Full-Time

Senior Technology Manager

Application Security

Confirmed live in the last 24 hours

Bank of America

Bank of America

10,001+ employees

Provides banking and financial services globally

Fintech
Financial Services

Compensation Overview

$134.9k - $217kAnnually

+ Discretionary Incentive

Senior, Expert

Washington, DC, USA + 2 more

More locations: Chicago, IL, USA | Denver, CO, USA

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
Python
JavaScript
Java
.NET
AWS
Google Cloud Platform
Requirements
  • 7+ years of experience in cybersecurity with a focus on application security, vulnerability management, and cloud application security.
  • Proven experience in deploying, managing, and optimizing application security scanning tools, such as Invicti, Checkmarx, Veracode, or others.
  • Experience in cloud platforms (AWS, Azure, GCP) with a track record of implementing security policies and validating secure coding practices within cloud-native applications.
  • Familiarity with secure code review techniques, both automated and manual, and the ability to identify, evaluate, and address security vulnerabilities across various coding languages (e.g., Java, Python, JavaScript, .NET, etc.).
  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or a related field. Advanced degrees are preferred.
Responsibilities
  • Provide hands-on leadership in the deployment, configuration, and management of application security scanning tools such as Invicti and Checkmarx.
  • Design and implement application security strategies for cloud-based and on-premises applications, focusing on secure code development and vulnerability management.
  • Serve as a technical subject matter expert on secure coding practices, secure architecture, and vulnerability scanning methods.
  • Manage the configuration, customization, and automation of application security scanning tools, enabling comprehensive scanning in CI/CD pipelines.
  • Analyze scan results, triage security findings, and provide detailed remediation guidance to developers.
  • Conduct regular assessments of the scanning tools to optimize their efficiency and accuracy in detecting security vulnerabilities.
  • Validate that cloud applications adhere to secure coding practices by leveraging static and dynamic analysis tools.
  • Collaborate with cloud architects to design secure application architecture and enforce security policies within cloud environments (AWS, Azure, GCP).
  • Implement and review cloud security configurations, ensuring alignment with security frameworks such as CIS Benchmarks and NIST.
  • Develop and enforce secure coding guidelines and policies to standardize secure coding practices across development teams.
  • Support secure code reviews, manual penetration tests, and red-team exercises to identify and mitigate complex security flaws.
  • Organize and lead training sessions to enhance developer awareness of common vulnerabilities, security best practices, and secure coding techniques.
  • Evaluate the risk impact of identified vulnerabilities and prioritize remediation efforts based on criticality and business impact.
  • Ensure compliance with security standards (e.g., OWASP Top 10, SANS CWE Top 25) and regulatory requirements.
  • Prepare documentation and evidence for internal audits and external compliance assessments.
  • Stay informed about the latest cybersecurity threats, trends, and emerging technologies relevant to software application security.
  • Evaluate new Application Security CI/CD tools, technologies, and techniques to improve the organization's security posture and stay ahead of potential threats.
  • Define and monitor key performance indicators (KPIs) related to the effectiveness of security scanning tools and the remediation process.
  • Create dashboards and detailed reports to communicate security findings, risk metrics, and remediation progress to stakeholders.
  • Continuously improve the security scanning program by staying current on emerging threats, new vulnerabilities, and the latest security tools.

Bank of America provides a wide range of financial services to individuals, small and medium-sized businesses, and large corporations. Their offerings include banking, investing, asset management, and risk management products. The company serves around 56 million consumer and small business clients in the U.S. and is recognized as a leading wealth management firm. Additionally, Bank of America is a major player in corporate and investment banking, as well as trading. What sets Bank of America apart from its competitors is its extensive client base and comprehensive service offerings that cater to various financial needs. The company's goal is to help clients achieve their financial objectives through a diverse array of financial solutions.

Company Stage

IPO

Total Funding

N/A

Headquarters

Charlotte, North Carolina

Founded

1904

Simplify Jobs

Simplify's Take

What believers are saying

  • Bank of America is exploring blockchain for faster, secure cross-border payments.
  • The bank collaborates with fintech firms to enhance digital offerings.
  • It invests significantly in cybersecurity to protect customer data and maintain trust.

What critics are saying

  • Increased competition in the credit facility market may impact market share.
  • Large corporations raising capital through share sales could affect traditional banking services.
  • The rise of fintech platforms could disrupt traditional syndicated loan processes.

What makes Bank of America unique

  • Bank of America is a global leader in corporate and investment banking.
  • The company is committed to a $1 trillion sustainable finance goal by 2030.
  • It invests heavily in AI-driven customer service tools for enhanced user experience.

Help us improve and share your feedback! Did you find this helpful?