Application Security Lead

August 15

Apply Now
Logo of Accurate Background

Accurate Background

Service and Technology for a Better Screening Experience

Background Checks • Drug Testing • Compliance Consultation • Criminal Searches • Credit Reports

1001 - 5000

💰 Private Equity Round on 2020-02

Description

• Manage and provide leadership to a team of security engineers, including hiring, training and performance management. • Collaborate with Development & DevOps engineers to evaluate and operationalize security tools integrated in development environments. • Collaborate with product managers, scrum masters, and application development to identify and inject security requirements into Acceptance Criteria of epics/stories. • Provide subject matter expertise on secure coding practice relating to SDLC, assist in building and rolling out related guidelines and standards, Conduct code scanning, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Composition Scanning (SCS), Infrastructure as Code (IaC), Dynamic Application Security Testing (DAST) and perform manual source code reviews for high-risk components. • Research and monitor emerging threats and vulnerabilities, understand current industry and technology trends and opportunities, and assess their impact to applications and the business. Drive Risk Management and Security Compliance within the AppSec environment. • Participate in a review board to address false positives and provide application security governance. • Create documentation for application security metrics, policies, procedures, standards, guidelines and training.

Requirements

• High level of expertise in Application development and security acquired through educational qualifications in computer science, Cyber Security or related field and a minimum of 4 years of relevant experience. • A proven track record in providing expertise and guidance in developing cloud hosted applications with focus on security on C#, Java, Python, .Net, MongoDB, SQL Server, Oracle etc • Strong understanding of various computing systems including Cloud architecture (AWS/Azure/GCP) • Detailed knowledge of operating security tools such as SAST, SCA and DAST and - supporting teams to use them in the most effective ways. • Strong working knowledge of various information technologies including user authentication, authorization pattern and components including knowledge of MFA mechanisms and configuration. Good awareness of industry best practices • Data analysis, metrics development and reporting • Experience with working in a highly outsourced environment (both infrastructure outsourcing and security operations outsourcing)

Apply Now

Similar Jobs

August 15

EasyPost

51 - 200

Ensure regulatory compliance for EasyPost's shipping operations through effective monitoring and reporting.

Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@remoterocketship.com