🚀 We’re Hiring: Application Security Specialist / Advisor (5494)
Posted yesterday · 0 applicants
Saving, applying or scoring takes a few seconds to set up your free account.
The role in plain words
- Deep understanding of Application Security concepts, Secure SDLC, and security methodologies
- Experience working closely with Software Development, DevOps, and Infrastructure teams
- Practical experience with API Management & Security solutions (e.g., Apigee, DataPower)
- In-depth knowledge of cloud technology, Containers, Kubernetes, and Serverless architectures
- Hands-on experience with CI/CD pipelines, Git/Repos, and Infrastructure as Code (IaC)
- Security certifications such as CISSP, CISM, CISA, or equivalent
- Hands-on experience in software development/coding
Extracted from the job description · kept up to date automatically
Who this suits
Full job description
Original listing · kept for referenceWe are looking for an experienced Application Security Specialist / Advisor to join our team! In this role, you will lead and oversee application security end-to-end across diverse technological projects, set security policies, and ensure top-tier security standards throughout the organization.
📌 Role & Responsibilities
• End-to-End Project Guidance: Lead technological projects from initiation to production, ensuring robust application security and policy implementation.
• Guidelines & Standards: Write technical guidance documents for R&D teams to enable secure coding, remediate vulnerabilities, and integrate appsec tools.
• Architecture Design: Collaborate on secure architecture design aligned with company policies and best practices.
• Vulnerability Assessment: Identify application-layer gaps, define necessary controls, and drive remediation efforts.
• Compliance & Governance: Monitor and audit compliance with regulatory guidelines (including Insurance Commissioner cyber risk regulations) and internal procedures.
• Security Assessments: Lead application security reviews, scoping documents, findings validation, and track risk mitigation.
• Tech Requirements: Define functional and security requirements for new security products and innovative technologies.
🛠️ Requirements & Qualifications
• Application Security Expertise: Deep understanding of AppSec concepts, Secure SDLC, and security methodologies.
• Cross-Functional Collaboration: Hands-on experience working closely with Software Development, DevOps, and Infrastructure teams.
• API Security: Practical experience with API Management & Security solutions (e.g., Apigee, DataPower, etc.).
• Cloud & Modern Tech: In-depth knowledge of cloud technology and cloud-native applications, focusing on Containers, Kubernetes, and Serverless architectures.
• DevSecOps & CI/CD: Hands-on experience with CI/CD pipelines, Git/Repos, and Infrastructure as Code (IaC).
• Security Tooling: Practical experience implementing SAST, DAST, SCA/OSS, CWPP, and similar security tools.
• Frameworks & Concepts: Deep familiarity with OWASP Top 10, Mobile Security, and Threat Modeling.
• Enterprise Background: Proven experience in AppSec project management, risk management, and security controls within large enterprise environments.
✨ Nice to Have / Advantages
• Certifications: CISSP, CISM, CISA, or equivalent security certifications.
• Development Background: Hands-on experience in software development/coding.
• Financial Sector Experience: Background in institutional, financial, or heavily regulated organizations.
• Regulatory Knowledge: Familiarity with financial/insurance technology regulations and compliance standards.
#JobOpening #Hiring #ApplicationSecurity #AppSec #DevSecOps #CyberSecurity #CloudSecurity #APIsecurity
Questions about this role
- This listing did not state a salary. We only show pay when the employer publishes it.
- Deep understanding of Application Security concepts, Secure SDLC, and security methodologies, Experience working closely with Software Development, DevOps, and Infrastructure teams, Practical experience with API Management & Security solutions (e.g., Apigee, DataPower), In-depth knowledge of cloud technology, Containers, Kubernetes, and Serverless architectures, Hands-on experience with CI/CD pipelines, Git/Repos, and Infrastructure as Code (IaC)