Salary
💰 $148,800 - $215,800 per year
About the role
- Act as a senior technical advisor partnering with cross-functional teams to define information security requirements for enterprise IT systems and internally developed applications.
- Proactively define security requirements for assigned applications, whether purchased or developed in-house.
- Analyze various technology environments such as on-prem, cloud, SaaS to detect critical security deficiencies and recommend solutions for improvement.
- Advise Information Security and Information Technology teams and collaborate cross-functionally to develop and implement solutions that ensure compliance with security requirements, best practices, and applicable laws and policies.
- Develop an implementation plan for enterprise security architecture based on business requirements and delivery strategies.
- Conduct detailed threat modeling and security testing of enterprise systems and their interactions.
- Ensure secure development lifecycle of applications including design, implementation, testing and maintenance.
- Conduct secure code review to ensure compliance with security requirements and policies.
- Ensure compliance with Bank Secrecy Act and maintain integrity, ethics, and Privacy Act compliance in all actions.
Requirements
- Bachelors Degree - Computer Science or Related - Minimum.
- Graduate Degree - Computer Science or Related - Preferred.
- 5 Years - Information Technology or Related - Minimum.
- 5 Years - Information Security, Application Security, or Related - Minimum.
- In Lieu of Education: 8 Years - Information Security or Related.
- CISSP - Preferred.
- One or more Azure certifications: AZ-500, AZ-305 - Preferred.
- Experience analyzing on-prem, cloud, and SaaS environments to detect security deficiencies.
- Experience defining security requirements for enterprise IT systems and internally developed applications.
- Experience developing enterprise security architecture implementation plans.
- Experience conducting threat modeling and security testing.
- Experience with secure development lifecycle and secure code review.
- Ability to advise and collaborate cross-functionally with Information Security and Information Technology teams.
- Knowledge of applicable state and federal laws, company procedures, and policies (including Bank Secrecy Act compliance).