AdTechTalent
Engineering10 days agoHybrid

Epsilon

Senior Manager, Application Security

application securitysecure codingsecurity testingvulnerability managementthreat modelingCI/CDOWASPcryptographynetwork securitycloud securitysoftware developmentsecurity architectureautomation

Key details

Salary

$113K – $210K

Employment type

Full-time

Seniority

Senior

Years experience

10+

Location

Boston, United States; Chicago, United States; Irving, United States

Full job description

The role involves ensuring secure delivery of software applications by designing and implementing secure coding practices, conducting advanced security testing, and collaborating with development teams to integrate security throughout the development lifecycle. Responsibilities include code analysis for vulnerabilities, recommending remediation, supporting security architecture design reviews and threat modeling, improving security automation and CI pipelines, building trust with teams, driving security initiatives, contributing to security standards and documentation, and onboarding new teams to security platforms. Requirements include a BS/MS in Computer Science or similar, 10+ years of relevant experience, software development experience, knowledge of CI/CD platforms, application security testing tools (SAST, DAST, MAST, RAST, IAST), vulnerability management, software development methodologies, OWASP Top 10, programming and scripting, software design lifecycle, web and app security, cloud security, authentication and authorization, threat modeling, network security, and cryptography. Strong communication, problem-solving, and independent work skills are required. Salary range is $112,800 to $209,600 annually. Locations include Irving, Texas; Chicago, Illinois; and Boston, Massachusetts.

What you'll do

  • Perform code analysis of applications, manually and through application security testing solutions, to identify vulnerabilities
  • Provide context and rationalization for identified vulnerabilities
  • Review and recommend remediation actions for identified vulnerabilities
  • Drive and support security architecture design reviews and threat modeling of products
  • Improve accessibility of security through automation, vulnerability exception processing, embedding secure practices within continuous integration pipelines
  • Build trust relationships with teams to effectively achieve security goals
  • Drive cross-disciplinary initiatives to improve security of engineering ecosystem and products
  • Contribute to relevant security standards, processes, and formal documentation
  • Collaborate with teams to ensure understanding and compliance with security policies, standards, and best practices
  • Assist in onboarding new teams and applications to security platforms
  • Recommend and guide implementation of modifications and enhancements to evolve with the threat landscape

Requirements

  • BS / MS in Computer Science or similar degree
  • Minimum of 10 years of experience in related fields
  • Direct experience in software development
  • Direct experience with at least one or more CI/CD platforms
  • Direct experience with application testing (e.g., SAST, DAST, MAST, RAST, IAST)
  • Direct experience in application vulnerability management processes
  • Working knowledge of current software development methodologies
  • Working knowledge of OWASP Top 10 and CWE 25
  • Working knowledge of programming languages and scripting
  • Working knowledge of software design lifecycle
  • Working knowledge of web and app security stack (e.g., API security)
  • Working knowledge of cloud security concepts and technologies
  • Working knowledge of authentication and authorization flows in web applications
  • Strong understanding of threat modeling
  • Strong understanding of network security (e.g., WAF, Micro-segmentation)
  • Strong understanding of cryptography topics
  • Strong collaboration, interpersonal, written and verbal communication skills
  • Excellent problem solving, critical thinking skills
  • Ability to work independently and self-motivate

Tech stack

SASTDASTMASTRASTIASTCI/CDOWASP Top 10CWE 25API securitycloud securityauthenticationauthorizationthreat modelingnetwork securityWAFMicro-segmentationcryptography

Benefits

Flexible time off (FTO)15 paid holidaysPaid sick timeParental/new child leaveChildcare & elder care assistanceAdoption assistanceComprehensive health coverage401(k)Tuition assistanceCommuter benefitsProfessional developmentEmployee recognitionCharitable donation matchingHealth coaching and counseling

Apply now

Ready to take the next step in your career? Click the button below to continue to the application process.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.