SWBC is seeking a talented individual that will be responsible for managing the company’s application security program to mitigate financial, legal, compliance, and privacy risks by identifying and eliminating vulnerabilities and facilitating delivery and maintenance of secure software. This role involves overseeing an enterprise-wide program, integrating security principles within the SDLC, ensuring compliance with regulatory requirements, and coordinating security training and standards for stakeholders. The manager collaborates with various teams under the CISO’s direction to develop and maintain secure infrastrucutre and applications; supporting multiple software engineering projects; including evaluating the security of software and applications. Additionally, the manager focuses on improving the software development lifecycle by embedding security early and often, ensuring robust security controls are in place, and continuously enhancing development and operations delivery and integration practices to produce secure, high-quality software. This position thrives in a fast-paced environment, leveraging the latest technology and development practices to achieve positive outcomes for the company and its clients.
Bachelor’s Degree in Computer or Software Engineering, Information Security, Cybersecurity, or related field from an accredited four year college or university. Master’s degree preferred.
Minimum five (5) years of extensive experience within an enterprise software development environment to include a minimum of two (2) years of specialized experience in Application Security.
Direct experience with and advanced knowledge of application and software development testing, verification, and remediation. Must be familiar with the principles of SDLC and separation of duties.
Direct experience developing and reviewing software development test plans.
Strong ability to strategize for the future, design controls, and define/generate reports and presentations to support recommendations.
Experience supporting vendor management programs and internal and external control assessments by auditors, clients, business partners, and other stakeholders.
Experience developing and maintaining an application catalog to support risk assessments.
Experience evaluating software development risk using relevant factors to assess the business impact.
Certified Secure Software Lifecycle Professional (CSSLP) required, or incumbent must be able to obtain certification within 6 months of hire.
GIAC Cloud Security Essentials (GCLD) certification desired.
Certified Information Systems Security Professional (CISSP) and Certified Cloud Security Professional (CCSP) highly desired.
AWS Certified Solutions Architect or DevOps Engineer Professional certification highly desired.
AWS Security Specialty certification highly desired.
Cloud Security Alliance (CSA) Certificate of Cloud Security Knowledge (CCSK) desired.
Knowledge of application security program management and OWASP’s Software Assurance Maturity Model (SAMM).
Knowledge of OWASP Application Security Verification Standard (ASVS) and Mobile Application Verification Standard (MAVS).
Knowledge of positive and negative security verification processes and methods including automated and manual reviews, scans, and testing.
Knowledge of Amazon Web Services.
Knowledge of JSON programming language desired.
Experience and understanding of the DevOps deployment pipeline and security considerations for each step of the CI/CD processes.
Experience using Microsoft Azure DevOps and its use within an enterprise software development lifecycle (SDLC).
Knowledge of Agile and Waterfall software development lifecycles and supporting systems such as Scrum and Kanban.
Knowledge the Payment Card Industry (PCI) Data Security Standard (DSS).
Knowledge of IT Security Operations.
Knowledge of Application Development/EDW/BI.
Knowledge of Cloud, Conversational UI, AI, and Machine Learning.
Knowledge of software engineering.
Demonstrated leadership and teamwork skills.
Excellent verbal and written communication skills with experience documenting software and application configurations and communicating with developers, architects, and administrators.
Self-starter with strong organization and project management skills and the proven ability to manage own time effectively.
Strong analytical skills with the ability to assess a question, risk, or an issue and respond appropriately and accurately.
Strong detail orientation and problem resolution skills in order to present results accurately and professionally.
Proficient Microsoft Office skills, including Word and Excel.
Excellent verbal and written communication skills.
Familiar with team development tools and source control, including Azure DevOps, GIT, etc.
Able to work as an essential part of a highly motivated business, technology, development teams.
Excellent communication skills and the ability to work with teams and external stakeholders are essential.
Able to use general office equipment including copy machine and phone system.
Proficient with MS Word and MS Excel.
SWBC is a Substance-Free Workplace and requires pre-employment drug testing.
Please note, SWBC does not hire tobacco users as allowed by law.
To learn more about SWBC, visit our website at www.SWBC.com. If interested, please click the appropriate apply button.