Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Vulnerability Code Analyst

6AM City

Job Description Job Description POSITION SUMMARY: CODICE seeks a highly skilled Senior Vulnerability Code Analyst specializing in Ruby-on-Rails to join our team. This role is critical in ensuring the security of our client’s platforms by performing thorough vulnerability code analysis prior to the deployment of every change. The ideal candidate will possess deep technical expertise in both Ruby on Rails and security practices, including extensive experience in code analysis and secure coding principles. ESSENTIAL FUNCTIONS Duties and Responsibilities Conduct vulnerability code analysis on the client’s platforms, with a focus on Ruby-on-Rails applications. Perform security assessments prior to the deployment of every code change. Utilize static and dynamic code analysis tools to identify potential vulnerabilities and security risks. Conduct threat modeling and risk assessments for new and existing applications. Work closely with development teams to remediate identified vulnerabilities and implement secure coding practices. Provide guidance and mentorship on secure coding principles and best practices. Stay current with emerging security threats and vulnerabilities, particularly those affecting Ruby-on-Rails applications. Collaborate with the CISO and other security team members to enhance overall application security posture. Develop and maintain security standards and guidelines for Ruby-on-Rails development. Participate in the software development lifecycle to ensure security is integrated at every stage. Conduct code reviews with a security focus and provide actionable feedback to developers. Assist in the selection and implementation of appropriate security tools and technologies. Contribute to the development of security policies and procedures related to application security. Prepare detailed reports on vulnerability assessments and remediation recommendations. Knowledge, Skills and Abilities o Coding Languages Ruby Demonstrated expert-level proficiency in Ruby programming language In-depth understanding of Ruby on Rails framework and its security implications Experience with Ruby version management tools (e.g., RVM, rbenv) Familiarity with Ruby testing frameworks (e.g., RSpec, Minitest) Additional Languages Demonstrated familiarity with at least one of the following: PHP: Understanding of common PHP frameworks and their security considerations Bash: Ability to write and analyze shell scripts for potential vulnerabilities PowerShell: Knowledge of PowerShell scripting and its security implications in Windows environments Python: Familiarity with Python scripting, especially in the context of security tools and automation o Code Analysis Tools Static Analysis Tools Demonstrated expertise with tools such as: Fortify: Ability to configure, run, and interpret results from Fortify static code analysis Checkmarx: Experience with Checkmarx SAST and its integration into CI/CD pipelines Veracode: Proficiency in using Veracode's static analysis capabilities SonarQube: Skill in setting up and managing SonarQube for continuous code quality and security checks o Dynamic Analysis Tools Demonstrated expertise with tools such as: Burp Suite: Advanced knowledge of using Burp Suite for web application security testing OWASP ZAP: Experience in configuring and using ZAP for automated and manual security testing o Fuzzing Tools and Techniques Familiarity with fuzzing concepts and tools Experience with tools like AFL (American Fuzzy Lop) or libFuzzer Understanding of how to integrate fuzzing into the development and testing process o Security Technologies and Concepts Vulnerability Knowledge Demonstrated expert knowledge of common cyber security vulnerabilities, including: In-depth understanding of the OWASP Top Ten and how they apply to Ruby on Rails applications Comprehensive knowledge of the CWE/SANS Top 25 Most Dangerous Software Errors Ability to identify and explain less common vulnerabilities specific to Ruby on Rails Attack Vectors Understanding of various attack methodologies used against web applications Knowledge of how these attacks can be executed and mitigated in a Ruby on Rails environment Secure Coding Practices In-depth knowledge of secure coding practices for Ruby on Rails Understanding of input validation, output encoding, and other security controls specific to web applications Familiarity with Ruby on Rails security features and best practices SDLC Security Comprehensive understanding of how to integrate security into each phase of the Software Development Life Cycle Experience with security practices in Agile and DevOps