Amgen Jobs

Mobile Amgen Logo

Job Information

Amgen Specialist Application Security Engineer DAST in Lisbon, Portugal

Specialist Application Security Engineer

LIVE

What you will do

The Specialist Application Security Engineer plays an integral role in Information Security for Amgen. The primary responsibility is to support various capabilities within Amgen’s Application Security function. You will work with various partners at Amgen in a manner aligned to Amgen’s values to define and implement Information Security Services strategies, standards, tools and processes. The Specialist IS Security Engineer will be a part of Amgen’s Information Security team and will be expected to contribute to and help deliver services and projects in other areas of information security.

The role will be part of the Information Security team responsible for delivering security services across Amgen globally. This position will focus on Secure SDLC and Application Security services and technologies to ensure a secure by design approach across Amgen’s applications.

The individual will partner with developers and business owners from applicable technical teams to assess the security architecture of new products and capabilities via application security assessments, prioritize and advise on options to mitigate identified flaws and vulnerabilities and work with development teams to define and evangelize security best practices. Let’s do this. Let’s change the world. In this vital role you will:

  • Manage Dynamic Application Security Testing platforms and engagement with development teams and SOC.

  • Review DAST results for security vulnerabilities and practices dangerous to security and privacy.

  • Create processes for efficient triaging and remediation of alerts and identified weaknesses produced by DAST platforms.

  • Script (Python, Perl, Ruby etc) and build automation tools on an ad-hoc basis.

  • Create and deliver knowledge sharing presentations and documentation to educate developers and operations teams on application security best practices and secure coding techniques.

  • Write reports including recommendations, root cause analysis, security summary analysis, and project roadmaps.

  • Help with tools identification, onboarding and/or tools development to assist developers in the secure development of applications.

  • Configure, run, maintain, and utilize security tools for Dynamic Application Security Testing (DAST) platforms and other relevant analysis tools.

  • Discover threats, vulnerabilities and exploits through architecture design review, threat modeling, code review, DAST and SAST assessments.

  • Triage issues found by tools, external reports, and various tests, to accurately assess the real risks.

  • Offer remediation guidance to stakeholders for identified issues and serve as an escalation resource for developers as they remediate issues.

  • Draft application security policies, standards and guidance documentation that can be leveraged in the secure development of products and services.

  • Monitor latest application security developments and security trends to continually improve internal processes.

  • Work with DevOps team to improve Application Security; Research, Prototype, integrate Security Tools into CI/CD pipelines (DAST, SAST, IAST, Container security, API security, third party vulnerability Scanning, etc).

  • Collaborates cross-functionally with analysts, engineers, data scientists to achieve continuous improvement in cyber defense/resilience.

  • Provide mentorship and training on areas of expertise to junior Application Security team members.

​Specialist IS Security Engineer will also present project status reports to senior management, adhere to policies and practices relative to technical guidelines and change management processes, and may contribute to the development of new policies and practices by suggesting innovative ideas.

WIN

What we expect of you

We are all different, yet we all use our unique contributions to serve patients. The information security professional we seek is team-oriented with these qualifications:

  • Bachelor or Master degree in Information Systems, Computer Science or equivalent and at 6 years of experience in a related field

  • Strong understanding of common software and web application security vulnerabilities. including OWASP Top 10,, OWASP API Top 10, SANS/CWE Top 25 etc.

  • Strong working knowledge and hands-on experience with tools and technologies used for Application Security testing (e.g., Burpsuite Enterprise, Burp Suite/ZAP, Synk, Checkmarx, Rapid7, Accunetix, Netsparker, Veracode, WhiteSource, Postman, Swagger, SoapUI, Fiddler, Insomnia)

  • Security verification of web applications OWASP ASVS and testing guides

  • Experience driving application security requirements in a traditional SDLC and through stories and epics in an Agile and SCRUM development environment

  • DevOps experience deploying automated security testing within CI/CD pipelines with GitLab, GitHub etc.

  • Experience with scripting languages (e.g., Python, Ruby) and automating tasks.

  • Good hands-on experience with AWS foundation services related to compute, network, storage, content delivery, administration and security, deployment and management, automation technologies

  • Ability to review, understand and proficiency with two or more of (JavaScript, Python, Java, Swift. Kotlin etc)

  • Experience with scripting languages (e.g., Python, Ruby) and automating tasks

  • Working knowledge of API technologies and platforms e.g., SOAP, REST, GraphQL, gRPC, XML, AWS API GW, MuleSoft

  • Experience building and maintaining relationships, excellent verbal and written communication skills and effective working with virtual teams

  • Team-oriented, placing priority on the successful completion of team goals

  • Self-starter with a high degree of initiative

  • One or more security certifications such as CSSLP, CISSP, GWEB, GSSP-JAVA or CEH

THRIVE

What can you expect of us

As we work to develop treatments that take care of others, so we work to care for our teammates’ professional and personal growth and well-being.

  • Vast opportunities to learn, develop, and move up and across our global organization.

  • Diverse and inclusive community of belonging, where colleagues are empowered to bring ideas to the table, take risks, and act.

  • Generous Amgen Total Rewards Plan comprising healthcare, finance, wealth and career benefits.

  • Flexible work arrangements.

APPLY NOW

FOR A CAREER THAT DEFIES IMAGINATION

In our quest to serve patients above all else, Amgen is the first to imagine, and the last to doubt. Join us.

CAREERS.AMGEN.COM

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

We will ensure that individuals with disabilities are provided a reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.

DirectEmployers