Search jobs > Louisville, KY > Application security

Application Security Principal

PPL Services Corporation
Louisville, Kentucky, US
Full-time

Responsibilities

Core Responsibilities

  • Work with Product Development teams to help prioritize and validate urgency of mitigation of identified product vulnerabilities and security feature enhancement requests.
  • Define security best practices and standards and ensure Product Development teams understand them and receive pertinent annual secure coding training.
  • Develop and maintain the application security architecture, ensuring that it aligns with overall security strategy and standards.
  • Evaluate, implement, and manage security tools and technologies that enhance the security posture of applications.
  • Conduct risk assessments for applications to identify potential vulnerabilities and threats, develop strategies to mitigate these risks.
  • Oversee and coordinate security testing activities, including static code analysis, dynamic application security testing, and penetration testing.
  • Perform system hardening and remediation to effectively guide developers and system administrators in addressing vulnerabilities and implementing security controls.
  • Perform security assessments, penetration testing, and code reviews to identify potential flaws in codes and mitigate vulnerabililties.
  • Analyze security needs and software requirements to determine feasibility of design within time and cost constratints and security requirements.
  • Perform threat modeling, risk assessment, and vulnerability management to identify potential security risks and work with development teams to implement appropriate security controls.
  • Provide guidance and training to development teams on secure coding practices and promote security awareness across the organization.
  • All other duties and projects as assigned.

Qualifications

Education

Bachelor’s degree in computer science, Information Security, or a related field.

Experience

  • A minimum of 10+ years of experience using penetration testing tools like Burp Suite.
  • Experience in application security tools and IDE Plug-in environments, including HP Fortify.
  • Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
  • Expertise in system hardening and remediation.
  • Proficiency in security assessments, penetration testing, and code reviews.
  • Expertise in threat modeling, risk assessment, and vulnerability management.
  • Knowledge of federal compliance standards, including NIST 800-53 and NIST CSF.
  • Strong leadership, communication, and interpersonal skills.
  • Collaborative and effective in cross-functional team environments.
  • Strong analytical skills to assess risks and vulnerabilities in complex systems.

Preferred Qualifications

  • Professional certifications such as CISSP, CSSLP, or CEH
  • Cloud Technology Expertise : Demonstrate a working knowledge of various enterprise technology stacks used to build applications in the cloud.

Your understanding of cloud infrastructure will enable you to assess secruity aspects unique to cloud-based mobile applications and API's.

Cloud Platform Experience : Possess working knowledge and practical experiences in security testing within cloud platforms, particularly Azure.

Your familiarity will be crucial for assessing the secruity of cloud-hosted mobile applications and APIs.

  • Proficiency in scripting and automation for security testing.
  • 30+ days ago
Related jobs
PPL Services Corporation
Louisville, Kentucky

Develop and maintain the application security architecture, ensuring that it aligns with overall security strategy and standards. Evaluate, implement, and manage security tools and technologies that enhance the security posture of applications. Oversee and coordinate security testing activities, inc...

Promoted
D Aceto Services LLC
Louisville, Kentucky

D Aceto Services LLC is seeking a motivated and detail-oriented Entry-Level Data Analyst to join our team. Help maintain data integrity and accuracy within databases. In this remote position, you will work closely with various departments to analyze data, generate insights, and support decision-maki...

Promoted
Strategic Education Inc.
Louisville, Kentucky

Bachelor of Engineering in Computing, Software Engineering, or related field or foreign equivalent. Participates as a technical expert in the design, development, coding, testing, and/or debugging of major new software and/or significant enhancements to existing software which may include applicatio...

Promoted
PMI (Project Management Institute)
Louisville, Kentucky

JobPosting","title":"Manager, Video","datePosted":"2024-09-30T00:00:00","validThrough":null,"description":"How will you make a difference to PMI?\n\nPMI is looking for a Video Manager who will be accountable for bringing PMI's brand and purpose to life through video. PMI is looking for a Video Manag...

Promoted
Allied Universal
Louisville, Kentucky

As a Security Officer, you will serve and safeguard clients in a range of industries such as Commercial Real Estate, Healthcare, Education, Government and more. Allied Universal, North America's leading security and facility services company, provides rewarding careers that give you a sense of purpo...

Promoted
Verizon
Louisville, Kentucky

Your focus on technical solutions will drive new opportunities and go-to-market strategies across our Business Internet, Cybersecurity, Unified Communications, and other solution portfolios. Celebrate wins and provide guidance on effective positioning through sharing best practices for identifying s...

Promoted
Thrive
Louisville, Kentucky

Are you a forward-thinking, strategic software developer with a passion for solving complex challenges? At Louisville Geek, we’re looking for someone who thrives in a fast-paced environment, who is confident and loves a challenge. You’ll be designing, developing, and maintaining cutting-...

Promoted
Michelin North America
Louisville, Kentucky

Control Systems Engineer (Entry/Experienced). Michelin has an immediate opportunity at our American Synthetic Rubber Company (ASRC) plant in Louisville, KY for a Control System Engineer to maintain and modify the control systems of the site in a high paced, dynamic, operational facility. Computer En...

Promoted
BrightSpring Health Services
Louisville, Kentucky

Assists in updates to enterprise information security policies, technical standards, guidelines, and procedures necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls. Develop and implem...

Promoted
Abel Construction
Louisville, Kentucky

The Project Manager provides overall leadership and administration to the construction project and assists in establishing project specific objectives and policies. If you're looking for a place where your contributions are valued and your career can flourish, ABEL is the best choice for you!We are ...