Responsible for developing and maintaining the technical IT/cyber security capabilities necessary for safeguarding the applications (software development lifecycle), including phases of SDLC and Static Application Security Lifecycle. Assist in the designing, planning, testing and implementation phases of cybersecurity technology projects.
Essential Duties and Responsibilities
The following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
Develop and maintain the technical IT/cyber capabilities including all phases of the software development lifecycle and software stack with a primary focus on static application security testing (SAST) and software composition analysis (SCA).
Work with development teams to identify methods to remediate vulnerabilities, evaluate existing workarounds, and troubleshoot false positives via manual code review.
Aid in the integration of the SAST and SCA process into shift-left processes (IDE, Pipelines, and Change Management Systems)
Participate in the implementation of new information security technologies or integration of existing technologies including initial configuration, installation, change management, and operational handoff
Take a new perspective on existing solutions to solve complex problems and exercise judgment based on the analysis (e.g. modeling, testing, etc.) of multiple sources of information.
Provide technical support of information security technologies, providing problem analysis and resolution in a timely manner and explain and interpret complex, difficult, or sensitive information.
Lead small cybersecurity projects with manageable risks and resource requirements; plays significant roles in larger, more complex initiatives.
Qualifications
Required Qualifications:
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Bachelor’s degree and five years of experience in systems engineering or administration or an equivalent combination of education and work experience
In-depth knowledge in applied enterprise information security technologies including but not limited to firewalls, intrusion detection/prevention systems, network operating systems, identity management, database activity monitoring, encryption, content filtering, and Mainframe security
Previous experience in planning and managing IT projects
Preferred Qualifications:
Master’s degree or MBA and 8 years of experience or an equivalent combination of education and work experience.
Other security certifications (e.g. CCNA Security, GSEC, GCED, GPPA, etc.)
Other technical Certifications (e.g. CCNA, RHCE, MCSE, etc.)
Experience on SAST or SCA Scanning Tool highly preferred
Experience with one or more additional programming languages
Experience with hands on remediation of vulnerabilities in developed codeset
Cloud Experience or Technical Certifications