This position consults with Project Management, Product Management, Product Development and Engineering teams to enable them to build and enhance security in EWS products and Services in line with EWS and Industry standards.
Complete the Identification, measurement, control and minimization of security risks to information systems across a broad range of disciplines including application and host security.
Develop repeatable application security architectures working with internal and external partners to ensure that systems are placed within the relevant security zones based on the data they house and their purpose.
Serves as the point of contact for all Product security issues in assigned areas.
Works with architecture teams to ensure that all newly developed and legacy applications and infrastructure implementations are in line with security policy and compliance with the required frameworks (ISO, PCI, OWASP, NIST 800-53, etc.).
Advises and approves changes and architectures for assigned areas from a security perspective.
Evaluates all product business cases including functional and detailed design specs to ensure security standards are met.
Assists in the security incident response process as assigned.
Contributes to the development of Early Warning security policy and procedures.
Develop Threat Models, design and develop Security architectures and publish reference architecture/patterns for Products and drive companywide adoptions.
Document and evaluate the present risks and security issues that could impact the confidentiality, integrity and/or availability of the business (both internally and externally) by assisting in documentation, tracking and creating solutions for mitigation.
Lead efforts to work with internal and external penetration testing organizations to effectively scope Product Pentests that help identify and mitigate gaps in security controls.
Manages efforts with Product Development and Engineering teams to perform security analysis on all internally developed products and services.
Interacts with customer banks to gather yearly testing and security requirements, review penetration testing findings, mitigating controls and/or projects to rectify security vulnerabilities.
Drives Product and Stakeholder teams efforts in building Cloud Native applications by incorporating Cloud Security and Microservices Security best practices and industry standards.
Drives Product Security efforts in evaluating new technology stacks and frameworks that help stakeholder and business teams deliver innovative and secure solutions.
Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.
Requirements
Education and experience typically obtained through completion of a Bachelor’s degree in Computer Science, Engineering, Math or Physical Science
Typically 10 or more years of engineering, IT, or Information Security experience with a combined 6 years of application security or Security Architecture or Consulting or related IT or Information Security experience.
Advanced knowledge of relational databases, Windows, and Linux operating systems.
Effective interpersonal skills, with ability to present to peers and coworkers.
Advanced knowledge of operating system, application, network, and database security architectures.
Application development and/ or Software Security background.
Exposure to the Agile SDLC process.
Experience in Threat Modeling and control design.
Experience in designing security for Cloud hosted products.
Knowledge of Security Integration into CI/CD and experience in driving CI/CD adaptation for Security controls.
Advanced experience in analyzing technical issues and making recommendations for corrective action.
Demonstrate advanced understanding in the field of Information Security in terms of both concepts and technology.
Ability to manage information security related efforts.
Advanced understanding of vulnerability exploitation chaining.
Tech Stack
Cloud
Linux
Microservices
SDLC
Benefits
Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
12 weeks of Paid Parental Leave
Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.