Sr. Information Security Consultant (AppSec Enablement and Insights)
Role details
Job location
Tech stack
Job description
We are seeking a skilled Application Security Consultant to strengthen the security posture of our applications across the development lifecycle.
The ideal candidate is well versed in application security overall and will interpret vulnerability data, perform control testing, and help application teams understand and address findings across multiple scanning disciplines.
This role works closely with development, DevOps, and domain security teams to support secure design, remediation, and control readiness., Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
- Conduct control testing and perform control validations across application security domains.
- Perform vulnerability analysis and remediation coordination for applications.
- Facilitate and advise application teams on remediation as needed, including vulnerability burndown.
- Assist with remediation support, vulnerability analysis, and metrics across AppSec domains.
- Produce program metrics, including burndown, aging, trend, and adoption.
- Assist in developing and refining application security standards, procedures, and intake workflows.
- Collaborate with DevOps teams to integrate security into CI/CD pipelines.
- Stay current with emerging application security threats, vulnerabilities, and technologies.
Requirements
- Strong understanding of application security and scanning disciplines, such as SAST, SCA, secrets, API, container, and IaC.
- Ability to interpret vulnerability data, including severity, CVSS, exploitability, and false positives.
- Experience with control testing, control validation, and evidence collection.
- Programming/scripting proficiency.
- Experience with vulnerability management platforms, including tools such as ServiceNow Vulnerability Response.
- Understanding of secure SDLC, CI/CD, and DevSecOps.
- Strong communication, analytical, technical writing, and documentation skills., The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Bachelor's degree in Computer Science, Information Systems, or related field.
- Minimum of 7 years of professional experience in information security.
- Advanced knowledge of data security, privacy laws, regulatory compliance, and advanced security technologies.
- Experience in threat analysis, vulnerability testing, incident response, and forensic methodologies., * Security certifications, including CISSP, CISM, GIAC, or equivalent.
- Familiarity with vulnerability management tools, including ServiceNow Vulnerability Response.
- Familiarity with cloud and container security tools.