- Location
- Atlanta, GA, US
- Type
- Full-time
- Department
- Security
- Seniority
- Director
- Education
- Bachelor
- Closing date
- Today
- Source
- iCIMS
Description
Overview
Job Purpose
As a Director in this role, you will lead two teams responsible for assuring secure software development and cloud security through education, continuous testing, and consultation.
Responsibilities
- Competently differentiates FUD and hype from legitimate business risk and assigns practical severity ratings to detected weaknesses
- Demonstrates compromise of detected vulnerabilities to educate and motivate development teams
- Adopts and improves on an established education, testing, and remediation methodology. Innovates and ensures all areas of the programs are operated effectively and results are distilled into meaningful metrics. Articulately codifies and communicates the Application and Cloud Security programs through writing and discussion
- Recruits, retains, and motivates highly talented staff and balances the need to allocate tasks efficiently with the need to keep talent engaged, challenged, and growing
- Successfully run an established enterprise AppSec program at scale, with 2,000+ applications and a large pool of developers
- Coaches and develops team leaders, including newer leadership hires, within an already high-performing, well-structured team
- Committed to continuous education and being a recognized industry leader in Application and Cloud Security
- Application Identification and Review: is responsible for maintenance, execution, and reporting of the AppSec assurance tasks from Design Review through operating a Bug Bounty program
- Standards and Policies: owns the Application Development Security Policy and is responsible for timely, practical updates, communication, and education
- Secure Design: establishes security requirements early in the SDLC and contributes security subject matter expertise during the development of new projects and releases
- Tool Management: implements and maintains cutting-edge technology to assess and protect applications and cloud environments throughout the SDLC and post deployment
- Evaluates and applies AI and machine learning capabilities within the AppSec space, including AI-assisted vulnerability detection, AI-powered code review and testing tooling, and securing AI-integrated development pipelines
- Developer Education: keeps software engineers apprised of secure coding practices and builds strong rapport and respect with the ICE application development community
- Cloud Practitioner: provides security leadership and solutions to business and technical teams as they look to build or buy products in the cloud
- Bug Bounty Program: operates a responsible disclosure program that appropriately incentivizes and fosters positive relationships with security researchers
Knowledge and Experience
- Bachelor's degree in Computer Science, Engineering, MIS, CIS, or a related discipline
- Hands-on or program-level experience applying AI in the AppSec space
- Software engineering experience in Java, C++, Python, and/or related languages
- Hands-on experience with information security and related technologies
Preferred Skills
- Background in financial services or a comparable regulated enterprise environment
- Technical expertise and understanding of AWS and/or Azure cloud platforms
- Hands-on experience with information security and related technologies
- Participation and leadership in Application Security consortia such as OWASP
#LI-LG