Role Description
EMCOR Group, Inc. seeks an Application Security Analyst who would support EMCORโs Security Program with a primary focus of integrating AppSec tools into CI/CD pipelines, managing application security vulnerabilities and partnering with development teams to prioritize security in their practices. This role plays a key part in maturing our DevSecOps culture, reducing EMCORโs overall attack surface and strengthening the EMCOR Information Security Program.
-
Support and monitor the enterprise information security system as directed by management.
-
Manage daily operations and support for Application Security products, including incident and ticket resolution.
-
Provide expertise during incidents, document findings and help improve protocols.
-
Maintain and upgrade application security related platforms.
-
Tune application security related policies and rulesets.
-
Collaborate with business and IT partners to integrate security tools (SAST, DAST, etc.) and platforms into CI/CD pipelines and workloads.
-
Contribute to and perform security reviews of Terraform configurations and reusable modules supporting EMCORโs Infrastructure as Code (IaC).
-
Validate Terraform changes for security, compliance and alignment with established cloud architecture standards.
-
Monitor code platforms and resources for security threats, investigate and respond to security incidents and findings.
-
Write SIEM queries and perform analysis of results.
-
Respond to security tool findings and collaborate with business and IT partners for remediation.
-
Implement, configure, manage and support Web Application Firewalls (WAFs), including the tuning of rulesets and policies.
-
Contribute to various application security related projects and initiatives.
-
Perform special projects as needed.
Qualifications
-
3+ years of hands-on experience in an Application Security, Product Security, DevOps or DevSecOps role.
-
Experience working in cloud platforms (Azure, AWS, GCP, OCI).
-
Experience with CI/CD and developer workflow automation such as GitHub Actions, Azure DevOps Pipelines.
-
Experience developing or reviewing Terraform used to deploy Azure infrastructure, including reusable modules.
-
Experience managing and tuning Web Application Firewall (WAF) policies, specifically for Azure Front Door.
-
Experience triaging and remediating vulnerabilities identified by GitHub Advanced Security (GHAS) or Microsoft Defender for Cloud platforms, including CodeQL, Secret Scanning and Dependency Review.
-
Demonstrated proficiency in using PowerShell for administration and automation purposes.
-
Proven ability to communicate effectively and interact professionally at all organization levels.
-
Strong project management capabilities.
-
Ability to consistently deliver an exceptional standard of customer service.
Requirements
-
Support and maintain EMCORโs Security Program.
Benefits
-
Competitive salary and benefits package.
-
Medical, dental, and vision coverage.
-
Health savings and flexible spending accounts.
-
Life insurance and disability coverage.
-
401(k) Savings Plan.
-
College Coach and employee assistance program.