- Salary
- $70 – $75/hr
- Location
- Sacramento, California, US
- Workplace
- Remote
- Type
- Part-time
- Department
- Security
- Experience
- 5+ years
- Education
- Master
- Source
- BetterTeam
Description
Estimated Level of Effort: Approximately 80 total hours over the duration of the project
Project Duration: Approximately 3-6 months
Work Arrangement: Primarily remote
- Review application architecture, technical designs, and security configurations for compliance with project security requirements.
- Provide security guidance during the design and development of a Microsoft-based web application and SQL Server database environment.
- Review and validate implementation of role-based access control (RBAC) and the principle of least privilege across application functions, database access, APIs, and administrative functions.
- Review user authentication and authorization controls, including federated identity, single sign-on, multi-factor authentication/two-factor authentication, password controls, and account-management processes.
- Verify appropriate security controls for internal users, administrators, developers, and authorized external partner users.
- Review application session-management controls, including inactivity timeouts and protections against session hijacking.
- Review secure storage and management of user credentials, including appropriate hashing and salting techniques.
- Review and validate encryption of data in transit and at rest, including TLS and applicable database/file encryption controls.
- Evaluate application and database audit logging, including authentication events, data access, data modifications, deletions, and configuration changes.
- Review protections that prevent unauthorized modification or deletion of security and audit logs.
- Assist with the implementation and review of alerts for suspicious activity and abnormal access patterns.
- Review data-classification and privacy controls to ensure appropriate protections are applied according to the sensitivity of project information.
- Perform or support application vulnerability scanning, security testing, authentication/authorization testing, and penetration testing.
- Analyze identified vulnerabilities, assess severity and risk, and work with developers to recommend appropriate remediation.
- Perform follow-up validation and re-testing of security findings following remediation.
- Review application APIs, database connections, cloud integrations, and file-upload functionality for common security weaknesses.
- Participate in pre-production security reviews and provide security input regarding production readiness.
- Assist the project team in documenting applicable application-security controls, configurations, findings, remediation activities, and security test results.
- Provide security-related input for technical documentation and knowledge-transfer activities.
- 5+ years of experience in application security, cybersecurity, information security, or secure software development.
- Hands-on experience evaluating the security of web-based applications.
- Experience with application security controls involving:
- Authentication and authorization.
- Role-Based Access Control (RBAC).
- Least-privilege access.
- Multi-factor authentication.
- Secure session management.
- Encryption in transit and at rest.
- Audit logging and monitoring.
- Experience performing or supporting vulnerability assessments, vulnerability scanning, and penetration testing of web applications.
- Experience identifying application vulnerabilities and working with development teams to remediate security findings.
- Knowledge of secure application-development practices and common web-application vulnerabilities.
- Experience reviewing security controls for databases, APIs, web services, or cloud-hosted application components.
- Working knowledge of NIST security controls/frameworks, particularly NIST SP 800-53.
- Ability to document security findings, risks, recommendations, and remediation results.
- Ability to work collaboratively with application developers, architects, database personnel, QA/testing staff, and project management.
- Experience with Microsoft .NET / C# web applications.
- Experience securing Microsoft SQL Server environments.
- Experience with Microsoft Azure application or security services.
- Experience with Microsoft identity technologies such as Microsoft Entra ID/Azure Active Directory, federated identity, SSO, and MFA.
- Experience working with California State government security standards, including State Administrative Manual (SAM) Section 5300.
- Familiarity with OWASP Top 10, secure coding standards, and secure SDLC practices.
- Experience with application-security tools used for static/dynamic analysis or vulnerability scanning.
- Experience conducting security assessments for government or other regulated environments.
- Relevant security certification such as CISSP, CSSLP, Security+, CEH, GIAC, or equivalent is desirable but not required.
- Design phase: security requirements/design review and RBAC/authentication architecture.
- Development phase: periodic review of application, database, API, encryption, audit, and identity controls.
- Testing phase: vulnerability/security testing, penetration-testing support, authentication/authorization testing, findings review, and remediation verification.
- Pre-production/deployment: final security validation and production-readiness review.