Miami-Fort Lauderdale Area
Different LLM models to assist with code review, threat models... Internal tools (Docker Containers, Python, Bash) Threat Model assessment (STRIDE) Code Review (Java, NodeJs, JavaScript, React..) Pen-Testing (Burp Suite, Android Studio) Deep Security Reviews (IntelliJ IDEA) Snyk/Semgrep
Incorporate security tools/tasks into automated product development and deployment lifecycle (SAST/DAST) integration into CI/CD pipeline) Provide expert knowledge and guidance to the product development teams about security vulnerabilities and applicable remediation paths Serve as a critical resource to ensuring each DFIN product is developed in alignment with industry-leading Secure Product/Software Development standards Provide security insights to vulnerability scan/pen test results Perform architectural risk analysis, threat modeling, secure design and source code review Use SAST/DAST tools such as Checkmarx, Rapid7, Core Impact...
Certify internal network tools (Checkpoint, Palo Alto, Cisco ISE, Arcsight, Menlo, Proxy SG, Pulse Secure, Cisco Firepower, Splunk) Integrate internal network tools with (SMART, HPNA, InfoVista) Automate and integrate internal tools using Python, Perl, Javascript, BASH Troubleshooting of the infrastructure, develop and support monitoring tools,
- ServiceNow SecOps Integrations, playbooks - Administration, Troubleshoot, and Installation of CyberArk security components, APIs, - Tenable Vulnerability Management - Writing scripts to automate internal processes (Python, Powershell, Bash) - LogRhythm, Cylance, OAV, IDERA, Proofpoint, Palo Alto
- Perform extensive internal and external penetration testing - Vulnerability assessments - Web-based applications penetration testing using OWASP Top 10 standards - PCI DSS audits, GLBA risk assessments, FFIEC cybersecurity assessments - Configuration reviews (Firewall, Switch, Router, Windows and Linux servers) - Computer forensics - Malware reverse engineering - Wifi penetration testing - Social Engineering assessments (Development of a phishing website)