Engr Iii-security Engrg

Verizon Verizon · Telecom · Hyderabad, India +1

Security Engineer role focused on Dynamic Application Security Testing (DAST) and integrating security into the SDLC. Requires strong Java development experience and expertise in DAST tools and methodologies. Responsibilities include strategy, tool management, scanning, analysis, automation, vulnerability remediation, code review, and training.

What you'd actually do

  1. Defining, implementing, and continuously mature the organization's DAST strategy, integrating automated scanning into CI/CD pipelines (e.g., Jenkins, GitLab CI).
  2. Selecting, configuring, managing, and maintaining DAST solutions (e.g., OWASP ZAP, Burp Suite Enterprise, or commercial tools like Tenable WAS).
  3. Performing comprehensive DAST scans on web applications, APIs, and microservices, analyzing results for false positives and reporting actionable vulnerabilities.
  4. Developing custom scripts and automation (using Python, Java, or Shell) to enhance DAST coverage, automate testing scenarios, and integrate DAST output with defect tracking systems (e.g., Jira).
  5. Partnering directly with development teams to explain vulnerability root causes, provide secure coding examples, and guide them through the remediation process.

Skills

Required

  • DAST Expertise
  • Java Development
  • Web Technologies
  • Vulnerability Knowledge
  • CI/CD
  • Cloud

Nice to have

  • Good communication and presentation skills
  • Relevant industry certifications (e.g: CSSLP, OSCP, eJPT )
  • Experience with other security testing methodologies (SAST, IAST, Penetration Testing)
  • Familiarity with containerization and orchestration technologies (Docker, Kubernetes)

What the JD emphasized

  • DAST Expertise
  • Java Development
  • DAST tools
  • Java application behavior