.
- Analyze and interpret security assessment findings, providing actionable recommendations to mitigate risks.
- Collaborate with software development teams to implement security best practices and ensure secure coding standards.
- Stay current with emerging threats, vulnerabilities, and industry trends, integrating this knowledge into risk assessment processes.
- Participate in security reviews to evaluate and validate the effectiveness of security controls.
- Provide technical guidance and support for incident response efforts related to application security incidents.
- Review and validate contracts, Statements of Work (SOW), and Data Processing Agreements (DPAs).
- Develop and maintain Data Loss Prevention (DLP) policy standards, reusable templates, naming conventions, and engineering runbooks.
Basic Job Requirements
- Accredited four (4) year degree or global equivalent in applicable field of study and five (5) years of work‑related experience or a combination of education and directly related experience equal to nine (9) years if non‑degreed; some locations may have additional or different qualifications in order to comply with local requirements.
- Ability to communicate effectively with audiences that include but are not limited to management, coworkers, clients, vendors, contractors, and visitors.
- Job related technical knowledge necessary to complete the job.
- Ability to learn and apply knowledge of applicable local, state/province, and federal/national statutes and guidelines.
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- Experience with security testing tools and methodologies (SAST, DAST, dependency scanning, API fuzzing, etc.).
- Familiarity with AI security concerns, including prompt injection and jailbreaking resistance.
- Strong understanding of secure coding practices and application risk assessment.
- Effective communication and collaboration skills for working with cross‑functional teams and external partners.
- Ability to develop and maintain technical documentation, policy standards, and runbooks.
- Proven experience (5 years) as an IT Security Analyst or similar role, with a focus on application security, Azure Active Directory, conditional access policies, and single sign‑on (SSO) configurations.
- Ability to effectively adapt to rapidly changing technology and apply it to business needs.
- Demonstrated strong technical and non‑technical communication skills, both oral and written.
- Strong team‑oriented interpersonal skills.
- Proficiency in scripting or programming languages (e.g., Python, JavaScript, Java) is a plus.
- Excellent communication skills to convey complex technical concepts to non‑technical stakeholders.
- Strong problem‑solving skills.
- Strong organizational skills and attention to detail, especially concerning note taking when evaluating applications and attending meetings.
- Organize and prioritize a variety of projects and multiple tasks in an effective and timely manner, set priorities, and meet deadlines.
We are an equal opportunity employer. All qualified individuals will receive consideration for employment without regard to race, color, age, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, genetic information, or any other criteria protected by governing law.
Benefits Statement
Fluor is proud to offer a comprehensive benefits package designed to promote employee health, wellness, and financial security. Our offerings include medical, dental and vision plans, EAP, disability coverage, life insurance, AD&D, voluntary benefit plans, 401(k) with a company match, paid time off (personal, bereavement, sick, holidays) for salaried employees, paid sick leave per state requirement for craft employees, parental leave, and training and development courses.
Market Rate Statement
The market rate for the role is typically at the mid‑point of the salary range; however, variations in final salary are determined by additional factors such as the candidate’s qualifications, relevant years of experience, geographic location, internal pay equity, and prevailing market conditions for the specific role.
Notice to Candidates
Background checks are carried out as part of any conditional offer made, including (but not limited to role dependent) education, professional registration, employment, references, passport verifications and Global Watchlist screening.
To be Considered Candidates Must be authorized to work in the country where the position is located.
IT Operations Specialist I - AppSec DevSecOps in Farnborough employer: Fluor Corporation
Fluor is an exceptional employer that prioritises a collaborative and innovative work culture, making it an ideal place for IT Operations Specialists looking to make a meaningful impact. With a comprehensive benefits package that includes health, wellness, and financial security, alongside ample opportunities for professional growth and development, employees are empowered to thrive in their careers while contributing to high-value projects for government agencies. Located in a dynamic environment, Fluor fosters a sense of community and encourages big-picture thinking, ensuring that every team member feels valued and engaged.
StudySmarter Expert Advice🤫
We think this is how you could land IT Operations Specialist I - AppSec DevSecOps in Farnborough
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their projects and values, especially around security practices. This will help you tailor your answers and show that you're genuinely interested in being part of their team.
✨Tip Number 3
Practice your technical skills! Brush up on your knowledge of security testing tools and methodologies. Being able to discuss your experience with SAST, DAST, and AI security concerns will set you apart from other candidates.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re serious about joining the team at Fluor and contributing to their mission.
We think you need these skills to ace IT Operations Specialist I - AppSec DevSecOps in Farnborough
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your relevant experience in AppSec and DevSecOps. We want to see how your skills align with the job description, so don’t hold back on showcasing your expertise!
Show Off Your Technical Skills:Since this role is all about security testing and coding practices, be sure to mention any specific tools or methodologies you’ve used. Whether it’s SAST, DAST, or something else, we love seeing your hands-on experience!
Communicate Clearly:Effective communication is key in this role, so make sure your application reflects that. Use clear language and structure your thoughts well. We want to know you can convey complex ideas simply, especially when working with cross-functional teams.
Apply Through Our Website:We encourage you to apply directly through our website for a smoother process. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!
How to prepare for a job interview at Fluor Corporation
✨Know Your Stuff
Make sure you brush up on your knowledge of security testing tools and methodologies like SAST, DAST, and API fuzzing. Be ready to discuss how you've applied these in past roles, especially in relation to AI security concerns.
✨Show Your Problem-Solving Skills
Prepare to share specific examples of how you've tackled security vulnerabilities or implemented secure coding practices. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your problem-solving abilities.
✨Communicate Clearly
Since this role involves collaboration with various teams, practice explaining complex technical concepts in simple terms. Think about how you would convey your ideas to non-technical stakeholders and be ready to demonstrate your effective communication skills.
✨Stay Current
Keep yourself updated on the latest trends and emerging threats in application security. Bring up any recent developments during your interview to show that you're proactive and engaged in the field.