SemanticBits is looking for a Security Analyst to keep our business, users, and data safe by assuring the security of our applications and platforms. This position requires collaboration within the security team and our delivery teams to ensure compliance with security requirements. This role is heavily focused on compliance, policy, and documentation and will support security engineers with system hardening and penetration testing.The ideal candidate will have experience with either Federal Government Security Control Assessment (SCA) or the Payment Card Industry (PCI) Security Standard.
Responsibilities:
Document System Security Plan and Contingency Plans for related projects
Responsible for documenting and evaluating security policies
Ensure security systems are up to date and create documentation and planning for all security-related information; including incident response and disaster recovery plans
Review policies and procedures for compliance with applicable standards and identify areas of improvement for finding remediation
Interact with senior level management, including the ISSO
Required Qualifications:
A Bachelor’s degree or higher in Computer Science, Electrical Engineering, Information Assurance, Network Security Computer Engineering or a related field, or equivalent experience
CISSP certification
At least 5 years of experience in the following;
NIST 800-53 security controls
Penetration Testing
System Hardening (blue team)
Programming/Scripting (java, node, python, etc)
Incident Response
Strong knowledge of and ability to perform the below tests:
Penetration testing
Static Analysis/Static Application Security Testing
Vulnerability Assessment/Scanning
Dynamic Analysis/Dynamic Application Security Test (DAST)
Malicious Software Analysis
Strong foundation in one or more of the following:
Data management security
Authentication
Applied cryptography
Linux security
Network & Cloud security
Advanced knowledge of Linux platforms
Advanced knowledge of application mobile security tools
Strong technical acumen securing software and hardware
Understanding of software development and working experience with any one of the higher level programming languages or scripting
Familiarity and experience with security technologies such as security engineering, security architecture, cryptography, data security, risk management, identity and access management, communication and network security, security assessment and testing, software development security, security operations
Familiarity and experience with popular open source security projects such as OWASP ZAP and Snort
Thorough understanding of issues documents in the OWASP Top Ten and CWE Top 25
Demonstrated ability to exploit and mitigate application-level vulnerabilities
Strong understanding of cryptography as applied to web application security (encryption, hashing, PKI management), including analysis and implementation
Experience using Linux/Unix at the command line for tasks related to web application development and deployment (DevOps)
Flexible and willing to accept a change in priorities as necessary
Nice To Have:
Strong engineering background
Application architecture experience
Physical and emotional requirements for the job:
- This position is to be performed remotely from an individual’s home office and involves sedentary work. Employees in this role can be expected to exert up to 10 pounds of force on occasion in order to lift, carry, push, pull or otherwise move standard electronic equipment. Employees are expected to make decisions in a timely manner and display emotional intelligence during occasional stressful situations.

