Senior Vulnerability Code Analyst
6AM City
Job Description Job Description POSITION SUMMARY: CODICE seeks a highly skilled Senior Vulnerability Code Analyst specializing in Ruby-on-Rails to join our team. This role is critical in ensuring the security of our client’s platforms by performing thorough vulnerability code analysis prior to the deployment of every change. The ideal candidate will possess deep technical expertise in both Ruby on Rails and security practices, including extensive experience in code analysis and secure coding principles. ESSENTIAL FUNCTIONS Duties and Responsibilities Conduct vulnerability code analysis on the client’s platforms, with a focus on Ruby-on-Rails applications. Perform security assessments prior to the deployment of every code change. Utilize static and dynamic code analysis tools to identify potential vulnerabilities and security risks. Conduct threat modeling and risk assessments for new and existing applications. Work closely with development teams to remediate identified vulnerabilities and implement secure coding practices. Provide guidance and mentorship on secure coding principles and best practices. Stay current with emerging security threats and vulnerabilities, particularly those affecting Ruby-on-Rails applications. Collaborate with the CISO and other security team members to enhance overall application security posture. Develop and maintain security standards and guidelines for Ruby-on-Rails development. Participate in the software development lifecycle to ensure security is integrated at every stage. Conduct code reviews with a security focus and provide actionable feedback to developers. Assist in the selection and implementation of appropriate security tools and technologies. Contribute to the development of security policies and procedures related to application security. Prepare detailed reports on vulnerability assessments and remediation recommendations. Knowledge, Skills and Abilities o Coding Languages Ruby Demonstrated expert-level proficiency in Ruby programming language In-depth understanding of Ruby on Rails framework and its security implications Experience with Ruby version management tools (e.g., RVM, rbenv) Familiarity with Ruby testing frameworks (e.g., RSpec, Minitest) Additional Languages Demonstrated familiarity with at least one of the following: PHP: Understanding of common PHP frameworks and their security considerations Bash: Ability to write and analyze shell scripts for potential vulnerabilities PowerShell: Knowledge of PowerShell scripting and its security implications in Windows environments Python: Familiarity with Python scripting, especially in the context of security tools and automation o Code Analysis Tools Static Analysis Tools Demonstrated expertise with tools such as: Fortify: Ability to configure, run, and interpret results from Fortify static code analysis Checkmarx: Experience with Checkmarx SAST and its integration into CI/CD pipelines Veracode: Proficiency in using Veracode's static analysis capabilities SonarQube: Skill in setting up and managing SonarQube for continuous code quality and security checks o Dynamic Analysis Tools Demonstrated expertise with tools such as: Burp Suite: Advanced knowledge of using Burp Suite for web application security testing OWASP ZAP: Experience in configuring and using ZAP for automated and manual security testing o Fuzzing Tools and Techniques Familiarity with fuzzing concepts and tools Experience with tools like AFL (American Fuzzy Lop) or libFuzzer Understanding of how to integrate fuzzing into the development and testing process o Security Technologies and Concepts Vulnerability Knowledge Demonstrated expert knowledge of common cyber security vulnerabilities, including: In-depth understanding of the OWASP Top Ten and how they apply to Ruby on Rails applications Comprehensive knowledge of the CWE/SANS Top 25 Most Dangerous Software Errors Ability to identify and explain less common vulnerabilities specific to Ruby on Rails Attack Vectors Understanding of various attack methodologies used against web applications Knowledge of how these attacks can be executed and mitigated in a Ruby on Rails environment Secure Coding Practices In-depth knowledge of secure coding practices for Ruby on Rails Understanding of input validation, output encoding, and other security controls specific to web applications Familiarity with Ruby on Rails security features and best practices SDLC Security Comprehensive understanding of how to integrate security into each phase of the Software Development Life Cycle Experience with security practices in Agile and DevOps environments o Vulnerability Management Threat Modeling Experience with threat modeling methodologies (e.g., STRIDE, DREAD) Ability to create and analyze threat models for Ruby on Rails applications Skill in identifying potential threats and proposing appropriate mitigations Risk Assessment Proficiency in conducting risk assessments for web applications Ability to prioritize vulnerabilities based on their potential impact and likelihood Experience in using risk assessment frameworks and methodologies Remediation Process Management Proven experience in managing the vulnerability remediation process Ability to work effectively with development teams to ensure timely fix of security issues Experience in tracking and reporting on remediation progress Skill in providing clear, actionable guidance for addressing identified vulnerabilities QUALIFICATIONS Required Education: Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related field Required Experience: § Minimum of 5 years of experience in application security, with a specific focus on Ruby on Rails applications § Demonstrated track record of identifying and mitigating security vulnerabilities in complex web applications § Experience working in an Agile development environment and integrating security into CI/CD pipelines § History of successful collaboration with development teams to implement security best practices § Strong analytical and problem-solving skills with attention to detail § Excellent communication skills (both written and verbal) for explaining complex security concepts to various stakeholders § Ability to work effectively in a team environment § Self-motivated with a passion for continuous learning in the rapidly evolving field of application security Preferred Education: Advanced degree (Master's or Ph.D.) in a relevant field is a plus Preferred Licensure/ Certification: Offensive Security Certified Professional (OSCP) Demonstrates hands-on ability to identify and exploit vulnerabilities Indicates a strong understanding of offensive security techniques GIAC Web Application Penetration Tester (GWAPT) Shows specialized