Search jobs > Atlanta, GA > Principal security engineer

Principal App Security Engineer

Focus Brands
Atlanta, GA
Full-time

Essential Functions

Application Development Lifecycle SecurityIndependently ensure that identified software defects are properly triaged for false positives, correctly prioritized based on criticality, and mitigated.

Automate the discovery, profiling, and continuous security monitoring of code.Responsible for integrating the security toolset into the CI / CD pipeline.

Responsible for managing the current application security toolset and advising management on improvements. Accountable for managing our software supply chain by defining, documenting, and updating the program to include discovery and reporting of software bill of materials (sbom).

Accountable for inventory, document, monitor, and secure production APIs.Accountable for conducting threat assessments, building threat models, and creating remediation plans based on the results of threat assessments.

Perform or facilitate the performance of security risk assessments.Perform RFI and engage web application penetration testers as needed and by policy.

Anticipate need, initiate, and guide discussions on security strategy and architecture changes.Work with the privacy function to implement data protection requirements.

Vulnerability Disclosure ProgramResponsible for managing vulnerabilities identified by independent researchers and vetting them for accuracy.

Independently assess the vulnerabilities against risk and criticality, then manage them alongside other security defects.

Additional responsibilitiesDefine and develop the Application Security strategy and roadmap across people, process, and technology.

Create and perform necessary testing, scanning, and remediation of our internet-facing web applications with respect to compliance with Americans and Disabilities Act (ADA)Configure, troubleshoot, and manage the development environment Identity and Access ManagementEnsure that development and production application assets in the cloud are configured to support security policies including those for data at rest and data in transit.

Where assigned, manage the relationship with the vendor, including contract review and negotiation, performing quarterly business reviews, and creating performance and other reporting metrics.

Design security compliance metrics that align with Application Security requirements and assist with driving enforcement.

Assist with triaging potential security incidents

Job Summary

Focus Brands is on a journey to build out an industry leading Digital Platform which will power its seven existing brands and enable smooth integration of future brands.

The Application Security Engineer, Principal performs a critical role in our roadmap to deliver the most secure, privacy-focused, and compliant customer-facing brand websites.

Although the role is a part of the Information Security organization, the experienced incumbent will be embedded with development teams and data scientists and collaborate effectively with various teams within technology and product, and will be responsible and accountable for creating programs and driving the performance of secure software development practices, including addressing vulnerabilities and software security defects, and documenting and managing software supply chain threats and risks.

This opportunity will reward the incumbent with a chance to originate security programs, tasks, and methodologies to enable Focus Brands to build products to allow more customers to enjoy our iconic brands.

Travel Requirements

30+ days ago
Related jobs
Promoted
VirtualVocations
Norcross, Georgia

A company is looking for a Principal Security Engineer for a remote position. ...

Promoted
U.S. Bank
Atlanta, Georgia

US Bank is looking for a Principal Information Security Engineer to focus on web access information security projects. As a Principal Information Security Engineer at US Bank, you will be a technical leader with massive impact. US Bank Principal Information Security Engineers are pragmatic visionari...

Promoted
VirtualVocations
Norcross, Georgia

A company is looking for a Senior Application Security Engineer. ...

Focus Brands
Atlanta, Georgia

The Application Security Engineer, Principal performs a critical role in our roadmap to deliver the most secure, privacy-focused, and compliant customer-facing brand websites. Create and perform necessary testing, scanning, and remediation of our internet-facing web applications with respect to comp...

Truist
Atlanta, Georgia

Strong functional and technical knowledge of information/cyber security capabilities with deep expertise in one or more of the following areas: Encryption, Data Security, Application Security, End Point Security, Identity and Access Management, Windows/Unix/Linux Systems Security, Mainframe Security...

New Relic, Inc.
Atlanta, Georgia
Remote

Principal Software Engineer - Platform Security/Compliance Architect - (Remote). Principal Software Engineer - Platform Security/Compliance Architect - (Remote). You will collaborate with cross-functional teams, including engineering, security, legal and compliance to ensure our software complies wi...

Salesforce
Atlanta, Georgia

Our Security Software Engineering team builds and operates highly scalable, fault-tolerant, distributed systems to deliver cloud-scale security software services. You will have the unique opportunity to learn from the best industry security experts and integrate that into your software and service e...

Gusto
Atlanta, Georgia

We are looking for a Principal Software Engineer to join our Product Security Engineering team. We help developers ship secure code by building security tools and services, providing security training and expertise, and advocating for best practices in authorization and safe data handling across the...

Promoted
Lockheed Martin
Marietta, Georgia

You will be the Software Engineer Senior for the Mission Systems and Software team. As the Software Engineer Senior you will be responsible for all phases of developing software solutions for Command & Control Systems. Our team is within Mission Control Systems organization under Combat Systems and ...

Promoted
VirtualVocations
Norcross, Georgia
Remote

A company is looking for a Software Developer. Key Responsibilities:Maintain, enhance, and debug software applications built with VB. ...