Information Security Senior Analyst, Application Security

Tephra Inc.
Goodlettsville, TN
Full-time

Description : Job Description :

Job Description : GENERAL SUMMERY :

GENERAL SUMMERY :

Responsible for performing static and dynamic application security testing in order to identify vulnerabilities in applications that are storing, processing, or handling DG data.

This includes applying an appropriate security risk rating based on compensating controls and other mitigating factors, and identifying and conveying vulnerabilities in a manner that clearly defines the security risk to a given application - while providing developers additional guidance as to how a vulnerability should be remediated and properly re-tested to validate the effectiveness of remediation efforts.

DUTIES & RESPONSIBIILTIES :

  • Perform static and dynamic application security testing using a combination of commercial, open-source, and manual testing methods.
  • Conduct application security risk and compliance reviews and analysis identify, recommend, and track progress of security risk mitigation plans while collaborating with IT and business units to drive risk mitigation plans to completion.
  • Represent the information security department through pragmatic consultation and participation in a defined SDLC, promoting application security best practices and standards.

KNOWLEDGE, SKILLS, & ABILITIES :

  • Strong understanding of current and emerging application security and general information security best practices, technologies, techniques, trends, threats, and countermeasures, to include application security aspects related to cloud technologies.
  • Strong, effective written and oral communications skills and able to communicate to technical and non-technical audiences across multiple levels.
  • Strong, hands-on experience performing static and dynamic application security tests, assessments, etc. using commercial and other tool sets, manual testing methods, etc.
  • Strong negotiation skills (e.g., driving internal security recommendations, external vendor action, etc.).
  • Strong understanding of effective, pragmatic application security controls and related industry (e.g. OWASP) best practices risk management and compliance strategies and techniques and PCI, HIPAA, and SOX regulatory requirements.
  • Solid understanding of agile and waterfall development methodologies and the efficient and effective integration of application security design and testing processes.
  • Ability to learn and retain new skills to adapt to evolving business, technical, risk, and security needs.
  • Ability to work occasionally during non-standard shifts, in an on-call capacity, and able to travel as needed (up to 5%).

WORK EXPERIENCE AND / OR EDUCATION :

College degree or equivalent experience in information security with a minimum 5 years current / recent application security experience.

Active CISSP or CSSLP certification preferred.

  • Extensive hands-on experience in static and dynamic application security testing using a variety of manual testing methods, commercial and non-commercial tools, best-practice security frameworks (e.g., OWASP ASVS), etc.
  • Foundational experience with host operating systems, networking principles, web application firewalls, and associated security controls network / system vulnerability scanning tools security information and event management (SIEM) privileged user management (PUM) and governance risk and compliance (GRC).

Candidate Must Have : undefined

30+ days ago
Related jobs
Promoted
State of Tennessee
Nashville, Tennessee

Qualifying experience in one or a combination of the following area may substitute for the required education, on a year-for-year basis, to a maximum of four years: 1) information security program design and implementation, or 2) information security risk analysis and mitigation, or 3) information s...

Promoted
Diversified
Nashville, Tennessee

Senior Installation Technician (Electronic Security) - Travel. JobPosting","title":"Senior Installation Technician (Electronic Security) - Travel ","datePosted":"2024-09-09T00:00:00","validThrough":null,"description":"What part will you play?\n$5,000 sign-on bonus for external candidates. The Senior...

Promoted
Deloitte
Nashville, Tennessee

The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government F...

Promoted
Amazon
Nashville, Tennessee

The GSS Security Culture and Readiness (SCR) empowers customers to navigate the evolving security landscape with confidence and resilience, by fostering security leadership of tomorrow and a culture of security that is both effective and human-centric. DescriptionThe Global Services, Security (GSS) ...

Highmark Health
TN, Working at Home, Tennessee

The Principal Information Security Architect – Enterprise Technology serves as the most senior security architect and advanced technology analyst in the company. The Open Group Architecture Framework Certification (TOGAF), Certified Information Security Professional (CISSP), Certified Information Se...

Oracle
Nashville, Tennessee

As a Security Engineer with OCI you will be responsible for the delivery and performance of Oracle’s security solutions and infrastructure, to include end point protection and network access control security tool ownership. Maintain global enterprise security solutions and infrastructure delivering ...

N. Harris Computer Corporation - USA
Tennessee, United States
Remote

As the Cloud Security Analyst, you will utilize your wide area of expertise in access control management, cybersecurity, vulnerability management, risk management, incident management, security frameworks and other areas to provide security support for the Harris group of companies. Work with Inform...

KPMG-UnitedStates
Nashville, Tennessee

Advanced knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, or application security. Minimum ten years of recent experience with at least three of the following: Security Architecture, threat modelling experience, id...

Deloitte
Nashville, Tennessee

As a Senior Consultant in our Cyber Application Security team, you will be responsible for delivering Oracle Cloud Applications Security & Controls implementations and Risk Management Cloud (RMC) modules. You will become part of a team that advises, implements, and manages solutions across five vert...

LH Services Corp
Nashville, Tennessee

Maintain and enforce endpoint security policies and standards in alignment with corporate Governance, Security-Risk and Audit policies, procedures, industry regulation, best practices, and security frameworks (e. A motivated security professional eager to contribute to the improvement of Loews Hotel...