Salary
💰 $120,000 - $180,000 per year
Tech Stack
AWSAzureCloudCyber SecurityGoogle Cloud PlatformJavaMongoDBOraclePythonSDLCSQL
About the role
- Manage and provide leadership to a team of security engineers, including hiring, training and performance management
- Collaborate with Development and DevOps engineers to evaluate and operationalize security tools integrated in development environments
- Collaborate with product managers, scrum masters, and application development to identify and inject security requirements into Acceptance Criteria of epics/stories
- Provide subject matter expertise on secure coding practices relating to the SDLC and assist in building and rolling out guidelines and standards
- Conduct code scanning including SAST, SCA, SCS, IaC scanning, DAST and perform manual source code reviews for high-risk components
- Research and monitor emerging threats and vulnerabilities, assess impact to applications and the business
- Drive risk management and security compliance within the AppSec environment
- Participate in a review board to address false positives and provide application security governance
- Create documentation for application security metrics, policies, procedures, standards, guidelines and training
- Report to the Director of Global Security and support application security oversight across the organization
Requirements
- Educational qualifications in Computer Science, Cyber Security, or related field preferred
- Minimum of 4 years of relevant experience in application development and security
- Proven experience developing cloud-hosted applications using C#, Java, Python, .Net
- Experience with databases such as MongoDB, SQL Server, Oracle
- Strong understanding of cloud architecture (AWS, Azure, GCP)
- Detailed knowledge and hands-on experience with security tools: SAST, SCA, SCS, DAST, IaC scanning
- Experience performing manual source code reviews for high-risk components
- Strong working knowledge of authentication and authorization patterns, including MFA mechanisms and configuration
- Data analysis, metrics development and reporting skills
- Experience working in a highly outsourced environment (infrastructure and security operations outsourcing)
- Preferred certifications: CISSP, ISO 27001, CASE or relevant certifications
- Demonstrated ability to take initiative and accountability for achieving results
- Effective communication skills with technical and non-technical staff