Application Security Manager at Remote, Remote, USA |
Email: [email protected] |
From: Saif Ali, Simpalm [email protected] Reply to: [email protected] Simpalm is looking for an Application Security Manager for our client in Dallas, Texas. The person will join the App Sec team within the Cybersecurity department and be responsible for directing and executing the company's AppSec and SAST scans, threat modeling, and SCA activities across multiple applications within multiple environments. Responsibilities Review source code, identify security vulnerabilities, perform risk analysis, and partner with development team for remediation. Perform internal application penetration testing activities and facilitate third party assessments primarily targeting web and other internally developed applications. Perform security assessments of existing architecture and make security recommendations. Develop AppSec scorecard and Dashboard with metrics. Work with cross-functional teams to triage the vulnerabilities, identify false positives, and provide recommendations. Analyze tools in the market and participate in Proof of Concept and support selection of products/tools. Engage with Senior Management to provide Application Risk View for the organization. Lead offshore team and provide accountability. Skills And Experience: 8-10 years of experience in the implementation and administration of the App Sec program. Experience and familiarity with tools such as HCL App Scan, Veracode, Checkmarx, Fortify, Snyk etc. Solid understanding of IAM protocols, services, and traffic flows for authentication. Understanding of Application Security including Vulnerability Management. Knowledge of application development, network engineering, operating systems, and cloud environments. Working understanding of Common Vulnerability Scoring System (CVSS) and their application to cyber analysis, knowledge of cyber intelligence lifecycle. Knowledge and familiarity with Enterprise Information Systems (web servers, databases, file sharing, etc.) Understanding of common network services (web, mail, DNS, FTP, etc.), network vulnerabilities, and network attack patterns. Should have good conceptual understanding of Windows, Linux Operating Systems & Networking TCP/IP Protocol Suite, Application Architecture. Familiarity of ITIL processes and Service Now and good understanding of DevOps concepts. Education: Bachelors/masters degree in technology and related fields. Security and App Sec related certifications preferably. CISSP, CISM, and/or International Information System Security Certification Consortium certification is a plus. Keywords: Application Security Manager [email protected] |
[email protected] View all |
Mon May 06 20:39:00 UTC 2024 |