Description
Company Overview:
Samsung SDS is the digital arm of the Samsung group and a global provider of cloud and digital transformation innovations.
Samsung SDS delivers enterprise-grade solutions and services in cloud, secure mobility, analytics / AI, digital marketing and digital workspace.
We enable our customers in government, financial services, healthcare, and other industries to drive business in a hyper-connected economy helping them to increase productivity, safeguard assets, and make smarter decisions.
Samsung SDS is entering on an exciting new chapter as we relocate our U.S.
headquarters from New Jersey to Plano, Texas.
This strategic move positions us for continued growth and innovation in one of the country's most dynamic business and technology markets.
As we expand our presence in Texas, employees will have the opportunity to be part of a growing organization, contribute to transformative technology initiatives, and help shape the future of Samsung SDS in the U.S.
Position Summary
Samsung SDS is seeking a detail-oriented Information Security Engineer - Web Application Security to join our Cloud Security Team.
This role is responsible for conducting web application security assessments, managing application security assets, identifying and tracking vulnerabilities through remediation, and partnering with development and technical teams to address security risks.
The engineer will support secure software development practices by providing security guidance and training to developers, analyzing reported vulnerabilities, and assisting with remediation efforts.
The role works cross-functionally with application developers, infrastructure and systems teams, information security, business units, and customers to identify risks and drive timely resolution of web application security issues.
Responsibilites
Perform periodic security assessments and vulnerability testing of company and customer-facing web applicationsConduct security assessments for newly developed or newly deployed web applications before production releaseMaintain and manage the inventory of web applications and related assets, ensuring accuracy and consistency of asset informationIdentify, analyze, and document web application vulnerabilities and provide remediation recommendations to development and system teamsTrack identified vulnerabilities through remediation and perform follow-up validation or retesting to confirm successful resolutionProvide security guidance and technical support to developers for vulnerability remediationDevelop and deliver secure development training for developers, including common web application vulnerabilities, secure coding practices, and vulnerability preventionInvestigate reported security concerns or vulnerabilities affecting specific websites and support the responsible teams in analysis, remediation, and validationPrepare and maintain vulnerability assessment reports, remediation status, and supporting documentationCollaborate with development, infrastructure, security, and customer teams to improve the overall security posture of web applications
Requirements
Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent practical experience2-5 years of experience in information security, web application security, vulnerability management, or a related fieldUnderstanding of web application security concepts and common vulnerabilities, including the OWASP Top 10Experience conducting web application vulnerability assessments or penetration testingKnowledge of HTTP/HTTPS, web architecture, authentication, session management, APIs, and common web technologiesFamiliarity with web security testing tools such as Burp Suite, OWASP ZAP, WebInspect, or similar toolsAbility to analyze vulnerability findings, identify exploitable security risks, and distinguish legitimate findings from false positivesUnderstanding of secure coding principles, vulnerability remediation, and validation techniquesBasic knowledge of operating systems, networking, and infrastructure securityStrong technical documentation and communication skills, with the ability to clearly communicate security findings and remediation requirements to developers and other stakeholdersAbility to collaborate effectively with application developers, infrastructure teams, information security teams, business units, and other stakeholders
Preferred Qualifications
Experience working directly with software developers to identify, remediate, and validate web application vulnerabilitiesExperience with web application asset management and vulnerability trackingExperience supporting secure software development practices or providing security guidance to development teamsSecurity certifications such as Security+, CEH, OSCP, or other relevant industry certificationsExperience with vulnerability management processes, including remediation tracking and validationStrong analytical, problem-solving, and organizational skills
Benefits
Samsung SDSA offers a comprehensive suite of programs to support our employees:
Top-notch medical, dental, vision and prescription coverageWellness programParental leave401K match and savings planFlexible spending accountsLife insurancePaid HolidaysPaid Time offAdditional benefits
Samsung SDS America, Inc.
is an equal opportunity employer.
All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, status as a protected veteran, marital status, genetic information, medical condition, or any other characteristic protected by law.
We are committed to providing reasonable accommodations to participate in the job application or interview process for candidates with disabilities.
Please let your recruiter know if you need an accommodation at any point during the interview process.