environments o Vulnerability Management Threat Modeling Experience with threat modeling methodologies (e.g., STRIDE, DREAD) Ability to create and analyze threat models for Ruby on Rails applications Skill in identifying potential threats and proposing appropriate mitigations Risk Assessment Proficiency in conducting risk assessments for web applications Ability to prioritize vulnerabilities based on their potential impact and likelihood Experience in using risk assessment frameworks and methodologies Remediation Process Management Proven experience in managing the vulnerability remediation process Ability to work effectively with development teams to ensure timely fix of security issues Experience in tracking and reporting on remediation progress Skill in providing clear, actionable guidance for addressing identified vulnerabilities QUALIFICATIONS Required Education: Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related field Required Experience: § Minimum of 5 years of experience in application security, with a specific focus on Ruby on Rails applications § Demonstrated track record of identifying and mitigating security vulnerabilities in complex web applications § Experience working in an Agile development environment and integrating security into CI/CD pipelines § History of successful collaboration with development teams to implement security best practices § Strong analytical and problem-solving skills with attention to detail § Excellent communication skills (both written and verbal) for explaining complex security concepts to various stakeholders § Ability to work effectively in a team environment § Self-motivated with a passion for continuous learning in the rapidly evolving field of application security Preferred Education: Advanced degree (Master's or Ph.D.) in a relevant field is a plus Preferred Licensure/ Certification: Offensive Security Certified Professional (OSCP) Demonstrates hands-on ability to identify and exploit vulnerabilities Indicates a strong understanding of offensive security techniques GIAC Web Application Penetration Tester (GWAPT) Shows specialized knowledge in web application security testing Indicates proficiency in identifying and exploiting web application vulnerabilities Certified Secure Software Lifecycle Professional (CSSLP) Demonstrates comprehensive knowledge of secure software development practices Indicates understanding of security considerations throughout the entire software lifecycle Company Description CODICE provides innovative solutions in health information management for the full lifecycle of healthcare finance and compliance operations. Our customized knowledge-based software helps manage healthcare costs. At the heart of CODICE services are our technology competencies. Paired with our unparalleled process methods, these competencies deliver solutions and results that become an integral part of our clients success. CODICE's technical expertise can be leveraged for full system development, project management or staff augmentation. CODICE areas of expertise include: SYSTEM DEVELOPMENT: Fully customized development from requirements to testing. ENTERPRISE CONTENT MANAGEMENT: System implementations for content management, digital assets, web content and record keeping. SYSTEM INTEGRATION: Expert integrations using open standards, APIs, and a comprehensive toolkit to seamlessly link applications. DATA WAREHOUSING & BUSINESS INTELLIGENCE: Data collection and analysis from multiple sources into a single access point portal that provides tools for key business functions. Company Description CODICE provides innovative solutions in health information management for the full lifecycle of healthcare finance and compliance operations. Our customized knowledge-based software helps manage healthcare costs. At the heart of CODICE services are our technology competencies. Paired with our unparalleled process methods, these competencies deliver solutions and results that become an integral part of our clients success. CODICE's technical expertise can be leveraged for full system development, project management or staff augmentation. CODICE areas of expertise include: SYSTEM DEVELOPMENT: Fully customized development from requirements to testing. ENTERPRISE CONTENT MANAGEMENT: System implementations for content management, digital assets, web content and record keeping. SYSTEM INTEGRATION: Expert integrations using open standards, APIs, and a comprehensive toolkit to seamlessly link applications. DATA WAREHOUSING & BUSINESS INTELLIGENCE: Data collection and analysis from multiple sources into a single access point portal that provides tools for key business functions. #J-18808-Ljbffr

