> Markdown version of [/jobs/ext/2614696-senior-information-security-administrator](https://www.wearedevelopers.com/jobs/ext/2614696-senior-information-security-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Administrator - **Company:** Public Storage - **Location:** Frisco, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Applications Architecture, User Authentication, Microsoft Azure, C Sharp (Programming Language), Software as a Service, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Continuous Integration, Cross-Origin Resource Sharing (Ajax Programming), Data Validation, Data Security, Software Design Patterns, DevOps, Multi-Factor Authentication, Federated Identity Management, Identity and Access Management, Python (Programming Language), Key Management, Network Segmentation, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Cloud Services, JSON Web Token, Security Assertion Markup Language (SAML), Secure Coding, Web Application Security, Session Management, Mobile Security, Software Deployment, Software Engineering, Data Streaming, TypeScript, Software Vulnerability Management, Web Applications, Policy as Code, Data Logging, Enterprise Software Applications, Software Security, GWAPT, Kubernetes, Information Technology, Build Process, Api Design, Api Gateway, Software Coding, Devsecops, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** August 20, 2026 - **Apply:** https://dejobs.org/x/x/7F659E57FAB54E57AD4EC6500A13425C/job/ ## About the Role * Bachelor's degree in information security, Computer Science, Software Engineering, Information Technology, or related field; or equivalent combination of education and experience. * 5-8+ years of experience in cybersecurity, application security, secure software development, DevSecOps, cloud security, or related technology roles. * Strong development background with practical experience reading, reviewing, or writing code in languages such as Java, C#, JavaScript/TypeScript, Python, Go, or similar. * Hands-on experience performing secure code reviews, application risk assessments, vulnerability validation, and remediation guidance. * Working knowledge of web applications, API, authentication, authorization, encryption, session management, and secure data handling concepts. * Experience with application security testing tools such as SAST, DAST, SCA, container scanning, secrets scanning, IaC scanning, or similar platforms. * Understanding of cloud security fundamentals across Azure, AWS, or GCP, including IAM, logging, workload security, encryption, networking, and secure configuration. * Familiarity with CI/CD pipelines, repositories, build processes, release controls, and DevSecOps automation. * Ability to communicate technical findings clearly to developers, engineers, leadership, auditors, and non-technical stakeholders. * Strong analytical, troubleshooting, documentation, and prioritization skills., * Professional certifications such as CSSLP, CISSP, GWAPT, GWEB, CASE, Security+, CISM, Azure Security Engineer, AWS Security Specialty, Google Professional Cloud Security Engineer, or similar. * Experience with OWASP risks, secure coding standards, threat modeling, API security, mobile security, cloud-native security, Kubernetes/container security, or software supply chain security. * Experience supporting compliance frameworks such as SOX, PCI DSS, NIST, ISO 27001, SOC 2, or internal secure SDLC standards. * Experience with developer enablement, security champions programs, secure coding training, and application security metrics. * Familiarity with identity federation, OAuth, OIDC, SAML, JWT, MFA, PAM, secrets vaulting, and key management patterns. * Experience in enterprise, multi-site, regulated, or high-volume application environments. Core Competencies Application Security Development and DevSecOps Cloud and Enterprise Risk Secure code review Secure SDLC practices Cloud security control design Threat modeling and design review CI/CD pipeline security Risk-based prioritization API and web application security Developer partnership Compliance evidence support Vulnerability validation Automation mindset Technical leadership ## Description The Senior Information Security Administrator is responsible for strengthening the security of enterprise applications, cloud services, APIs, and development practices. This role partners closely with software engineering, DevOps, architecture, infrastructure, and business teams to identify and remediate application security risks, perform secure code reviews, guide secure design decisions, and embed security controls into the software development lifecycle. The ideal candidate combines hands-on application security experience, a strong development background, cloud security knowledge, and practical security operations expertise to reduce risk across the enterprise., * Lead or support application security assessments for internally developed, third-party, SaaS, cloud-hosted, web, mobile, and API-based applications. * Perform secure code reviews and provide actionable remediation guidance for common application security issues, including authentication, authorization, input validation, secrets exposure, insecure dependencies, API abuse, logging gaps, and insecure configuration. * Partner with development teams to implement secure coding practices throughout the SDLC, including threat modeling, design reviews, peer review standards, and release readiness checks. * Operate and improve application security tooling such as SAST, DAST, SCA, container scanning, IaC scanning, secrets detection, API security tools, and CI/CD security controls. * Review application architecture, data flows, cloud deployment patterns, and integration designs to identify security risks before production deployment. * Translate vulnerability findings into prioritized, risk-based remediation plans and work with application owners, developers, DevOps, and product teams to drive closure. * Secure application-side configurations, including encryption, session management, authentication flows, authorization models, logging, error handling, secure headers, CORS, API gateways, and secrets management. * Support cloud security control design and validation across platforms such as Azure, AWS, or GCP, including IAM, network segmentation, workload protection, logging, storage security, key management, and policy-as-code. * Advise on DevSecOps practices, including secure CI/CD pipelines, branch protection, dependency governance, artifact signing, container hardening, and environment separation. * Coordinate with security operations teams on application-related incidents, suspicious activity, exploit attempts, and remediation validation. * Support vulnerability management by validating exploitability, reducing false positives, documenting compensating controls, and tracking remediation evidence. * Develop and maintain application security standards, secure coding guidelines, design patterns, checklists, procedures, and technical documentation. * Support audit and compliance activities by providing evidence for secure development, change management, access controls, logging, vulnerability remediation, and cloud security controls. * Mentor developers, security analysts, and IT teams on application security concepts and practical remediation techniques., Sponsorship for Work Authorization is not available for this posting. Candidates must be authorized to work in the U.S. without restrictions or requiring sponsorship now or in the future. We do not provide training plans or support for F-1 OPT, STEM OPT extensions, or future visa sponsorship. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)