knowledge in web application security testing Indicates proficiency in identifying and exploiting web application vulnerabilities Certified Secure Software Lifecycle Professional (CSSLP) Demonstrates comprehensive knowledge of secure software development practices Indicates understanding of security considerations throughout the entire software lifecycle Company Description CODICE provides innovative solutions in health information management for the full lifecycle of healthcare finance and compliance operations. Our customized knowledge-based software helps manage healthcare costs. At the heart of CODICE services are our technology competencies. Paired with our unparalleled process methods, these competencies deliver solutions and results that become an integral part of our clients success. CODICE's technical expertise can be leveraged for full system development, project management or staff augmentation. CODICE areas of expertise include: SYSTEM DEVELOPMENT: Fully customized development from requirements to testing. ENTERPRISE CONTENT MANAGEMENT: System implementations for content management, digital assets, web content and record keeping. SYSTEM INTEGRATION: Expert integrations using open standards, APIs, and a comprehensive toolkit to seamlessly link applications. DATA WAREHOUSING & BUSINESS INTELLIGENCE: Data collection and analysis from multiple sources into a single access point portal that provides tools for key business functions. Company Description CODICE provides innovative solutions in health information management for the full lifecycle of healthcare finance and compliance operations. Our customized knowledge-based software helps manage healthcare costs. At the heart of CODICE services are our technology competencies. Paired with our unparalleled process methods, these competencies deliver solutions and results that become an integral part of our clients success. CODICE's technical expertise can be leveraged for full system development, project management or staff augmentation. CODICE areas of expertise include: SYSTEM DEVELOPMENT: Fully customized development from requirements to testing. ENTERPRISE CONTENT MANAGEMENT: System implementations for content management, digital assets, web content and record keeping. SYSTEM INTEGRATION: Expert integrations using open standards, APIs, and a comprehensive toolkit to seamlessly link applications. DATA WAREHOUSING & BUSINESS INTELLIGENCE: Data collection and analysis from multiple sources into a single access point portal that provides tools for key business functions. #J-18808-Ljbffr
- ...A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...Senior
$107.9k - $195.05k
Leidos is seeking an experienced Vulnerability Assessor to enhance cybersecurity capabilities for our customers. Responsibilities include conducting vulnerability scans, collaborating on solutions, and performing assessments using Nessus technologies. The ideal candidate...Senior- Booz Allen Hamilton is seeking a Vulnerability Assessment Analyst to support the Army by identifying and reporting security vulnerabilities. This role involves performing vulnerability scans and analyzing results to track remediation progress. The ideal candidate will...SeniorRemote job
$107.9k - $195.05k
A leading technology firm seeks an experienced Vulnerability Assessor in Arlington, VA. The role involves assessing and managing vulnerabilities, configuring security scans, and collaborating with teams to enhance cybersecurity capabilities. The ideal candidate should have...Senior- Booz Allen Hamilton is seeking a Vulnerability Assessment Analyst in Alexandria, Virginia. You will support the Army by delivering high-quality cybersecurity services, identify and report vulnerabilities, perform scans, and recommend remediation actions to ensure system...Senior
$140.5k - $210k
...of audiences ranging from non-technical senior leaders to highly technical subject matter... ...remediation. Oversees implementation of vulnerability scans and ensures operational systems... ...of vulnerabilities and proof of concept code as it becomes available to assess the technical...SeniorFull timeWork at office- ...Senior Penetration Tester Job Description Overview CoStar Group is a leading... ...developing test plans to validate identified vulnerabilities and demonstrate the exploitation of the... ...that address root causes, including code changes, architectural improvements, and...SeniorFull timeWork at officeWork from homeMonday to Thursday
- ...methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. Design and deploy risk-... ...Windows and Unix-like Operating Systems Experience in source code review and/or building software with multiple programming languages...SeniorWorldwide
$53k - $57k
...Howard University is seeking a Senior Coding Specialist for their Faculty Practice Plan in Washington, DC. The role involves ensuring accurate coding for diverse specialties, compliance with billing regulations, and mentorship of junior coders. Ideal candidates have over...Senior$86.8k - $198k
...Tester to enhance the security of critical digital environments. Your role will involve conducting thorough penetration testing, vulnerability assessments, and implementing risk mitigation strategies. Candidates should have at least 3 years of experience in cyber...Senior- ...Maximus is seeking a Senior Medical Billing and Coding Coordinator for a fully remote position to support our California Independent Medical Review project. Candidates should thrive in remote environments and possess strong analytical skills. This role involves auditing...SeniorRemote work
- ...Datavant is seeking a Client Coding Project Manager in Washington, D.C., to oversee risk adjustment coding audits and ensure compliance across operations. You'll be responsible for monitoring performance, educating staff, and maintaining high-quality standards in coding...Senior
- Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime contractor... ..., and provide expert analysis to senior customer stakeholders. Eligibility Must... ...vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and...For contractors
$50 - $150 per hour
A leading AI company in Washington is seeking a Mid-Senior Level Software Engineer for a contract role. This position involves improving... ...engineering tasks, leading various projects, and ensuring code quality. Candidates should have several years of software engineering...SeniorHourly payContract work- ...customer to provide cybersecurity vulnerability analysis support to reduce... ...Cybersecurity Vulnerability Analyst utilizes cybersecurity best... ...and provide expert analysis to senior customer stakeholders.... ....g., buffer overflow, mobile code, cross-site scripting, PL/SQL...