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior Vulnerability Code Analyst in Washington DC vacancy
  •  ...A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit... 
    Senior

    Node.Digital

    Arlington, VA
    4 days ago
  • $107.9k - $195.05k

    Leidos is seeking an experienced Vulnerability Assessor to enhance cybersecurity capabilities for our customers. Responsibilities include conducting vulnerability scans, collaborating on solutions, and performing assessments using Nessus technologies. The ideal candidate... 
    Senior

    Leidos

    Bethesda, MD
    3 days ago
  • Booz Allen Hamilton is seeking a Vulnerability Assessment Analyst to support the Army by identifying and reporting security vulnerabilities. This role involves performing vulnerability scans and analyzing results to track remediation progress. The ideal candidate will... 
    Senior
    Remote job

    Booz Allen Hamilton

    Arlington, VA
    1 day ago
  • $107.9k - $195.05k

    A leading technology firm seeks an experienced Vulnerability Assessor in Arlington, VA. The role involves assessing and managing vulnerabilities, configuring security scans, and collaborating with teams to enhance cybersecurity capabilities. The ideal candidate should have... 
    Senior

    Leidos Inc

    Arlington, VA
    4 days ago
  • Booz Allen Hamilton is seeking a Vulnerability Assessment Analyst in Alexandria, Virginia. You will support the Army by delivering high-quality cybersecurity services, identify and report vulnerabilities, perform scans, and recommend remediation actions to ensure system... 
    Senior

    Booz Allen Hamilton

    Alexandria, VA
    3 days ago
  • $140.5k - $210k

     ...of audiences ranging from non-technical senior leaders to highly technical subject matter...  ...remediation. Oversees implementation of vulnerability scans and ensures operational systems...  ...of vulnerabilities and proof of concept code as it becomes available to assess the technical... 
    Senior
    Full time
    Work at office

    Federal Reserve Board

    Washington DC
    3 days ago
  •  ...Senior Penetration Tester Job Description Overview CoStar Group is a leading...  ...developing test plans to validate identified vulnerabilities and demonstrate the exploitation of the...  ...that address root causes, including code changes, architectural improvements, and... 
    Senior
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Group

    Arlington, VA
    21 hours ago
  •  ...methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. Design and deploy risk-...  ...Windows and Unix-like Operating Systems Experience in source code review and/or building software with multiple programming languages... 
    Senior
    Worldwide

    JPMorgan Chase & Co.

    Washington DC
    1 day ago
  • $53k - $57k

     ...Howard University is seeking a Senior Coding Specialist for their Faculty Practice Plan in Washington, DC. The role involves ensuring accurate coding for diverse specialties, compliance with billing regulations, and mentorship of junior coders. Ideal candidates have over... 
    Senior

    Howard University

    Washington DC
    3 days ago
  • $86.8k - $198k

     ...Tester to enhance the security of critical digital environments. Your role will involve conducting thorough penetration testing, vulnerability assessments, and implementing risk mitigation strategies. Candidates should have at least 3 years of experience in cyber... 
    Senior

    Phase2 Technology

    Alexandria, VA
    1 day ago
  •  ...Maximus is seeking a Senior Medical Billing and Coding Coordinator for a fully remote position to support our California Independent Medical Review project. Candidates should thrive in remote environments and possess strong analytical skills. This role involves auditing... 
    Senior
    Remote work

    MAXIMUS

    Washington DC
    3 days ago
  •  ...Datavant is seeking a Client Coding Project Manager in Washington, D.C., to oversee risk adjustment coding audits and ensure compliance across operations. You'll be responsible for monitoring performance, educating staff, and maintaining high-quality standards in coding... 
    Senior

    Datavant

    Washington DC
    3 days ago
  • Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime contractor...  ..., and provide expert analysis to senior customer stakeholders. Eligibility Must...  ...vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and... 
    For contractors

    kozmetickesluzby.vecnakraska.sk - Jobboard

    Arlington, VA
    3 days ago
  • $50 - $150 per hour

    A leading AI company in Washington is seeking a Mid-Senior Level Software Engineer for a contract role. This position involves improving...  ...engineering tasks, leading various projects, and ensuring code quality. Candidates should have several years of software engineering... 
    Senior
    Hourly pay
    Contract work

    Turing

    Washington DC
    2 days ago
  •  ...customer to provide cybersecurity vulnerability analysis support to reduce...  ...Cybersecurity Vulnerability Analyst utilizes cybersecurity best...  ...and provide expert analysis to senior customer stakeholders....  ....g., buffer overflow, mobile code, cross-site scripting, PL/SQL... 

    Node.Digital

    Arlington, VA
    4 days ago
  • $22.33 - $36.86 per hour

    Johns Hopkins Medicine is seeking a Coding Specialist in Washington DC. This role involves all aspects of coding, provider education, and quality assurance in compliance with Federal guidelines. The ideal candidate will have at least five years of coding experience and... 
    Senior
    Remote job
    Hourly pay

    Johns Hopkins Medicine

    Washington DC
    2 days ago
  • WSP is seeking a Senior Fire Protection Consultant to lead fire protection solutions in Arlington, VA. This role demands extensive expertise in building and fire codes, mentoring, and ensuring the highest standards of safety across diverse projects. The ideal candidate... 
    Senior

    WSP

    Arlington, VA
    4 days ago
  • $131.3k - $237.35k

    Koitecc Solutions in Alexandria, Virginia is seeking a skilled SME Penetration Testing Analyst with active TS/SCI clearance and a strong background in cybersecurity. The role involves conducting and coordinating penetration tests, collaborating with DoD organizations, and... 
    Senior

