Capital One Services, LLC Master Application Security Engineer (Web and Mobile) in New York, New York
Job ID: R71633
Locations: NY - New York, United States of America, New York, New York
At Capital One, we're building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.
Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.
Master Application Security Engineer (Web and Mobile)
Understand security controls deployed on both web and mobile applications, perform penetration test to vet their strength and identify any gaps.
Perform focused penetration testing on upgrades / updates made on security controls from time to time and report any gaps.
Perform focused threat modeling on risky features & functions for both web and mobile applications.
Following SDLC, perform focused advance penetration testing on risky features & functions being developed and report vulnerabilities during regression test cycle.
Maintain continuous awareness on threats, vulnerabilities, and techniques in web and mobile security.
Emulate advance techniques used by attackers to find and exploit vulnerabilities on web and mobile applications.
Explore opportunities to automate pen test cases (wherever applicable) in CI/CD
Interact with engineers and developers to explain vulnerabilities and provide guidance on remediationBasic Qualifications:
Bachelor's Degree or military experience
At least 5 years of experience using OWASP Top 10 risks and mitigation techniques
At least 5 years of experience performing penetration testing on web and mobile applications
At least 5 years of experience with architecture patterns of web and mobile applications
At least 5 years of experience performing threat modeling and penetration testing
At least 5 years of experience emulating adversaries for performing advanced penetration testing
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
Capital One is an equal opportunity employer committed to diversity in the workplace. Capital One promotes a drug-free workplace.
All qualified applicants will receive consideration for employment without regard to gender, race, color, religion, national origin, sexual orientation, protected veteran status, or disability status.
Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; Newark, New Jersey Ordinance 12-1630; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.