Responsible for developing and maintaining the technical IT/cyber security capabilities necessary for safeguarding the firm's information systems and applications (software development lifecycle), including every phase of the SDLC and software stack. Assist in the designing, planning, testing and implementation phases of cybersecurity technology projects.
Essential Duties and Responsibilities
Develop and maintain the technical IT/cyber capabilities including all phases of the software development lifecycle and software stack with a focus on static application security testing (SAST), and software composition analysis (SCA)
Work to develop and implement a global vulnerability burndown plan and reporting methodology including interacting with the ISO and Developer communities
As needed work with development teams and senior teammates to identify methods to remediate vulnerabilities, evaluate existing workarounds, and troubleshoot false positives via manual code review.
Create and maintain all documentation (e.g. standards, policies, procedures) necessary for compliance and application of application security controls and tool selection.
Complete low to moderately complex engineering work and documentation based on the guidance of others and contributes to project by completing assigned tasks: i.e. Automation of Daily Tasks and Documentation of common CWE remediations
Analyze basic information and makes decisions within guidelines or standard practices to solve problems. Contributes to projects by completing assigned tasks and participating in larger and more complex initiatives.
Qualifications
Required Qualifications:
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Bachelor’s degree or an equivalent combination of education and work experience
Two or more years of experience working within an enterprise Information/Cyber Security setting, or equivalent experience
Knowledge in information systems and ability to apply that knowledge in practice
Experience participating in IT projects
Preferred Qualifications:
Banking or financial services experience
Technical certifications (e.g. MCSE, CCNA, Network+)
Security certifications (e.g. SANS GCIF, SANS GSEC, Security+)
Preferred security certifications (e.g. CCNA Security, GSEC, GCED, GPPA, etc.)
Preferred technical Certifications (e.g. CCNA, RHCE, MCSE, etc.)
Preferred experience with SAST or SCA Scanning Tool
Experience with one or more additional programming languages
Experience with hands on remediation of vulnerabilities in developed codeset
Cloud Experience or Technical Certifications