Cybersecurity Security Engineer /Tester

Categoría: Ciberseguridad
Ubicación principal: United States, Virginia, Fairfax
ID de Posición: J0822-1429
Tipo de empleo: Jornada Completa

Conoce a nuestros profesionales

CGI USA - Best version of me

Descripción de la publicación:

CGI Federal’s Enterprise Solutions Group (ESG) seeks a highly-motivated Application Security Engineer to join their Cyber Security team. The candidate will join a multi-disciplinary team of security specialists, engineers, project managers and delivery professionals responsible for supporting a CMS Healthcare Marketplace system and potentially other CMS and non-CMS contracts.

Sus futuros deberes y responsabilidades:

1. Application security testing techniques, using automated tools and manual testing
2. Creation of exploit proofs of concept
3. Discovery of application security weaknesses, and writing recommendations for preventing or fixing them
4. Analyze and Respond to vulnerability inquiries and vulnerability reports
5. Research and implement new threats and attack vectors that impact web applications and infrastructure
6. Assess new and existing applications and system deployments for vulnerabilities and design flaws, and prioritize remediation efforts based on risk level
7. Hands-on experience with one or more tools like BurpSuite, Snyk, OWASP ZAP, Fortify, Checkmarx, Nessus, Kubernetes is desired
8. Be able to adjust to working in a fast pace environment, multitask and switch between priorities
9. Be able to learn new technologies, security trends and help build new capabilities and services
10. Support and consult with product and development teams in the area of application security
1. Serve as subject matter expert for secure coding practices, penetration testing, mobile platform security and all aspects of application and product security
11. Collaborate with team members on a daily basis, while working on the same projects
12. Follow team’s established processes and procedures, adhere to due dates and deliverable
13. Deliver high quality work at all the time
14. Support DevSecOps activities, which include but not limited to:
o Consultation pertaining to the implementation/enhancement of SAFe DevOps strategies (certification will be given preference)
o Research and benchmarking of technologies used in CI/CD pipeline
o Automation of security processes related to the CI/CD pipeline
o Integration of new technologies
o Documentation of processes and procedures

Calificaciones requeridas para tener éxito en este rol:

1. Application development or security experience will be required to perform the role well
2. Knowledge of secure development principles for both Java or .NET development solutions
3. Experience with OWASP static/dynamic application security analysis and common security tools
4. Excellent and professional communication skills (written and verbal) with ability to articulate complex topics in clear and concise matter
5. Minimum 2 years of experience in system development in technologies like Java, JavaScript, Angular JS, Python, Ruby, .Net, etc.
6. Strong knowledge of security-related best programming practices for J2EE and .NET
7. Experience designing and executing web application security evaluations, solo and as part of a team
8. Knowledge of the SDLC and experience working with development teams (waterfall, Agile, etc.)
9. One or more certifications like CISSP, CEH, Security +, OSCP desired
10. Ability to document and explain risks and vulnerabilities to technical and non-technical stakeholders
11. Knowledge of Microservices and Container Technology such as Kubernetes, Docker, etc.
12. Understand how to implement best security aspects to the above mentioned technologies.



  • Gestión de vulnerabilidades (IAVM)

¿Qué esperas de nosotros?:

Insights you can act on

While technology is at the heart of our clients’ digital transformation, we understand that people are at the heart of business success.

When you join CGI, you become a trusted advisor, collaborating with colleagues and clients to bring forward actionable insights that deliver meaningful and sustainable outcomes. We call our employees “members” because they are CGI shareholders and owners and owners who enjoy working and growing together to build a company we are proud of. This has been our Dream since 1976, and it has brought us to where we are today — one of the world’s largest independent providers of IT and business consulting services.

At CGI, we recognize the richness that diversity brings. We strive to create a work culture where all belong and collaborate with clients in building more inclusive communities. As an equal-opportunity employer, we want to empower all our members to succeed and grow. If you require an accommodation at any point during the recruitment process, please let us know. We will be happy to assist.

Ready to become part of our success story? Join CGI — where your ideas and actions make a difference.

Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, pregnancy, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status, political affiliation, genetic information, or any other legally protected status or characteristics.

CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at You will need to reference the requisition number of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a requisition number will not be returned.

We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members.

All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.

CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI’s legal duty to furnish information.