Search jobs > Boston, MA > Information security

Sr. Manager, Information Security-Application Security

G-P
Boston, Massachusetts, US
$176K-$220K a year
Full-time

About the position :

If your skills, experience, and qualifications match those in this job overview, do not delay your application.

As a Senior Manager of Information Security - Application Security, you will help drive and implement the company’s application security program.

This position reports to the Sr Director of Information Security but works closely with Engineering, DevOps, Product, and other team leads across the organization to build security into the product lifecycle from design through deployment.

What you will do :

  • Manage a team of engineers / analysts and build resiliency into the team.
  • Evangelize application security fundamentals and act as a consultative partner to development teams.
  • Implement and leverage SAST / DAST / SCA security tools like Veracode and Snyk. Make recommendations on application security tools.
  • Guide and perform security activities including threat modeling and vulnerability analysis, code review, and security testing, ensuring teams are validating for OWASP Top 10 and CWE / SANS Top 25.
  • Triage application risks daily as identified by AppSec scanning tools to eliminate false positives and provide a well-vetted set of vulnerabilities to engineering.
  • Collaborate with engineering to drive the timely remediation of vetted risk and to implement creative solutions that increase operational effectiveness.
  • Generate, collect, and report on AppSec metrics on a regular basis.
  • Make recommendations on development processes and provide production application security support as needed.
  • Create and maintain technical documentation for the AppSec program.
  • Contribute to the development and delivery of security awareness and secure development training programs.

What we are looking for :

  • 10+ years of related work experience in the Application Security field.
  • Strong communication and relationship building skills with a high degree of comfort speaking with developers, IT executives, and business partners.
  • Strong experience managing & developing a high-performance team.
  • Strong experience performing security focused application design reviews, threat modeling, manual code reviews, container security, and ethical hacking.
  • Strong experience implementing and working with SAST / DAST / SCA security tools.
  • Deep knowledge of security vulnerabilities, being able to identify issues, assess risk, and provide remediation guidance.
  • Deep knowledge of authentication and authorization options and standards.
  • Strong experience using common security testing tools and techniques to perform security assessments with significant expertise in either web or mobile penetration testing.
  • Strong experience working with developers and knowledgeable about modern web, mobile, and API development practices.
  • Ability to read and write code in at least one programming language.
  • Knowledge of CI / CD practices and experience incorporating security requirements into a SDLC.

The annual gross base salary range for this position is $176,000-$220,000 plus an annual bonus opportunity.

G-P values its employees and offers excellent benefits and perks including generous paid parental leave, flexible time off, flexible spending accounts, medical Insurance, dental Insurance, vision Insurance, 401k, and sabbatical after 5 years of service.

J-18808-Ljbffr

10 days ago
Related jobs
Promoted
Ultra Electronics Ocean Systems, Inc.
Braintree, Massachusetts

We are looking for an experienced Information Systems Security Manager (ISSM) looking to take that next step. You will be responsible for maintaining the overall security posture of our accredited systems and serve as the principal advisor on all matters involving the security of these systems. Main...

Promoted
Boston Consulting Group
Needham, Massachusetts

The role will report to the head of Governance & Risk Management for BCG X and sit within BCG’s information Security risk management team, working closely with product and engineering, security and IT teams. The right candidate must be able to demonstrate understanding of the fundamental security co...

G-P
Boston, Massachusetts

As a Senior Manager of Information Security - Application Security, you will help drive and implement the company’s application security program. This position reports to the Sr Director of Information Security but works closely with Engineering, DevOps, Product, and other team leads across the orga...

Ultra
Braintree, Massachusetts

Maintaining a working knowledge of systems functions, security policies, technical safeguards, and operational security measures. Developing, maintaining, and overseeing the system security program and policies for our accredited systems. Ensuring compliance with cyber security policies, concepts, a...

Cabot Corporation
Boston, Massachusetts

Cabot has an exciting opportunity for a Sr Director of Information Security to join the Digital organization at one of our Cabot domestic locations in Boston or Billerica, MA. This critical role is ideal for someone passionate about leading Cabot’s global cyber and data security programs and oversee...

Company 1 - The Manufacturers Life Insurance Company
Boston, Massachusetts

The leader of our Information Security Risk Management efforts is responsible for the overall delivery of the enterprise Information Security oversight and challenge, approach across Manulife. This leader will be the content owner for Manulife enterprise Information Security related Standards, will ...

Securitas
Quincy, Massachusetts

Ensures site health and key performance indicator goals are met or exceeded; works with the Site Lead/ Sr Ops Manager to enhance security team effectiveness and performance. Job Title: Security Operations Manager. Must have leadership experience (strong knowledge of Security protocols, scheduling, t...

Thegradcafe
Boston, Massachusetts

Job Summary: We are seeking an experienced Security Architect with a strong background in application security, architecture reviews, and security risk assessments. Perform Security Risk and Assessments (SRA) for critical applications, identifying potential vulnerabilities and recommending enhanceme...

Deloitte
Boston, Massachusetts

As a Tax Senior Manager within the Global Information Reporting practice, you will be part of a diverse team that is currently leading the transformation and digitalization of the tax profession in the area of international tax transparency for the financial industry. Our Global Information Reportin...

GDIT
Norwood, Massachusetts

The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system. The ISSO is responsible for ensuring the appropriate operational se...