Motion Recruitment
Lead Application Security Engineer
Job Location
Plano, TX, United States
Job Description
Lead Application Security Engineer
Our Client's Global Application Security Program is responsible for integrating automated security testing into both CI/CD pipelines and continuous monitoring to identify and manage security risks in applications. The mission is to make security risks visible and actionable to the business and ensure that vulnerabilities are addressed promptly and effectively. You will be involved in leading a team of application security engineers, driving the integration of automated security tools into CI/CD pipelines, and developing innovative scalable full-stack solutions, middleware, and automation solutions. You will be responsible for translating strategic application security objectives into actionable plans, providing expert guidance on vulnerability triage and remediation, and fostering a culture of proactive security across the organization. Your leadership will be key in defining plans, developing metrics and KPIs, and continuously improving our security practices to ensure the highest standards of protection for our applications.
Contract Duration: 6+ month Contract; potential Contract to Hire
Hybrid; Onsite 3/days in Plano, TX
Required Skills & Experience
Non-technical Skills
Distinctive Attributes
What You Will Be Doing
You will receive the following benefits:
Motion Recruitment Partners (MRP) is an Equal Opportunity Employer, including Veterans/Disability/Women. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP's Employment Accommodation policy. Applicants need to make their needs known in advance.
Posted by: Theresa Schermer
Specialization: Security Engineering
Location: Plano, TX, US
Posted Date: 12/1/2024
Our Client's Global Application Security Program is responsible for integrating automated security testing into both CI/CD pipelines and continuous monitoring to identify and manage security risks in applications. The mission is to make security risks visible and actionable to the business and ensure that vulnerabilities are addressed promptly and effectively. You will be involved in leading a team of application security engineers, driving the integration of automated security tools into CI/CD pipelines, and developing innovative scalable full-stack solutions, middleware, and automation solutions. You will be responsible for translating strategic application security objectives into actionable plans, providing expert guidance on vulnerability triage and remediation, and fostering a culture of proactive security across the organization. Your leadership will be key in defining plans, developing metrics and KPIs, and continuously improving our security practices to ensure the highest standards of protection for our applications.
Contract Duration: 6+ month Contract; potential Contract to Hire
Hybrid; Onsite 3/days in Plano, TX
Required Skills & Experience
- Proficient in at least one programming language (Java, C#, Go) and scripting language (Python, bash, PowerShell).
- Proficient in at least one database management system and query language (MSSQL, PostgreSQL, etc.)
- Proficient in developing full-stack applications and rapidly prototyping solutions to support automated data collection, aggregation, and analysis.
- Proficient in integrating and managing automated security tools within CI/CD pipelines.
- Proficient in application security vulnerabilities and remediation techniques (e.g., OWASP Top Ten).
- Proficient in developing and monitoring metrics and KPIs.
- Experience with application security testing tools (Synopsys, OpenText Fortify, Invicti, Snyk, Semgrep, etc.)
- Experience with modern CI/CD tools and practices, and their integration into the development lifecycle (Jenkins, Azure DevOps, GitHub Enterprise, Circle CI, Heroku, etc.)
- Experience with public cloud services (Azure, AWS, Alibaba).
- Experience with Centralized Findings Management Systems (e.g., ServiceNow VR/AVR, PlexTrac, DefectDojo, ThreatFix).
- 7+ years in software development; or master's degree in computer science/engineering or related cyber field, and 5 years of relevant experience.
- 2+ years in a leadership or senior role within application security.
- Experience with implementing and managing Web Application Firewalls (Fortinet FortiWeb, Imperva Cloud WAF, Cloudflare WAF, Akamai Kona, MS Azure WAF, AWS WAF, etc.).
- Experience with CMS application security (Wordpress, Drupal, Joomla, Elementor, OpenText TeamSite, Concrete CMS, etc.).
- Experience with generative AI technologies.
Non-technical Skills
- Excellent leadership and team management skills.
- Strong communication skills, both verbal and written.
