Application Security Engineer
At Pearson, we’re committed to a world that’s always learning and to our talented team who makes it all possible. From bringing lectures vividly to life to turning textbooks into laptop lessons, we are always re-examining the way people learn best, whether it’s one child in our own backyard or an education community across the globe. We are bold thinkers and standout innovators who motivate each other to explore new frontiers in an environment that supports and inspires us to always be better. By pushing the boundaries of technology — and each other to surpass these boundaries — we create seeds of learning that become the catalyst for the world’s innovations, personal and global, large and small.
ESSENTIAL DUTIES AND RESPONSIBILITIES
The ideal candidate will have a strong development background with prominent web development languages and frameworks; with the ability to understand the code and provide security remediation advice
Provide expert-level guidance to security analysts, testers, and development teams during application security assessments. Must be able to identify, re-create, and remediate security defects. .
Design, develop, and implement automation features into our existing security pipeline. Experience with Django / Python required. Experience with Go a plus.
Working knowledge of automated application security-related tools such as AppSpider, Checkmarx, Qualys, and Nessus.
Working knowledge of manual assessment tools such as HTTP Proxies (BurpSuite Pro, OWASP ZAP), automation scripts, shell scripting w/ curl, fuzzers and other commercial and open source tools.
Experience using and testing REST and/or SOAP APIs.
In depth knowledge on common web application security flaws and secure coding practices and the ability to clearly explain security issues to project and development staff.
Familiar with OWASP Application Security Verification Standard (ASVS) and how it applies to application development teams.
Ability to prioritize and track security issues and work with the necessary teams to ensure remediation
Serve as a leader by promoting security awareness, mentoring other team members, and staying up-to-date on current development methodologies (Agile/DevOps) and information security trends.
Understanding of HTTP, REST, SOAP, XML and JSON as it relates to APIs and AJAX
Familiar with AWS/Rackspace/VSphere APIs and the cloud SDK’s
Experience with OpenStack, Kubernetes, and Docker a plus, but not required.
Performs other duties as assigned.
KNOWLEDGE, SKILLS, AND ABILITIES
CERTIFICATES, LICENSES, REGISTRATIONS
EDUCATION and/or EXPERIENCE
Primary Location: GB-GB-London
Work Locations: GB-London-80 Strand 80 Strand London WC2R 0RL
Organization: Technology & Operations
Employee Status: Regular Employee
Job Type: Standard
Shift: Day Job
Job Posting: Feb 6, 2018
Job Unposting: Ongoing
Schedule: Full-time Regular
Req ID: 1719975
Pearson is an Equal Opportunity and Affirmative Action Employer and a member of E-Verify. All qualified applicants, including minorities, women, protected veterans, and individuals with disabilities are encouraged to apply.