Search jobs > Jersey City, NJ > Director engineering

Director - Application Security Engineering: Web Application Firewall (WAF)

finra
Jersey City, NJ
Full-time

Under general direction from Cyber and Information Security (CIS) Leadership, the Director of Application Security Engineering oversees the Secure Software Development Lifecycle (SSDLC), including all relevant tooling, processes, training and guidance to educate the organization's development community and help drastically minimize the security risks to its applications, data and hosting environment.

The Director defines or reviews relevant information security strategies, policies, and standards - most specifically focused on Web Application Firewall (WAF).

At FINRA, we infuse innovation into how we work. We use cutting-edge technologies like AI, machine learning, cloud computing, and big data analytics to protect investors and ensure market integrity.

As a result of our pioneering work, Computerworld ranked us #2 globally as a Best Place to work in IT among mid-sized companies in 2024.

Join our forward-thinking culture and elevate your career.

Manage a team focused on delivering high quality security testing, or secure development and operations, results within the Application Security Program.

This includes assignment coordination and training of subordinate staff, and backup coverage for next level management

  • Define, review or promote relevant security strategy, policies, standards, guidelines and procedures
  • Perform project management and status reporting to leadership on all major initiatives within the purview of the respective team
  • Create the team roadmap in alignment with organizational needs, any relevant business cases for new capabilities or staff to support the program, and oversee relevant budget planning and maintenance
  • Oversee the establishment and maintenance of processes and techniques used to identify, validate, and prioritize security risks on FINRA’s in-house and proprietary software applications, including both on-premises and AWS cloud-based hosting
  • Oversee secure software development or security testing for full SDLC from initiation to release for relevant technologies such as Java / J2EE, .NET or Python
  • Develop and implement strategies to promote consistent use of security controls across the enterprise
  • Oversee the execution of manual and automated secure software development activities by deploying, configuring, monitoring, or testing security controls, utilizing cyber security tools, to perform service security assessments, integrations, or operations
  • Identify, evaluate, and recommend new security technologies, techniques, and tools; prepare and deliver professional communications, including security assessment reports, status reports or dashboards and / or training briefings

Other Responsibilities

Education / Experience

Bachelor’s degree in Computer Science, Information Systems or related discipline with at least seven (7) years of related experience, or equivalent training and / or work experience;

Master’s degree and past Financial Services industry experience preferred.Experience must include direct experience in leading key areas such as : securing networks and systems architecture, design and implementation, secure software assurance, intrusion detection, defense and incident response, security configuration management, access controls design and implementation and security policy and standards development.

In-depth knowledge of more than one communications protocol.Experience managing several Cyber Security tools, including : Configuration Assessment, Log Aggregation, Integrity Verification, Web Application Security Testing, Network Access Control System, Network Intrusion prevention systems, and Endpoint Security Solutions.

Strong written and verbal technical communication skills.Demonstrated ability to develop effective working relationships that improved the quality of work products.

Should be well organized, thorough, and able to handle competing priorities. Ability to maintain focus and develop proficiency in new skills rapidly.

Ability to work in a fast paced environment.Excellent planning skills.Willingness to accept new challenges and grasp new or changing concepts, technologies and procedures.

In-depth knowledge across all areas of Information Security.

Work Conditions

Work is normally performed in an office environment. Occasional travel and extended hours may be required.

30+ days ago
Related jobs
finra
Woodbridge Township, New Jersey

Under general direction from Cyber and Information Security (CIS) Leadership, the Director of Application Security Engineering oversees the Secure Software Development Lifecycle (SSDLC), including all relevant tooling, processes, training and guidance to educate the organization's development commun...

Promoted
MokshaaLLC
NJ, United States

We are seeking a highly skilled and motivated Security Automation and Security Testing (SAST) Engineer to join our Information Security team. The successful candidate will be responsible for implementing and maintaining security testing frameworks, performing static code analysis, and ensuring the s...

Promoted
Efficus Inc.
Jersey City, New Jersey

Being a member of the Application Security team, you will be part of the Technology Risk initiative to support offensive security assessments on applications and provide SME guidance to key projects. The Application Offensive Security Consultant is responsible for providing technical direction and p...

Corebridge Financial
Jersey City, New Jersey

Knowledgeable in several application architectures (Client-Server, Web, Cloud Native and Distributed/Messaging) and the approaches that are used to maintain the availability and performance, the security, and recoverability each architectural pattern. The Application Management System (AMS) team is ...

Community FoodBank of New Jersey
Hillside, New Jersey

As the Assistant Director of Application, you will work to service, build, and enhance our portfolio of applications. You will troubleshoot complex application issues that involve SAAS applications, custom built applications, and a variety of integrations between systems. Manage the Run Operations a...

Enterprise EQ
Jersey City, New Jersey

Be a subject matter expert and respond to any security engineering questions/ requests related to Application Defense enhancements7. Hello, Client: Financial Industry Position: Application Offensive Security Consultant Location: Jersey City, NJ 07310 (HYBRID ROLE) Duration: 06 Months - CON...

Alliance of Professionals & Consultants, Inc.
Jersey City, New Jersey

As a Senior Web Application Developer, you will play a key role in designing, developing, and maintaining high-quality web applications while also overseeing and implementing data integration processes. Web Application Development: Develop, test, and deploy scalable web applications using modern tec...

Wakefern Food Corp
Woodbridge Township, New Jersey

The full-stack developer will be front end focused and will work within the Web and Client Applications team. Applications are built on variety of platforms including Azure and internal web servers. They are responsible for development and support of various e-commerce (customer facing and internal)...

eTeam Inc
Jersey City, New Jersey

Being a member of the Application Security team, you will be part of the Technology Risk initiative to support offensive security assessments on applications and provide SME guidance to key projects. The Application Offensive Security Consultant-Secure Code Reviewer is responsible for providing tech...

JPMorgan Chase & Co.
Jersey City, New Jersey

Web application development experience. Drive significant business impact through your capabilities and contributions, and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of challenges that span multiple technologies and applications. Regularly leads and me...