Cybersecurity Consultant IV

Kaiser Permanente
Burlington, NC, United States
10 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$121,000.0 - $156,530.0
Working hours
Shift work
Job source

Tech stack

Java (Programming Language) .NET Framework Agile Methodology Data Analysis Android Software Development Apple IOS Application Firewall Software System Penetration Testing Cloud Computing Security Static Program Analysis Cyber Security Computer Programming
+16 more
Databases Query Languages DevOps Dynamic Program Analysis Java Platform Enterprise Edition (J2EE) Mobile Application Software Object-Oriented Software Development Systems Development Life Cycle Software Engineering SQL Databases Web Services Software Security Information Technology Objective C++ Vulnerability Analysis Dynamic Application Security Testing

Job description

In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate. Essential Responsibilities:

  • Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities.
  • Practices self-development and promotes learning in others by proactively providing information, resources, advice, and expertise with coworkers and customers; building relationships with cross-functional stakeholders; influencing others through technical explanations and examples; adapting to competing demands and new responsibilities; listening and responding to, seeking, and addressing performance feedback; providing feedback to others and managers; creating and executing plans to capitalize on strengths and develop weaknesses; supporting team collaboration; and adapting to and learning from change, difficulties, and feedback.
  • Effectively communicates investigative findings to non-technical audiences.
  • Collaborates with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture.
  • Provides recommendations to management and business stakeholders on how to remediate issues identified through security testing processes.
  • Identifies the impact of security test plans on upstream and downstream solution components.
  • Supports information sharing and integration procedures across cyber security through the exchange of threat intelligence and cyber security vulnerability assessment data.
  • Contributes to cyber security intellectual capital by making process or procedure improvements, conducting brown bag training sessions, and creating new training documents.
  • Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis.
  • Recommends business line or business technology team security process improvements which align with sustainable best practices, and the strategic and tactical goals of the business.
  • Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across multiple business domains.
  • Performs complex security test data analysis in support of security vulnerability assessment processes, including root cause analysis.
  • Serves as an escalation point on issues, dependencies, and risks related to security testing.
  • Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately to highly complex technology initiatives across multiple IT domains by analyzing business and technology requirements.
  • Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems.
  • Provides insight and consultation on the development of testing scope and approach, and collaborates with cross-functional IT and business stakeholders to review the overall testing approach.
  • Validates security test scenarios across various SDLC phases (e.g., development, reproduction, production) for low- to moderately-complex projects.
  • Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams and management as appropriate.

Requirements

  • Minimum three (3) years software or application development experience.
  • Minimum one (1) year experience in application security (e.g., source code analysis, dynamic analysis, etc.).
  • Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum six (6) years experience in IT or a related field, including Minimum two (2) years in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement., * One (1) year experience in risk management, governance, or compliance.
  • Three (3) years software or application development experience.
  • Two (2) years experience in security penetration testing or related security research.
  • Two (2) years experience developing and/or implementing mobile applications.
  • One (1) year experience programming Java for the Android platform.
  • One (1) year experience working with Objective-C, Swift, or iOS.
  • Two (2) years experience in the design, engineering, implementation, and operations of cloud security technologies.
  • Two (2) years experience in database technologies.
  • Two (2) years experience using SQL or similar query language.
  • Two (2) years experience working with web services.
  • Two (2) years experience applying Agile development practices.
  • Three (3) years experience with J2EE, Java Stack, and/or .NET development technologies.
  • Three (3) years experience in object oriented application development.
  • Two (2) years experience working on cross-functional project teams

Benefits & conditions

Pay Range: $121000 - $156530 / year Kaiser Permanente strives to offer a market competitive total rewards package and is committed to pay equity and transparency. The posted pay range is based on possible base salaries for the role and does not reflect the full value of our total rewards package. Actual base pay determined at offer will be based on labor market data, internal alignment, and a candidate’s years of relevant work experience, education, certifications, skills, and geographic location. Travel: Yes, 10 % of the Time

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:25 min

Testing the AI generated Apple iOS Flashcards application

MIlan Todorović MIlan Todorović · WWC Europe 2026

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all