Search jobs > Newark, NJ > Application security

Specialist, Application Security

Prudential Financial
Newark, NJ, USA
Full-time

Job Classification :

Technology - Information Security

Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency?

The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career all while growing your skills and advancing your profession at one of the world’s leading financial services institutions.

Your Team & Role

As a Specialist, Application Security in the Application Security team, you will partner with other security professionals across the Information Security Office, the Chief Technology Office, and other engineering groups in Prudential to advance Prudential’s application security program.

In this role, you would be responsible for efforts to secure modern applications and ensuring secure by design development best practices across all digital assets in alignment with industry standards.

You will track and govern risk reduction. You will work with partner organizations to consult on implementation efforts, mature operational processes and enable automation CI / CD controls for enforcement and monitoring.

In addition to applied experience, you will bring excellent problem solving, communication and teamwork skills, along with agile ways of working, strong business insight, an inclusive leadership attitude and a continuous learning focus to all that you do.

The ideal candidate will have a deep understanding of modern application architecture, cloud-native security, and DevOps practices.

Forward-thinking is required for this role to include focus on how to securely develop systems, enable self-service and incorporate capabilities for Security to scale and defend against evolving threats.

Here is What You Can Expect on a Typical Day

  • Function as the escalation point for all daily operational work as well as project work from more junior staff on the team.
  • Leverage AppSec tool / process specific knowledge to resolve complex technical / process / people problems the team faces.
  • Leverage organizational and industry knowledge to bridge gaps between the AppSec / DevOps teams and internal IT / business teams to ensure the team has the information and resources they need to meet team goals.
  • Partner with leadership to set direction for the future of the AppSec program, while ensuring an accurate understanding and in-depth knowledge of daily operations to provide team recommendations.
  • Maturing existing vulnerability and configuration monitoring capabilities for open source, third party and first party code and applications.
  • Collaborate with cross functional teams to integrate security best practices into development and operations, implement these as controls.
  • Mature and develop / design and assist in implementing security policies and alerting mechanisms in our security stack based on SOX and NIST standards.
  • Assist in vetting new software solutions and provide guidance and support to the other teams.
  • Employ a variety or qualitative and quantitative analysis techniques to continually improve user experience.
  • Promote the adoption of secure-by-design principles and practices throughout the software development lifecycle.
  • Validate proper mitigation controls are in place until remediation activities are complete.
  • Ensure reporting metrics relay proper risk posture to leadership and evolve as necessary support.
  • Revise processes and procedures, metrics, and documentation that continue to improve the AppSec program capabilities.
  • Provide proof-of-concept exploits in a lab environment to demonstrate exploitability and provide validation of proposed / implemented remediation actions
  • Experience with common vulnerability feeds from government, vendor, and open-source communities
  • Understanding of threat actors with the ability to articulate how they operate and demonstrate how they subvert common security controls
  • Understanding of the OWASP Top 10. Familiarity with vulnerabilities in 3rd party libraries and remediation
  • Scripting / programming skills (e.g., Python, PowerShell)
  • Work with IT peers and business stakeholders to ensure remediation efforts adhere to corporate standards and policies
  • Create technical documentation and SoPs to support internal security processes.
  • Ability to collaborate extensively with engineering teams to help them understand their application vulnerabilities and assist them to develop remediation and mitigation strategies.
  • Implement security improvements by assessing current situation, evaluating trends, and anticipating requirements.
  • Define requirements to automate the application related requirements for orchestration and workflow tools needed to assess and manage application security posture.

The Skills & Expertise You Bring

  • Bachelor of Computer Science or Software Engineering or experience in related fields
  • Leverage diverse ideas, experiences, thoughts, and perspectives to the benefit of the organization
  • Experience with agile development methodologies and Test-Driven Development (TDD)
  • Knowledge of business concepts tools and processes that are needed for making sound decisions in the context of the company's business.
  • Experience with OWASP
  • Experience with SAST, SCA, DAST, ASPM tools
  • Strong understanding of software composition analysis and SBOMs.
  • Ability to learn new skills and knowledge on an on-going basis through self-initiative and tackling challenges.
  • Excellent problem solving, communication and collaboration skills.
  • Ability to adjust communicate style to the target audience with a proficiency in communicating technical and business risk

