Cloud Threat Intelligence Analyst

Remote Full-time
Title: Application/Cloud Security Engineer - Primarily remote Location: Richmond,VA Length :Long term Restriction: w2 or c2c
Discription: About the role Seeking an Application Security Engineer (ASE) with 5+ years of experience to join the Office of Technology under Joint Security Operations. In this role, the ASE serves as a dedicated security partner to application teams, providing guidance on secure design, vulnerability management, and secure development practices. The ASE works collaboratively across the SDLC to ensure security is embedded into application design, development, testing, and deployment. This includes supporting compliance requirements, delivering training and education, and assisting teams with vulnerability remediation efforts. The successful candidate will identify and recommend improvements to improve the security of all Virginia Tax applications, promote secure coding and development practices, and contribute to ongoing initiatives that reduce risk and strengthen the agency's overall security posture.
Responsibilities Responsibilities include but not limited to Provide security guidance, training, and best practices for development and operations teams. Support secure software development by applying knowledge of SDLC, Agile, and Scrum methodologies. Evaluate software architecture and design for security risks and alignment with DevSecOps principles. Promote and enforce secure coding standards and guidelines. Review source code to identify vulnerabilities and recommend remediation strategies. Assess security risks across multiple programming languages (e.g., JavaScript, C#, Java, Ruby, SQL). Analyze and secure modern web application architectures, including cloud, APIs, microservices, and client server models. Identify and address common vulnerabilities, including those outlined in the OWASP Top 10. Support vulnerability remediation, patch management, and continuous improvement efforts. Utilize application security testing tools such as SAST, DAST, IAST, and platforms like Accunetix, Veracode, Jenkins, Splunk, Rapid7, and Tenable. Interpret and act on findings from SIEM systems, including Splunk. Apply knowledge of common security controls and frameworks. Ensure compliance with relevant security regulations and standards (e.g., NIST 800 53, IRS Pub 1075, PCI DSS). Implement and evaluate AWS cloud security controls and best practices. Create, maintain, and review System Security Plans (SSPs). Troubleshoot and resolve complex technical and security-related issues. Stay current with evolving threats, technologies, and industry trends. Develop detailed plans and communicate risks, impacts, and recommendations effectively. Collaborate with application teams, QA engineers, and operations teams to integrate security into workflows. Provide constructive, actionable feedback to application teams. Communicate technical concepts clearly to both technical and non technical audiences. Work closely with other security analysts and technology teams to support agency and enterprise security initiatives. Manage multiple tasks, prioritize effectively, and meet deadlines. Apply critical thinking to evaluate and mitigate security risks and vulnerabilities.
Required Skills/Experience Five or more years' experience in application security. Two or more years' network or firewall/AWS Security Groups. Experience with log collection, vulnerability scans and remediation, or privileged access management. Strong understanding of security concepts, network protocols, and threat vectors. Proficiency in SIEM, IDS/IPS, EDR, and other relevant security tools. Excellent analytical and problem-solving skills. Strong communication, collaboration, and documentation skills. Ability to work independently and as part of a team in a fast-paced environment. Have experience and a strong knowledge of the following Splunk, InsightVM Rapid7, Tenable, CyberArk, Jenkins, Veracode Linux and Windows Operating Systems, Baseline hardening of operating systems IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall At least one of these certs below is REQUIRED CompTIA Security+ ISC2 CC (Certified in Cybersecurity) Offensive Security Certified Professional (OSCP) CCSP (Certified Cloud Security Professional) CSSLP (Certified Secure Software Lifecycle Professional) At least one of these certs below is highly DESIRED (Independently and or with one of the above) AWS Solutions Architect (Associate/Professional) AWS Security Specialty At least one of the any is DESIRED CompTIA PenTest+, Certified Ethical Hacker (CEH), GIAC Certified Intrusion Analyst (GCIA) Required skills: Application Security Required 5 Years Network or Firewall/AWS security Groups Required 2 Years Infrastructure as Code (IaC): Advanced proficiency in Terraform for multi-account landing zones and automated provisioning. Required 2 Years Experience with log collection, vulnerability scans and remediation, or privileged access management Required 4 Years Proficiency in SIEM, IDS/IPS, EDR, and other relevant security tools. Required 4 Years Networking & Hybrid Connectivity: Solid understanding of routing, firewalls, AWS Direct Connect, and VPNs in a hybrid cloud environment. Required 4 Years One REQUIRED: CompTIA Security+, ISC2 CC (Certified in Cybersecurity), Offensive Security Certified Professional (OSCP), CCSP, or CCLP. UPLOAD COPY!! Required CI/CD & DevOps: Experience with GitLab CI/CD, Jenkins, or AWS CodePipeline for automated, secure deployments. 5 Years Splunk, InsightVM Rapid7, Tenable, CyberArk, Jenkins, Veracode 2 Years Linux and Windows Operating Systems, Baseline hardening of operating systems 2 Years IIS and Apache, Scripting Languages and SQL, PowerShell, Firewall 2 Years One highly DESIRED (Independently and or with one of the above): AWS Solutions Architect (Associate/Professional) or AWS Security Specialty One of these is DESIRED: CompTIA PenTest+, Certified Ethical Hacker (CEH), or GIAC Certified Intrusion Analyst (GCIA)

For applications and inquiries, contact: [email protected]

Apply tot his job

Apply To this Job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Clinical Triage Specialist, Part Time Nights, Connect to Care (PA residency) – Access Center

Remote Full-time

PT Store Supervisor - 4296 MARKETPLACE AT AUGUSTA – Amazon Store

Remote Full-time

Experienced Customer Service Representative - Flexible Hours, Remote Work Opportunity at blithequark

Remote Full-time

[Remote] Sales Support Professional

Remote Full-time

Sr. Cloud DevOps Developer - Remote

Remote Full-time

Experienced Director, Internal Audit – Remote Work Opportunity for a Full-Time Director of Internal Audit to Lead Governance, Risk, and Control Environment in a Large Multinational Public Company

Remote Full-time

Senior Manager, Customer Success Enterprise

Remote Full-time

Production Associate, Body in White Model Y

Remote Full-time

Virtual Hiring Event - November 20th - Case Management

Remote Full-time

Intern - Supply Chain

Remote Full-time
← Back to Home