$22.33 - $36.86 per hour
Johns Hopkins Medicine is seeking a Coding Specialist in Washington DC. This role involves all aspects of coding, provider education, and quality assurance in compliance with Federal guidelines. The ideal candidate will have at least five years of coding experience and...SeniorRemote jobHourly pay- WSP is seeking a Senior Fire Protection Consultant to lead fire protection solutions in Arlington, VA. This role demands extensive expertise in building and fire codes, mentoring, and ensuring the highest standards of safety across diverse projects. The ideal candidate...Senior
$131.3k - $237.35k
Koitecc Solutions in Alexandria, Virginia is seeking a skilled SME Penetration Testing Analyst with active TS/SCI clearance and a strong background in cybersecurity. The role involves conducting and coordinating penetration tests, collaborating with DoD organizations, and...Senior- A cybersecurity service provider is seeking a Penetration Tester to support authorized penetration testing and security assessments. Responsibilities include executing tests, documenting findings, and verifying remediation. Candidates must hold a BS/BA degree and have 5...Senior
- ...Offensive Security & Code Analysis Engineer Washington, DC Remote Full-Time About This Role As an Offensive Security & Code Analysis Engineer, you will identify vulnerabilities before attackers do. You will conduct penetration testing, code reviews, and security assessments...Full timeRemote work
$53k - $57k
...Wellness programs, commuter benefits, and a vibrant company culture BASIC FUNCTION The Howard University Faculty Practice Plan Senior Coding Specialist is responsible for accurate and timely assignment of CPT, HCPCS, ICD-10-CM, and modifiers for professional services rendered...SeniorFlexible hours$110k - $170k
...Technologies (IDT), a leading defense technology company, is seeking a Senior Information System Security Officer (ISSO) to be part of our... ...Industrial Security Program Operating Manual (NISPOM), The 32 Code of Federal Regulations Part 117 and Defense Counterintelligence...SeniorFull timeWork at officeImmediate start- ...acceptable risk tolerance. • Evaluate newly identified threats and vulnerabilities to customer information systems to ascertain the need for... ...principles, secure design, secure architecture, and secure coding techniques. • Keep abreast of current and new security...SeniorFor contractorsWork at office
- ...Senior Security Engineer We are seeking a Senior Security Engineer to strengthen cloud... ...Automate security processes, conduct vulnerability scanning, penetration testing, and continuous... ..., and Python scripting (ability to read code). Regulatory Frameworks: Deep...Senior
- ...JRAD is seeking candidates for a Senior Level Software Tester position responsible for executing test cases, identifying defects, documenting... ...strong problem-solving skills, writes clean and maintainable code, and leads system testing / quality assurance / verification &...SeniorFull timeContract workRemote workFlexible hours
$70 - $85 per hour
A trusted staffing and consulting firm seeks an Intrusion Analyst to support federal law enforcement with advanced digital forensic investigations. The role involves detailed forensic analysis, evidence preservation, and expert testimony. Candidates should have a minimum...SeniorHourly payRemote work$88k
...Description IT Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect when you join Sikich... ...alternative practice structure in accordance with the AICPA Professional Code of Conduct and applicable law, regulations, and professional...SeniorFull timeContract workInterim roleWork at officeLocal areaFlexible hours- ...gray/black box testing, red teaming, API testing, and DevSecOps code reviews. Develop and execute SBA’s enterprise penetration... ...Persistent Threat (APT) tactics. Provide source code analysis, vulnerability scanning, phishing simulations, and exploitation assessments....SeniorLocal areaRemote work
$107k
...Description IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect when you join Sikich... ...practice structure in accordance with the AICPA Professional Code of Conduct and applicable law, regulations, and professional...SeniorFull timeWork experience placementInterim roleInternshipWork at officeLocal areaFlexible hours- ...Systems Interoperability Tester, Senior Category: Architecture Main location: United States, Virginia, Arlington Position ID:J0925-2138 Employment Type: Full Time Position Description: CGI Federal has an exciting opportunity for...SeniorFull timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Vulnerability Code Analyst. Be the first to apply!
- penetration tester Washington DC
- ethical hacker Washington DC
- vulnerability analyst Washington DC
- senior automation controls engineer Washington DC
- senior accounts payable Washington DC
- senior brand designer Washington DC
- senior financial advisor Washington DC
- senior underwriter Washington DC
- senior cost analyst Washington DC
- senior business analyst contract Washington DC

