Cybersecurity Consultant IV, Application Security (Greensboro, NC)
Kaiser Permanente
- LocationGreensboro, North Carolina
- CategoryI.T. & Communications
- Posted
- Job ID3146413658
Job description
Job Summary:In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths.
This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate.
Essential Responsibilities:
- Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities.
- Practices self-development and promotes learning in others by proactively providing information, resources, advice, and expertise with coworkers and customers; building relationships with cross-functional stakeholders; influencing others through technical explanations and examples; adapting to competing demands and new responsibilities; listening and responding to, seeking, and addressing performance feedback; providing feedback to others and managers; creating and executing plans to capitalize on strengths and develop weaknesses; supporting team collaboration; and adapting to and learning from change, difficulties, and feedback.
- Effectively communicates investigative findings to non-technical audiences.
- Collaborates with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture.
- Provides recommendations to management and business stakeholders on how to remediate issues identified through security testing processes.
- Identifies the impact of security test plans on upstream and downstream solution components.
- Supports information sharing and integration procedures across cyber security through the exchange of threat intelligence and cyber security vulnerability assessment data.
- Contributes to cyber security intellectual capital by making process or procedure improvements, conducting brown bag training sessions, and creating new training documents.
- Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis.
- Recommends business line or business technology team security process improvements which align with sustainable best practices, and the strategic and tactical goals of the business.
- Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across multiple business domains.
- Performs complex security test data analysis in support of security vulnerability assessment processes, including root cause analysis.
- Serves as an escalation point on issues, dependencies, and risks related to security testing.
- Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately to highly complex technology initiatives across multiple IT domains by analyzing business and technology requirements.
- Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems.
- Provides insight and consultation on the development of testing scope and approach, and collaborates with cross-functional IT and business stakeholders to review the overall testing approach.
- Validates security test scenarios across various SDLC phases (e.g., development, reproduction, production) for low- to moderately-complex projects.
- Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams and management as appropriate.
Minimum Qualifications:
- Minimum three (3) years software or application development experience.
- Minimum one (1) year experience in application security (e.g., source code analysis, dynamic analysis, etc.).
- Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum six (6) years experience in IT or a related field, including Minimum two (2) years in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement.
Additional Requirements:
Apply now
You'll be taken to the employer's application page.
