Granite delivers advanced communications and technology solutions to businesses and government agencies throughout the United States and Canada. We provide exceptional customized service with an emphasis on reliability and outstanding customer support and our customers include over 85 of the Fortune 100. Granite has over $1.85 Billion in revenue with more than 2,100 employees and is headquartered in Quincy, MA. Our mission is to be the leading telecommunications company wherever we offer services as well as provide an environment where the value of each individual is recognized and where each person has the opportunity to further their growth and achieve success. Granite has been recognized by the Boston Business Journal as one of the "Healthiest Companies" in Massachusetts for the past 15 consecutive years. Our offices have onsite fully equipped state of the art gyms for employees at zero cost. Granite's philanthropy is unparalleled with over $300 million in donations to organizations such as Dana Farber Cancer Institute, The ALS Foundation and the Alzheimer's Association to name a few. We have been consistently rated a "Fastest Growing Company" by Inc. Magazine. Granite was named to Forbes List of America's Best Employers 2022, 2023 and 2024. Granite was recently named One of Forbes Best Employers for Diversity. Our company's insurance package includes health, dental, vision, life, disability coverage, 401K retirement with company match, childcare benefits, tuition assistance, and more. If you are a highly motivated individual who wants to grow your career with a fast paced and progressive company, Granite has countless opportunities for you. EOE/M/F/Vets/Disabled General Summary of Position: We are seeking a skilled and experienced Application Security Engineer to join our team in Boston, MA. As an Application Security Engineer, you will be responsible for designing, implementing, and maintaining robust security measures to protect our applications and systems from cyber threats. You will work closely with our development and operations teams to identify and address security vulnerabilities, provide guidance on secure coding practices, and develop and enforce application security policies and procedures. Duties and Responsibilities:
- Conduct thorough security assessments of applications, systems, and networks to identify vulnerabilities, assess risk, and provide recommendations for improvement.
- Collaborate with development and operations teams to integrate security into the software development lifecycle (SDLC) and ensure that security requirements are met.
- Design, implement, and maintain security controls and measures, such as firewalls, intrusion detection/prevention systems, web application firewalls, encryption, and access controls.
- Develop and implement secure coding practices and provide guidance to developers on coding best practices, security standards, and vulnerability remediation.
- Stay up to date with the latest threats, vulnerabilities, and industry best practices in application security, and apply that knowledge to proactively identify and mitigate risks.
- Monitor and respond to security incidents, conduct root cause analysis, and implement corrective actions to prevent recurrence.
- Conduct security testing, including vulnerability scanning, penetration testing, and code review, to identify and address security weaknesses.
- Collaborate with cross-functional teams to perform threat modeling, risk assessments, and security architecture reviews for new applications and systems.
- Develop and deliver security awareness training to educate employees on security best practices and ensure adherence to security policies and procedures.
- Participate in incident response efforts, including investigation, mitigation, and resolution of security incidents.
Required Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Minimum of 3 years of experience in application security, including experience with web application security, mobile application security, cloud security, and secure coding practices.
- Strong understanding of secure software development practices, threat modeling, risk assessment, and vulnerability management.
- Familiarity with industry standards and frameworks, such as OWASP Top Ten Project, NIST Cybersecurity Framework, and ISO/IEC 27001.
- Hands-on experience with security tools and technologies, such as web application scanners, vulnerability scanners, penetration testing tools, and SIEM systems.
- Knowledge of common application security vulnerabilities, such as cross-site scripting (XSS), SQL injection, and cross-site request forgery (CSRF), and ability to provide guidance on mitigation strategies.
- Strong understanding of network protocols, operating systems, and web technologies.
- Excellent communication and interpersonal skills, with the ability to effectively communicate complex security concepts to technical and non-technical stakeholders.
- Certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Offensive Security Certified Professional (OSCP) are a plus. Experience with Network Automation/DevOps including familiarity with Python, Cl/CD tools and scripting large deployments/complex changes.
- Relevant certifications such as CCNA, CCNP, JNCIS, or equivalent.
|