    Koitecc Solutions

    Alexandria, VA
    3 days ago
  • A cybersecurity service provider is seeking a Penetration Tester to support authorized penetration testing and security assessments. Responsibilities include executing tests, documenting findings, and verifying remediation. Candidates must hold a BS/BA degree and have 5...
    Senior

    Medium

    Alexandria, VA
    3 days ago
  •  ...Offensive Security & Code Analysis Engineer Washington, DC Remote Full-Time About This Role As an Offensive Security & Code Analysis Engineer, you will identify vulnerabilities before attackers do. You will conduct penetration testing, code reviews, and security assessments... 
    Full time
    Remote work

    Districttechgroup

    Washington DC
    4 days ago
  • $53k - $57k

     ...Wellness programs, commuter benefits, and a vibrant company culture BASIC FUNCTION The Howard University Faculty Practice Plan Senior Coding Specialist is responsible for accurate and timely assignment of CPT, HCPCS, ICD-10-CM, and modifiers for professional services rendered... 
    Senior
    Flexible hours

    Howard University

    Washington DC
    1 day ago
  • $110k - $170k

     ...Technologies (IDT), a leading defense technology company, is seeking a Senior Information System Security Officer (ISSO) to be part of our...  ...Industrial Security Program Operating Manual (NISPOM), The 32 Code of Federal Regulations Part 117 and Defense Counterintelligence... 
    Senior
    Full time
    Work at office
    Immediate start

    Innovative Defense Technologies

    Arlington, VA
    21 hours ago
  •  ...acceptable risk tolerance. • Evaluate newly identified threats and vulnerabilities to customer information systems to ascertain the need for...  ...principles, secure design, secure architecture, and secure coding techniques. • Keep abreast of current and new security... 
    Senior
    For contractors
    Work at office

    Modern Technology Solutions Inc

    Washington DC
    2 days ago
  •  ...Senior Security Engineer We are seeking a Senior Security Engineer to strengthen cloud...  ...Automate security processes, conduct vulnerability scanning, penetration testing, and continuous...  ..., and Python scripting (ability to read code). Regulatory Frameworks: Deep... 
    Senior

    Executive Recruiting

    Washington DC
    1 day ago
  •  ...JRAD is seeking candidates for a Senior Level Software Tester position responsible for executing test cases, identifying defects, documenting...  ...strong problem-solving skills, writes clean and maintainable code, and leads system testing / quality assurance / verification &... 
    Senior
    Full time
    Contract work
    Remote work
    Flexible hours

    Joint Research and Development , Inc.

    Arlington, VA
    4 days ago
  • $70 - $85 per hour

    A trusted staffing and consulting firm seeks an Intrusion Analyst to support federal law enforcement with advanced digital forensic investigations. The role involves detailed forensic analysis, evidence preservation, and expert testimony. Candidates should have a minimum... 
    Senior
    Hourly pay
    Remote work

    Seneca

    Washington DC
    4 days ago
  • $88k

     ...Description IT Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect when you join Sikich...  ...alternative practice structure in accordance with the AICPA Professional Code of Conduct and applicable law, regulations, and professional... 
    Senior
    Full time
    Contract work
    Interim role
    Work at office
    Local area
    Flexible hours

    Sikich

    Alexandria, VA
    1 day ago
  •  ...gray/black box testing, red teaming, API testing, and DevSecOps code reviews. Develop and execute SBA’s enterprise penetration...  ...Persistent Threat (APT) tactics. Provide source code analysis, vulnerability scanning, phishing simulations, and exploitation assessments.... 
    Senior
    Local area
    Remote work

    eTelligent Group LLC

    Washington DC
    more than 2 months ago
  • $107k

     ...Description IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect when you join Sikich...  ...practice structure in accordance with the AICPA Professional Code of Conduct and applicable law, regulations, and professional... 
    Senior
    Full time
    Work experience placement
    Interim role
    Internship
    Work at office
    Local area
    Flexible hours

    Sikich

    Alexandria, VA
    21 hours ago
  •  ...Systems Interoperability Tester, Senior Category: Architecture Main location: United States, Virginia, Arlington Position ID:J0925-2138 Employment Type: Full Time Position Description: CGI Federal has an exciting opportunity for... 
    Senior
    Full time
    Local area

    CGI

    Arlington, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Vulnerability Code Analyst. Be the first to apply!