The Security Architect is responsible for developing and | Spring, TX

Detailed Information

  • Location: Spring, TX

  • Company: American Bureau Of Shipping

cloud, embedding and automating security controls in Dev Ops, and helping development teams identify and track security risks to remediation. This position is a Hybrid role in Spring, Texas (Remote Monday and Friday, in Office Tuesday - Thursday). What You Will Do: Develop and maintain software application security policies, standards, and procedures.

Develop and implement software application security controls, including security best practices for the software development lifecycle. Support and consult with product and development teams in application security, including application threat modeling, application architecture reviews, code security reviews and analysis, and application

security testing. Design technical solutions to address security weaknesses in applications. Analyze system services and identify security issues in applications.

Assist teams in reproducing, triaging, and addressing application security vulnerabilities. Assist in identifying and implementing automated tooling to identify and prevent security vulnerabilities and enable an effective Dev Sec Ops environment. Communicate the nature and severity of security concerns to the development team. Help development teams backss and remediate application security concerns. What You Will Need: Education and Experience Bachelor's degree in information security or related field of study, or equivalent

work experience. Minimum of 10 years of work experience within software development or information security.

Knowledge, Skills and Abilities Able to work well with software development teams and guide them on secure software development processes. Expertise in Azure platform offerings and security best practices. Cloud security experience with MS Azure (AWS and/or GCP a strong plus). Experience configuring and running WAFs (Web Application Firewalls). Experience identifying security threats and vulnerabilities using threat modelling, and code review and analysis. Work experience in securing containers. Work experience with Dev Sec Ops environments, orchestration, and security tools.

Work experience with application security processes, tools, and principles, such as: SCA, SAST, DAST, Web Application Firewalls, including API security. Application security expertise understanding vulnerabilities and remediation solutions (OWASP, SANS 25). Basic development or scripting experience and skills. Ruby, Ruby on Rails, Java Script, and/or Go are preferred. A basic understanding of network and web related protocols (such as HTTP, HTTPS, SSH.). Excellent and professional communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.

Working knowledge of the ABS Health, Safety, Quality & Environmental Management System (applicable to internal candidates). It Would Be Nice If You Had: Professional information security certification (such as: CISSP, CCSP, GWAPT, GWEB, AWS/Azure Solutions Architect) preferred. AZ-204: Developing Solutions for Microsoft Azure - preferred. AZ-305: Designing Microsoft Azure Infrastructure Solutions - preferred. AZ-500: Microsoft Azure Security Technologies - preferred. Reporting Relationships: Reports to a Manager or Director Level Position

View Jobs by Category >>

Related Jobs