- Ability to translate strategic vision into actionable plans.
- High level of integrity and ethical standards.
- Ability to lead and mentor junior engineers.
- Excellent problem-solving, analytical, and critical thinking skills.
- Demonstrated ability to autonomously make high-judgment decisions and take calculated risks.
- A proactive and positive team player who is impact-focused, driven, curious, analytical, and a self-starter.
- Ability to establish trust relationships and influence others to positively impact the security posture and the business.
- Flexible and adaptive to support a dynamic and global environment with diverse stakeholders and ambiguity.
- Solid customer orientation with excellent oral and written communication skills in English.
- Must be able to operate extremely well under pressure.
Distinctive Attributes
- Demonstrated ability to innovate and drive continuous improvement.
- Strong mentorship and coaching capabilities.
- Ability to handle high-pressure situations with a calm and methodical approach.
- Ability to lead globally dispersed teams to achieve a unified outcome.
- Experience driving large-scale risk reduction initiatives across Fortune 500 organizations.
- Ability to weigh the relative costs/benefits/trade-offs of potential actions and identify the best resolution.
- Information Security certifications such as CISSP, OSCP, GPEN, GWAPT, GXPN, GSE are a plus.
- Ability to organize tasks, manage time, and prioritize actions to meet business needs.
What You Will Be Doing
- Drive the development and execution of the application security strategy by translating high-level objectives into actionable plans. Lead and inspire the team to achieve these goals, ensuring alignment with overall organizational security initiatives and fostering a culture of proactive security.
- Develop technical documentation (i.e. system design, architecture diagrams, data flows, functional specifications).
- Contribute to defining the future state of cybersecurity within the organization by conducting technical assessments between current state and the desired state across security tools and services.
- Develop program metrics, continuously measure progress and Impact and drive improvements.
- Collaborate with the Senior leadership and cross-functional teams including DevOps, development teams, security operations, data and analytics, enterprise architecture, Platform team, and sector functions.
- Implement and manage automated security tools within CI/CD pipelines. Ensure seamless integration and operation to enhance security posture.
- Integrate and operate a centralized findings management system to efficiently manage and track security vulnerabilities and remediation efforts.
- Define and implement a strategy to ensure automated security tools are configured to operate in an optimal fashion. Establish and monitor key performance indicators (KPIs) to constantly measure effectiveness and make necessary adjustments for continuous improvement.
- Develop and maintain green field automation solutions and full stack applications to support and enhance application security.
- Provide expert triage and remediation guidance for security vulnerabilities. Assist and mentor team members and other engineering teams in understanding and addressing security issues.
- Foster a collaborative environment, promote knowledge sharing, and mentor junior engineers to build a strong, skilled security team.
- Continuously research and raise novel concepts to improve the application security posture of the business. Stay updated with the latest security trends, tools, and practices.
- Execute projects, objectives, and deliverables in alignment with the team's vision, mission, and goals.
- Create and deliver training sessions; mentor junior team members; and engage in knowledge transfer sessions, technical design reviews, security reviews, and business review meetings.
You will receive the following benefits:
- Medical Insurance - Four medical plans to choose from for you and your family
- Dental & Orthodontia Benefits
- Vision Benefits
- Health Savings Account (HSA)
- Health and Dependent Care Flexible Spending Accounts
- Voluntary Life Insurance, Long-Term & Short-Term Disability Insurance
- Hospital Indemnity Insurance
- 401(k) including match with pre and post-tax options
- Paid Sick Time Leave
- Legal and Identity Protection Plans
- Pre-tax Commuter Benefit
- 529 College Saver Plan
Motion Recruitment Partners (MRP) is an Equal Opportunity Employer, including Veterans/Disability/Women. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP's Employment Accommodation policy. Applicants need to make their needs known in advance.
Posted by: Theresa Schermer
Specialization: Security Engineering
Location: Plano, TX, US
Posted Date: 12/1/2024
Contact Information
Contact | Human Resources Motion Recruitment |
---|