Managed Application Security Sme
This role supports solution architects designing strategic deals or owns multiple components of large complex deals.
Supports the solution reviews with various stakeholders including meetings with the client team presenting the solution and offerings and understanding client needs and requirements.
Works on building the win strategy and the cost model for the solution and support response content creation collecting inputs internally and externally.
The role will help to implement client Managed Application Security capabilities to enable secure product development.
Help with design, build, deploy and maintain secure services within their defined scope of products, systems, and team.
And ensures that the products and systems delivery process it's self is secure enough (for example so that intellectual property is protected).
This will involve managed security services security in the whole software lifecycle from inception, design, threat modelling, development, testing and releasing them, to operating and protecting them.
In order to do so, the role will be responsible for defining the security requirements and policies of their in-scope team and working closely with the Agile Scrum teams to help ensure they are understood and implemented appropriately.
Computer Science, Telecommunications or Information Security Master Degree or a related field and full professional proficiency in English is required.
Experience with SW development, DevOps, Secure SLDC and Application Security Testing is required.
Experience in other fields of Information Security (Pentesting, Security Architecture, Infrastructure Security) is desired.
Applicants must have experience in managing people and projects with multidisciplinary and geographically dispersed teams.
Applicants are expected to exhibit proactive behaviour, propose improvements and innovations and provide constructive feedback.
Key Responsibilities:
- Manage teams, projects and relationship with clients on daily basis
- Manage project finances and work assignment and allocation
- Participate in business development and sales activities (including responses to RFPs)
- Lead offering development and contribute to innovation activities as a Subject Matter Expert
- Contribute to the internal professional community
- Perform quality assurance of services provided to the client
- Provide advisory to different groups (Technology, Developers, Digital Transformation, etc.
)
- Define and execute training program for different teams
- Work with senior management on defining roadmaps, needs and provide short and mid-term forecasting
- Collaborate with clients to define best approach to maximize the security posture
Qualifications:
**Education**:
- Master Degree in Computer Science, Telecommunications or Information Security
- Certifications such as CSSLP, CISSP, CEH, OSCP, CISM, etc.
are preferred
Work Experience:
- 3+ years of experience in Application Security Testing
Work Requirements:
- Willing to travel and attend meetings/workshops on client premises and work from client premises within the country or abroad
Knowledge/Skills Requirements:
- Has a passion for Application Security
- Experience in management and definition of security in the software development lifecycle (SDLC)
- Working knowledge of Waterfall, Agile and primarily DevOps development methodologies
- Understanding of security testing of virtualization and container technologies (Docker, OpenShift, )
- Experience with OWASP Testing Guide v3 / 4 and OWASP TOP 10
- Knowledge of SOA security
- Knowledge of the WS-Security standard
- Knowledge of security in micro-services is valuable
- Vulnerability Management and Vulnerability Lifecycle experience
- Client focus
- Communications skills including the ability to understand client process in any area in detail
- Excellent coordination and communication skills
- Business writing skills (capturing needs and writing it down on formal documents)
- Reliable and with attention to detail
- Ability to work alone and bring results
- Leadership and coordination skills for teams and projects, role will manage customer expectations & deadlines and will participate on business activities
- Coaching and people development skills
Diventa il primo a rispondere a un'offerta di lavoro!
-
Perché cercare un lavoro con PostiVacanti.it?
Ogni giorno nuove offerte di lavoro È possibile scegliere tra un'ampia gamma di lavori: il nostro obiettivo è quello di offrire la più ampia selezione possibile Ricevi nuove offerte via e-mail Essere i primi a rispondere alle nuove offerte di lavoro Tutte le offerte di lavoro in un unico posto (da datori di lavoro, agenzie e altri portali) Tutti i servizi per le persone in cerca di lavoro sono gratuiti Vi aiuteremo a trovare un nuovo lavoro