Vulnerability Management & Application Security Liaison SPOC

Delan Associates, Inc
Woodbridge Township, NJ, United States
5 days ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Artificial Intelligence Apache HTTP Server Apache Tomcat Automation of Tests Cyber Security Databases Continuous Integration Linux DevOps Middleware IBM Websphere Application Server
+13 more
PostgreSQL Microsoft SQL Server Windows Servers OpenShift Oracle (Applications) Service Pack Software Testing Automation Framework Software Vulnerability Management Software Security Checkmarx Devsecops Servicenow Static Application Security Testing

Job description

Analyze infrastructure-adjacent flaws by applying a solid understanding of Linux and Windows operating system vulnerabilities. Oversee containerized security within OpenShift Container Platform (OCP), ensuring image scanning findings are triaged effectively. Collaborate on data-layer risk, tracking and managing vulnerabilities related to databases (e.g., Oracle, SQL Server, PostgreSQL) and core middleware components (e.g., Apache, Tomcat, WebSphere). Cross-reference application flaws (Checkmarx/Black Duck) with host-level and container-level vulnerabilities to determine the true, contextual runtime risk. Automation & Platform Transformation Track IDP Adoption: Partner with Platform Engineering to ensure development squads migrate to the Internal Developer Platform, standardizing secure guardrails. Measure AI Security Adoption: Track and report metrics on how effectively developers utilize AI-driven security companions to triage and fix code flaws. Govern Test Automation: Collaborate with QA and DevOps to embed automated security gates seamlessly into continuous integration pipelines. Continuous Monitoring: Build dashboards that display automation maturity, remediation velocity, and the reduction of manual security operations. [1] Cross-Functional Orchestration & Governance Act as the primary SPOC aligning App Dev, AppSec, and Production Support teams to prioritize and resolve software flaws. Enforce remediation SLAs ensuring security patches are delivered according to corporate compliance and risk thresholds. Govern the Exception Management workflow, reviewing developer risk-acceptance requests and documenting temporary business justifications. Integrate security fixes with Change Management protocols (e.g., ServiceNow) to ensure production support stability remains intact during deployments. Local & Hybrid Expectations Work Structure: 2-3 days on-site, 2-3 days remote (Hybrid). Location Options: Iselin, NJ (Metropark) or Charlotte, NC (Corporate Hub).

Requirements

AppSec Tooling: Foundational knowledge 3+ years managing workflows in Checkmarx (SAST) and Black Duck (SCA). Infrastructure Stack: Strong foundational knowledge of Linux, Windows Server, OpenShift Container Platform (OCP), databases, and middleware technologies. Modern Engineering Frameworks: Practical understanding of Internal Developer Platforms (IDPs) and DevSecOps pipelines. Automation & AI: Direct experience tracking or managing test automation frameworks and AI-assisted coding/security tools.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all