Lawrence Harvey has partnered with a Financial Services firm in search for an Application Security professional to join their team.
Responsibilities:
- Conduct dynamic application security testing (DAST) and software composition analysis (SCA) scans to identify and address vulnerabilities.
- Collaborate with development teams to triage and remediate security findings from static (SAST), dynamic (DAST), and composition (SCA) scans.
- Help build the Security Champions program, promoting secure coding practices, patterns, and standards across our development teams.
- Integrate threat modeling into the software development lifecycle (SDLC), creating and maintaining models to anticipate and mitigate potential risks.
- Stay ahead of emerging security threats and industry best practices, continuously enhancing our security posture.
- Evaluate and select cutting-edge application security tools, processes, and standards.
Experience preferred:
- Strong well-rounded background in cybersecurity, specifically within Application Security; ideally 5+ years in such role
- Hands-on experience with DAST tools and familiarity with SCA tools.
- Strong understanding of common vulnerabilities and familiarity with OWASP Top 10
- Ability to define, initiate and lead an Application Security program
- Experience threat modeling, reviewing code, remediating vulnerabilities
- Proficiency in at least one programming language - ideally: Python, Java, Javascript
- Experience leveraging AI/LLM tools for automation
Preferred qualifications:
- Degree in Tech discipline: Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent
- Certifications: CISSP, CEH, CSSLP
Please note:
- The client is unable to transfer or sponsor visas at this time; US Citizen or GC only
- NO C2C