Security Consultant Job at The Juno Group, Inc., California

ajMvU05vclB1V1BqdDB3ZVg1TmRzN3Q5bkE9PQ==
  • The Juno Group, Inc.
  • California

Job Description

We are looking for a highly-skilled Security professional with a good aptitude for Threat Modeling, ability to read through (software) architectural documents and requirements from the different business groups and give accurate and actionable recommendations for the engineers to implement.

The Consultant must have a good understanding of software architecture and development for threat modeling purposes—i dentify designs and implementations which go against best practices and security vulnerabilities, analyze the system and break it down into key components based off logic, and speak to security risks, which may be found in each of those components, and apply sound logic and risk determination in relation to risk acceptance and business operation impact.

Job Title: Security Consultant

Location: Hybrid | San Francisco or Sunnyvale, CA; Seattle, WA; New York, NY; Toronto, Canada

Contract: Long-Term

***Independent/Direct Contractors only. NO THIRD-PARTIES, please.

Requirements:

Security Design Review

  • In-depth knowledge of secure software development practices and SDLC
  • Experience with threat modeling techniques and tools
  • Strong understanding of common security frameworks (e.g., OWASP, NIST)
  • Proficiency in identifying and mitigating security vulnerabilities in application designs
  • Familiarity with regulatory compliance standards (e.g., GDPR, HIPAA, PCI-DSS)
  • Ability to analyze complex data flows and identify sensitive data protection needs
  • Experience with security architecture and design patterns
  • Strong communication skills to effectively convey security concepts to technical and non-technical stakeholders
  • Hands-on experience with security tools (e.g. static analysis, DAST, SAST)
  • Proven ability to collaborate with cross-functional teams, including developers and DevOps
  • Experience with integrating security into CI/CD pipelines
  • Knowledge of encryption, authentication, and access control mechanisms
  • Experience in conducting risk assessments and developing mitigation strategies
  • Familiarity with automated security testing and continuous monitoring practices
  • Ability to document and report security findings clearly and effectively
  • Experience with incident response planning and forensic readiness in application design
  • Strong problem-solving skills and attention to detail

Threat Modeling

  • Deep understanding of threat modeling methodologies, particularly STRIDE
  • Proficiency in identifying and categorizing threats, vulnerabilities, and risks
  • Experience with threat modeling tools (e.g., Microsoft Threat Modeling Tool, OWASP Threat Dragon)
  • Strong knowledge of security frameworks and standards (e.g., OWASP, NIST)
  • Ability to map threat models to security requirements and controls
  • Experience in applying STRIDE to various architectural patterns and data flows
  • Familiarity with risk assessment and management practices
  • Ability to work with cross-functional teams to integrate threat modeling into the SDLC
  • Strong analytical skills for identifying potential attack vectors and weaknesses
  • Experience with security architecture and defensive design techniques
  • Effective communication skills to explain threat modeling findings to stakeholders
  • Knowledge of common security vulnerabilities and their mitigations (e.g., SQL injection, XSS)
  • Ability to create and maintain comprehensive threat models for complex systems
  • Experience in developing mitigation strategies based on threat model findings
  • Familiarity with regulatory compliance requirements and their impact on threat modeling
  • Strong documentation skills to create detailed threat model reports
  • Continuous learning mindset to stay updated on emerging threats and modeling techniques

Job Tags

Contract work, For contractors,

Similar Jobs

Strategic Resolution Experts, Inc.

Senior Policy Analyst-REMOTE Job at Strategic Resolution Experts, Inc.

 ...when we leave then when we came. We are seeking professional consultants who share in our mission of service, our vision of leaving the...  ...work location of this position is Washington D.C. Metro area, remote work is allowed but not guaranteed. If you live outside the commutable... 

GD Land Systems

Manufacturing Engineer, Wire Harness Manufacturing Job at GD Land Systems

 ...Career Level: Mid-Career Requisition ID: 15299844 Date Posted: Dec 2, 2024 Description: Company Information General Dynamics is a successful Fortune 100, global aerospace, and defense company, with over 90,000 employees world-wide. General Dynamics Land... 

Multimedia Solutions Corp.

Join us for a Digital Marketing Internship Job at Multimedia Solutions Corp.

Join us for a Digital Marketing InternshipAre you interested in helping to transform the way people communicate?At Multimedia Solutions, we depend on collaboration for many of our marketing engagements. Thus, we have a great deal of knowledge and experience to... 

Veterans Affairs, Veterans Health Administration

Senior Social Worker Job at Veterans Affairs, Veterans Health Administration

 ...proficient in spoken and written English to be appointed as authorized by 38 U.S.C. 7403(f). Education. Have a master's degree in social work from a school of social work fully accredited by the Council on Social Work Education (CSWE). Graduates of schools of social work... 

University of Texas at San Antonio

Associate or Full Professor - Space Science, Technology, and Human Performance in Space Cluster Job at University of Texas at San Antonio

 ...Five positions are open in areas of emphasis related to space research, including: Satellites and space-based instrumentation Space...  ...Institute (SwRI), UT Health San Antonio, Veterans Affairs medical centers, Velocity TX, local businesses and other academic institutions...