Information Security Sr. Manager, Application Security

Tephra Inc.
Goodlettsville, TN
Full-time

Description : Job Description :

Job Description :

Title : Information Security Sr. Manager, Application Security

Department : IT Security

Reports to : CISO

Supervises : IS Sr. Analyst, IS Analyst

General Summary :

Responsible for working with the information security management team to administer the Company's information security programs maintain Sarbanes-Oxley, HIPAA, and PCI DSS compliance programs and support a variety of security systems and applications.

Recommends, designs, implements, and administers information security controls that meet dynamic tactical and strategic information security objectives.

Responsible for managing the application security team and associated program including, but not limited to : application security standards definition, publication, awareness and training, and compliance application security testing, tracking, reporting, and escalation application security regulatory compliance management application security risk monitoring, analysis, and reporting application security risk mitigation planning and coordination and budget planning, invoice management, personnel management, financial management, vendor relationship management, etc.

Duties and Responsibilities :

  • Perform static and dynamic application security testing conduct application security risk and compliance reviews and analysis identify, recommend, and track progress of security risk mitigation plans and collaborate with IT and business units to drive risk mitigation plans to completion.
  • Manage an effective, pragmatic application security program develop, maintain, and evangelize application security standards and procedures manage team personnel and financial resources ensure team members are appropriately trained and aware of performance expectations and manage customer engagement and service delivery.
  • Represent the information security department through pragmatic consultation and participation in a defined SDLC, promoting application security best practices and standards.
  • Promote security best practices via awareness and leadership by example monitor compliance with policies and regulatory requirements maintain audit readiness support internal and external auditors through effective and timely fulfillment of audit requests and assist in the development of audit responses and action plans.

Knowledge, Skills, and Abilities :

  • Strong understanding of current and emerging application security and general information security best practices, technologies, techniques, trends, threats, and countermeasures.
  • Strong, effective written and oral communications skills and able to communicate to technical and non-technical audiences across multiple levels.
  • Strong, hands-on experience performing static and dynamic application security tests, assessments, etc. using commercial and other tool sets, manual testing methods, etc.
  • Strong negotiation skills (e.g., driving internal security recommendations, external vendor action, etc.).
  • Strong understanding of effective, pragmatic application security controls risk management and compliance strategies and techniques and PCI, HIPAA, and SOX regulatory requirements.
  • Solid understanding of agile and waterfall development methodologies and the efficient and effective integration of application security design and testing processes.
  • Ability to learn and retain new skills to adapt to evolving business, technical, risk, and security needs.
  • Ability to work occasionally during non-standard shifts, in an on-call capacity, and able to travel occasionally (up to 5%).

Work Experience and / or Education :

College degree or equivalent experience in information security with a minimum six years information security experience, focused on application security.

Active CISSP, CISA, or CISM certification preferred.

Extensive hands-on experience in static and dynamic application security testing using a variety of manual testing methods, commercial and non-commercial tools, best-practice security frameworks (e.g., OWASP ASVS), etc.

Extensive experience holistically managing application security risk associated with architecture, design, operations, and support.

Foundational experience with host operating systems, networking principles, web application firewalls, and associated security controls network / system vulnerability scanning tools security information and event management (SIEM) privileged user management (PUM) and governance risk and compliance (GRC).

Candidate Must Have :

  • Extensive experience in pragmatic, holistic application security risk management.
  • Extensive hands-on experience in static and dynamic application security testing using a variety of manual testing methods, commercial and non-commercial tools, etc.
  • Foundational experience with host operating systems, networking principles, and web application firewalls network / system vulnerability scanning tools security information and event management (SIEM) privileged access management and governance risk and compliance (GRC).
  • Solid understanding of agile and waterfall development methodologies and how to efficiently and effectively integrate application security design and testing processes.
  • Minimum six years information security experience, focused on application security. Active CISSP, CISA, or CISM certification preferred.
  • 30+ days ago
Related jobs
Promoted
State of Tennessee
Nashville, Tennessee

Qualifying experience in one or a combination of the following area may substitute for the required education, on a year-for-year basis, to a maximum of four years: 1) information security program design and implementation, or 2) information security risk analysis and mitigation, or 3) information s...

Promoted
KOORSEN FIRE & SECURITY INC.
Nashville, Tennessee

Becoming the leader in the fire and security industry takes talent—yours. A test for Evidence of Substance Abuse by urinalysis test is required if this application results in an offer of employment. ...

Promoted
Accenture
Nashville, Tennessee

We blend risk strategy, digital identity, cyber defense, application security, and managed service solutions to rethink the entire security lifecycle. Accenture's more than 2,000 security professionals deliver holistic and proactive security solutions in 47 countries, and we'd love to discuss our op...

Promoted
Deloitte
Nashville, Tennessee

The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government F...

Promoted
KOORSEN FIRE & SECURITY INC.
Nashville, Tennessee

Project Manager in Security Division. Becoming the leader in the fire and security industry takes talent—yours. Manage the installation of Security products and systems, including; Intrusion, Video Surveillance, Access Control, Intercom, and Monitoring. Clearly communicate, and monitor project...

Dollar General
Goodlettsville, Tennessee

Strong understanding of current and emerging application security and general information security best practices, technologies, techniques, trends, threats, and countermeasures, to include application security aspects related to cloud technologies. Represent the information security department thro...

First Horizon Bank
Nashville, Tennessee

The Corporate Security Investigative Manager will be responsible for leading the efforts of the First Horizon Corporate Security Investigations department, which will include the management of internal and external fraud case data and oversight of the investigative process to ensure compliance and c...

Highmark Health
TN, Working at Home, Tennessee

The Open Group Architecture Framework Certification (TOGAF), Certified Information Security Professional (CISSP), Certified Information Security Manager (CISM), etc. The Principal Information Security Architect – Enterprise Technology serves as the most senior security architect and advanced technol...

Healthcare Systems and Technologies, LLC
Nashville, Tennessee

Analyze IT and business requirements and provide objective advice on the use of security requirements Plan, research, and perform security engineering for IT systems and applications (on-prem and cloud) Review existing security controls and recommend/implement improvements Perform information securi...

Walden Security
Nashville, Tennessee

Responsible for Operations Managers, Account Managers, and security personnel seven days a week. Oversees Operations Managers in meeting client needs; meets with clients regularly, listens to issues, and provides security and technical expertise and solutions. Capably utilizes WinTeam to produce rep...