๐ Weโre Hiring: Application Security Specialist / Advisor (5494)
ืคืืจืกื ืืชืืื ยท 0 ืืืขืืืื
ืฉืืืจื, ืืืฉื ืื ืืืืงืช ืืชืืื โ ืืื ืฉื ืืืช ืืืงืืช ืืฉืืื ืืื ื.
ืืชืคืงืื ืืืืืื ืคืฉืืืืช
ืืืืฅ ืืชืืืืจ ืืืฉืจื ยท ืืชืขืืื ืืืืืืืืช
ืืื ืื ืืชืืื
ืชืืืืจ ืืืฉืจื ืืืื
ืืืฉืจื ืืืงืืจืืช ยท ื ืฉืืจ ืืขืืืWe are looking for an experienced Application Security Specialist / Advisor to join our team! In this role, you will lead and oversee application security end-to-end across diverse technological projects, set security policies, and ensure top-tier security standards throughout the organization.
๐ Role & Responsibilities
โข End-to-End Project Guidance: Lead technological projects from initiation to production, ensuring robust application security and policy implementation.
โข Guidelines & Standards: Write technical guidance documents for R&D teams to enable secure coding, remediate vulnerabilities, and integrate appsec tools.
โข Architecture Design: Collaborate on secure architecture design aligned with company policies and best practices.
โข Vulnerability Assessment: Identify application-layer gaps, define necessary controls, and drive remediation efforts.
โข Compliance & Governance: Monitor and audit compliance with regulatory guidelines (including Insurance Commissioner cyber risk regulations) and internal procedures.
โข Security Assessments: Lead application security reviews, scoping documents, findings validation, and track risk mitigation.
โข Tech Requirements: Define functional and security requirements for new security products and innovative technologies.
๐ ๏ธ Requirements & Qualifications
โข Application Security Expertise: Deep understanding of AppSec concepts, Secure SDLC, and security methodologies.
โข Cross-Functional Collaboration: Hands-on experience working closely with Software Development, DevOps, and Infrastructure teams.
โข API Security: Practical experience with API Management & Security solutions (e.g., Apigee, DataPower, etc.).
โข Cloud & Modern Tech: In-depth knowledge of cloud technology and cloud-native applications, focusing on Containers, Kubernetes, and Serverless architectures.
โข DevSecOps & CI/CD: Hands-on experience with CI/CD pipelines, Git/Repos, and Infrastructure as Code (IaC).
โข Security Tooling: Practical experience implementing SAST, DAST, SCA/OSS, CWPP, and similar security tools.
โข Frameworks & Concepts: Deep familiarity with OWASP Top 10, Mobile Security, and Threat Modeling.
โข Enterprise Background: Proven experience in AppSec project management, risk management, and security controls within large enterprise environments.
โจ Nice to Have / Advantages
โข Certifications: CISSP, CISM, CISA, or equivalent security certifications.
โข Development Background: Hands-on experience in software development/coding.
โข Financial Sector Experience: Background in institutional, financial, or heavily regulated organizations.
โข Regulatory Knowledge: Familiarity with financial/insurance technology regulations and compliance standards.
#JobOpening #Hiring #ApplicationSecurity #AppSec #DevSecOps #CyberSecurity #CloudSecurity #APIsecurity
ืฉืืืืช ืขื ืืืฉืจื
- ืืืฉืจื ืื ืฆืืื ื ืฉืืจ. ืื ืื ื ืืฆืืืื ืฉืืจ ืจืง ืืฉืืืขืกืืง ืืคืจืกื ืืืชื.