Application Security

hace 3 meses


Tijuana, México Solar Turbines A tiempo completo

Career Area:
Business Technologies, Digital and Data

Job Description:
Your Work Shapes the World at Caterpillar Inc.

When you join Caterpillar, you're joining a global team who cares not just about the work we do - but also about each other. We are the makers, problem solvers, and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here - we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it.

We are seeking an Application Security (Appsec) developer to join our world-class cybersecurity team. This role will work with other cybersecurity professionals as well as IT partners to advocate for and create security solutions for the development of software and other technologies.

Responsibilities:
DAST Scan Review and Triage:

- Conduct in-depth reviews of DAST scan findings to identify and prioritize potential vulnerabilities.
- Manually reproduce and retest vulnerabilities to validate their existence and severity.
- Provide expert consulting to IT partners on remediation strategies and risk mitigation measures.

SAST Scan Review and Triage:

- Conduct in-depth reviews of SAST scan findings, particularly those generated using GitHub CodeQL.
- Analyze source code for vulnerabilities and provide recommendations for remediation.
- Collaborate with development teams to address SAST findings and improve code quality.

Vulnerability Exploitation and Demonstration:

- Ensure compliance with Enterprise Security Policies and Directives, including OWASP Top 10, SANS 25 software flaws, and other vulnerabilities.

DAST Tool Configuration and Support:

- Configure and tune the Enterprise DAST scanning tool to optimize its effectiveness.

Vulnerability Prioritization and Remediation:

- Regularly review DAST scans and prioritize vulnerabilities based on risk and impact.
- Collaborate with IT partners to drive remediation efforts and meet required metrics thresholds.

Technical Education and Awareness:

- Document and report DAST scan findings to business and IT stakeholders.

DAST Program Development and Support:

- Contribute to the development and evolution of the DAST scanning program.
- Provide awareness, education, and guidance on DAST tools and best practices.

Cross-Functional Collaboration:

- Collaborate with Corporate Security partners and other teams to ensure effective security practices.
- Provide backup support for SAST scanning operations and firewall rule requests.

Automation and Tool Development:
Minimum Qualifications:

- Bachelor's degree in Computer Science, Information Technology, or related field or equivalent experience
- 5+ years previous cumulative Information Technology and/or Cybersecurity experience
- 3+ years experience developing software in at least one or more of the following disciplines: JavaScript,.Net Core, C#, CSS, Python, Java, Bootstrap, Git
- 3+ years experience utilizing databases such as SQL or cloud native databases

Preferred Qualifications:

- Familiar with access control systems, network security, or cryptography
- Previous experience with DAST/SAST scanning tools
- Active CISSP Certification or relevant industry certifications
- Previous experience with Risk Management frameworks
- Previous experience with Threat Model Assessments
- Previous experience with Project Management (Waterfall, Agile, etc.)
- Strong analytical and problem-solving skills
- Excellent oral and written communication skills
- Ability to work independently and in a team environment
- Experience in developing software using UX/UI design principles
- Experience in RESTful API design and implementation
- Experience in cloud software development and security

Skill Descriptors

Level Working Knowledge:

- Explains the requirements, deliverables, costs, and criticalities of the assignment.
- Participates in developing consulting opportunities or assignments.
- Uses formal and informal means to keep client informed on progress and issues.
- Carries out the agreed-upon consulting assignment in a professional manner.
- Documents client's objectives and project scope.

Cybersecurity Risk Management: Knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks.

Level Basic Understanding:

- Explains major methods, tools and processes involved in cyber risk assessment.
- Identifies major categories of cyber risks.
- Describes the goals and objectives of cybersecurity risk management.
- Identifies an organization's resources for cyber risk avoidance and management.

Information Security Technologies: Knowledge of technologies and technology-based solutions dealing with information security issues; ability to protect information security across the organization using encryption technologies and appropriate security software.



  • Tijuana, México Thermo Fisher Scientific A tiempo completo

    Senior Software Security Engineer engages with product development teams across the organization and acts as a domain expert for providing mentorship related to secure software development practices. Key responsibilities As a software security engineer on the Product Security team, you will be responsible for promoting and implementing secure...


  • Tijuana, México Thermo Fisher Scientific A tiempo completo

    As part of the Thermo Fisher Scientific team, you’ll discover meaningful work that makes a positive impact on a global scale. Join our colleagues in bringing our Mission to life every day to enable our customers to make the world healthier, cleaner, and safer. We provide our global teams with the resources needed to achieve individual career goals while...


  • Tijuana, Baja California, México Outrider A tiempo completo

    About the CompanyOutrider is a leading company in autonomous vehicle technology, committed to responsible deployment and innovation.About the RoleWe are seeking an experienced Senior Cloud Application Leader to join our team. As a key member of our leadership team, you will be responsible for managing the day-to-day operations of our cloud applications,...


  • Tijuana, México Integer Holdings Corporation A tiempo completo

    By living according to a common set of values, we create a culture that unifies, embraces the uniqueness we all bring to the company, and positions Integer for long-term success. At Integer, our values are embedded in everything we do. Customer We focus on our customers’ success Innovation We create better solutions Collaboration We create...


  • Tijuana, México Integer A tiempo completo

    By living according to a common set of values, we create a culture that unifies, embraces the uniqueness we all bring to the company, and positions Integer for long-term success. At Integer, our values are embedded in everything we do. Customer We focus on our customers’ success Innovation We create better solutions Collaboration We create success...