Applied experience with several of the following :

  • Identifies opportunities for process and technical security improvements in the environment
  • Excellent communication, presentation, writing and documentation skills
  • Follow-up and attention to detail.
  • Good deductive reasoning skills, creative thinker.
  • Analytical and detail-oriented individuals must have a passion for information security, creativity to identify gaps and initiative to find the appropriate solutions to fill needs
  • Understand and able to create queries to support data extraction correlation and reporting
  • Candidates must be skilled in technical risk assessments, risk rating, threat correlation, asset-based remediation management, and reporting.
  • Candidates must be familiar with various vulnerability and security scanning tools, should be familiar with CVEs, CVSS, Secunia, and MITRE as well as other industry specific vulnerability classification standards, frameworks, and best practices.

Preferred qualifications :

  • GIAC Web Application Penetration Tester (GWAPT)
  • CompTIA Advanced Security Practitioner (CASP+)
  • GIAC Cloud Security Automation (GCSA)
  • IT Security certification beyond intro level certifications, (e.g., GCFA, GCIA, GNFA, GCTI, GREM, GCIH, GCFA, GPEN, OSCP, etc.).
  • Cloud (AWS, Azure, GCP, etc.) Certs
  • Other Security Certifications beyond intro level

You’ll Love Working Here Because You Can

Join a team and culture where your voice matters; where every day, your work transforms our experiences to make lives better.

As you put your skills to use, we’ll help you make an even bigger impact with learning experiences that can grow your technical AND leadership capabilities.

You’ll be surprised by what this rock-solid organization has in store for you.

4 days ago
Related jobs
Prudential Financial
Newark, New Jersey

As a Specialist, Application Security in the Application Security team, you will partner with other security professionals across the Information Security Office, the Chief Technology Office, and other engineering groups in Prudential to advance Prudential’s application security program. Define requ...

Promoted
D Aceto Services LLC
Jersey City, New Jersey

D Aceto Services LLC is seeking a motivated and detail-oriented Entry-Level Data Analyst to join our team. Help maintain data integrity and accuracy within databases. In this remote position, you will work closely with various departments to analyze data, generate insights, and support decision-maki...

Promoted
Source EQ
Paramus, New Jersey

Word processing software; spreadsheet software/advance Excel knowledge internet software and database software. ...

Promoted
Hackensack Meridian Health
Nutley, New Jersey

All Security Officers will assume responsibility for the safety and well-being of Students, Team Members, visitors and IHSC Campus property. Always keeps Senior Officer informed of all matters pertinent to safety and security conditions. Previous experience as Security Officer, Law Enforcement exper...

Promoted
ADP (Automatic Data Processing)
Parsippany-Troy Hills, New Jersey

The Senior Business Systems Analyst / Data Analyst role combines deep data analysis, communications, and reporting. With a passion to work at the intersection of data, business, and technology and to drive innovative data protection and remediation solutions, the successful candidate must be ambitio...

Promoted
MDMS Recruiting LLC
Jersey City, New Jersey

The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations), internal (company policies) requirements and industry frameworks (NIST CSF, ISO 27001, FFIEC CAT) as well as working with other IT and security teams to impl...

Promoted
Starkflow
Jersey City, New Jersey

Being a member of the Application Security team, you will be part of the Technology Risk initiative to support offensive security assessments on applications and provide SME guidance to key projects. The Application Offensive Security Consultant is responsible for providing technical direction and p...

Promoted
Verisk
Jersey City, New Jersey

As an Application Security Analyst III, you will play a key role in securing our applications by managing the full lifecycle of Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST), handling bug bounty submissions, and advancing our secure software development l...

Englewood Health
Englewood, New Jersey

With its high-quality, culturally sensitive inpatient care, outpatient services, and community health and wellness programs, Englewood Health delivers a healthcare experience that puts patients at the center. It is recognized as a 2022-23 Best Regional Hospital by US News & World Report, holds t...

Newark Beth Israel
Newark, New Jersey

The RWJBH Security Officer ensures a safe and secure environment for all patients, visitors, and staff with blend of vigilance and compassionate service, you will be part of a team that represents the Organization using a positive attitude when on duty in all interactions. The officer balances the d...