Application Security Specialist

PRI Global
Charlotte, NC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Software System Penetration Testing Confluence JIRA Microsoft Azure Static Program Analysis Continuous Integration Github Network Security Scrum Methodology Power BI Secure Coding
+12 more
Software Vulnerability Management Grafana Software Security GWAPT Gitlab-ci Kubernetes Terraform Splunk Jenkins Servicenow Static Application Security Testing Dynamic Application Security Testing

Job description

Job Description: Look for someone who has Application Security experience, has worked closely with software developers, conducted threat modeling and secure coding activities, integrated security tools into CI/CD pipelines, and ideally built or led a Security Champions Program or Community of Practice. Leadership, enablement, training, and influencing engineering teams are more important than deep penetration testing or network security experience.

Requirements

  • Security Gates

  • Pipeline Security

  • Compliance Automation

  • Security Controls

  • Continuous Security Testing

Security Testing Tools

  • SAST

  • DAST

  • SCA

  • Static Analysis

  • Dynamic Testing

  • Software Composition Analysis

  • Vulnerability Management

Governance & Metrics

  • Security Metrics

  • KPIs

  • Dashboards

  • Compliance Reporting

  • Risk Management

  • Risk Register

  • Governance

  • Security Controls

Collaboration

  • Cross-Functional Leadership

  • Stakeholder Management

  • Program Management

  • Change Management

  • Community of Practice (CoP)

  • Security Champion Program, * Mend (WhiteSource)

CI/CD

  • Jenkins

  • GitHub Actions

  • GitLab CI/CD

  • Azure DevOps

Dashboards

  • Power BI

  • Grafana

  • Splunk

Collaboration

  • ServiceNow

  • Confluence

  • Jira

  • Microsoft Teams, * Ethical hacking
  • Red teaming
  • Bug bounty, * Kubernetes
  • Terraform
  • AWS deployment

Need AppSec ownership and security leadership. __________________

  1. Certifications to Prioritize

Strong:

  • CSSLP
  • CISSP
  • CRISC

Good:

  • GWAPT
  • GWEB
  • CASE
  • Security+

Nice to Have:

  • Scrum Master
  • SAFe
  • PMP

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www2.jobdiva.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all