  • Tijuana, México CA Locksmith and Doors A tiempo completo

    **The CA **team helps clients identify and fix their locksmithing and door issues. Anything to do with security. Our team is dedicated to helping our clients whether developers, small, large businesses, schools or residents — As part of our team, you will play a role in understanding the needs of our clients and help shape the future of home improvement...

  • Security Guard I

    hace 7 meses


    Tijuana, México CommScope A tiempo completo

    In our ‘always on’ world, we believe it’s essential to have a genuine connection with the work you do. En nuestro mundo "siempre activo", creemos que es esencial tener una conexión genuina con el trabajo que realiza. Como nos ayudaras a conectar el mundo Bajo la supervisión directa del jefe directo, el Guardia de Seguridad se enfoca a hacer...


  • Tijuana, México Allstate A tiempo completo

    Integon is a part of The Allstate Corporation, which means we have the same innovative drive that keeps us a step ahead of our customers’ evolving needs. It’s how we’ve become industry leaders in property and casualty insurance servicing. We support our insurance company affiliates by offering property and casualty insurance products inclusive of...


  • Tijuana, México nice2chat A tiempo completo

    Responding to incoming calls from customers to provide information, answer inquiries, and address concerns. - Initiating calls to customers for various purposes such as confirmations. - Offering detailed information about products or services - Recording detailed notes of customer interactions, including inquiries, issues, resolutions, and follow-up...


  • Tijuana, México Digitronic Tech Savvy Inc. A tiempo completo

    **Responsibilities** - Responding to customer tickets in a timely manner, owning infrastructure issues to resolution - Proactively identifying the root cause of issues and recommending and implementing solutions - On projects supporting the build and migration of SAP systems on AWS - Liaising with basis, and other team members to support a customer’s...


  • Tijuana, Baja California, México Teradata Group A tiempo completo

    About UsAt Teradata Group, we empower our customers with better information, driving their success through harmonized data, trusted AI, and faster innovation. Our cloud analytics and data platform for AI has been widely adopted by top companies across various industries.Job OverviewWe are seeking a highly motivated Cloud Engineer to manage our as-a-service...

  • Cloud Engineer

    hace 7 meses


    Tijuana, México Teradata A tiempo completo

    What You’ll Do Manage and support mission-critical/24x7 public cloud environments for multiple customers Backup, Archive and Recovery execution of the cloud-based data warehouses Throughput monitoring, load balancing, improving the overall system health by optimizing the key public cloud resources Working with distributed teams Real-time...

  • Cloud Engineer

    hace 7 meses


    Tijuana, México Teradata A tiempo completo

    What You’ll Do Manage and support mission-critical/24x7 public cloud environments for multiple customers Backup, Archive and Recovery execution of the cloud-based data warehouses Throughput monitoring, load balancing, improving the overall system health by optimizing the key public cloud resources Working with distributed teams Real-time...


  • Tijuana, México North American Production Sharing, Inc. A tiempo completo

    Full stack data visualization developerJob Description:Full stack developer to develop web based application to process, analyze and visualize pivot data. This includes collaborating with cross-functional engineering teams to translate scientific requirements into working and maintainable solutions.The ideal candidate will have experience in UI/UX design,...

  • Cloud Engineer

    hace 2 meses


    Tijuana, México Teradata A tiempo completo

    What You’ll Do Manage and support mission-critical/24x7 public cloud environments for multiple customers. Backup, Archive, and Recovery execution of the cloud-based data warehouses Throughput monitoring, load balancing, and improving the overall system health by optimizing the critical public cloud resources Working with distributed teams Real-time...


  • Tijuana, México TaskUs A tiempo completo

    About TaskUs: TaskUs is a provider of outsourced digital services and next-generation customer experience to fast-growing technology companies, helping its clients represent, protect and grow their brands. Leveraging a cloud-based infrastructure, TaskUs serves clients in the fastest-growing sectors, including social media, e-commerce, gaming, streaming...


  • Tijuana, México TaskUs A tiempo completo

    Description About TaskUs: TaskUs is a provider of outsourced digital services and next-generation customer experience to fast-growing technology companies, helping its clients represent, protect and grow their brands. Leveraging a cloud-based infrastructure, TaskUs serves clients in the fastest-growing sectors, including social media, e-commerce,...

  • Cloud Engineer

    hace 3 semanas


    Tijuana, México Teradata A tiempo completo

    Our Company At Teradata, we believe that people thrive when empowered with better information. That’s why we built the most complete cloud analytics and data platform for AI. By delivering harmonized data, trusted AI, and faster innovation, we uplift and empower our customers—and our customers’ customers—to make better, more confident decisions. The...

  • Lavanderia

    hace 4 meses


    Tijuana, México JLL A tiempo completo

    Description Auxiliar de Lavandería Tijuana Acerca de la posición:  Estamos buscando un Auxiliar de Lavandería Responsabilidades: Acomodo de batas en casilleros Acomodo de cubre calzado en contenedores Limpieza del área de trabajo Secado de batas Lavado de batas Operar lavadoras de ropa tipo industrial Operar secadoras de ropa...


  • Tijuana, México Allegion A tiempo completo

    Creating Peace of Mind by Pioneering Safety and Security Como Gerente de Ingeniería de Manufactura, serás responsable de maximizar la productividad del sitio en el corto, mediano y largo plazo, a través de la optimización de nuestros recursos industriales y laborales; centrando su desempeño en el enganche del personal, la estandarización de...