Digital Solutions- Cyber Security Architect | Virginia Beach, VA

Detailed Information

  • Location: Virginia Beach, VA

  • Company: Sentara Health

Alabama , Delaware , Florida, Georgia, Idaho , Indiana, Kansas , Louisiana , Maine Maryland, Minnesota , Nebraska , Nevada, New Hampshire , North Dakota , Ohio, Oklahoma , Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Washington (state), West Virginia, Wisconsin, Wyoming Primary Responsibilities: Application Security backssments: Conduct comprehensive security backssments of software applications, including static and dynamic code analysis, vulnerability scanning, and penetration testing.

Work with digital solution teams to evaluate the d igital p roduct e xperience solutions to include u ser i nterface (UI), u ser e xperience (UX), f unctionality, p ersonalization

, a ccessibility , security and privacy, c ross- p latform c onsistency , etc. Identify and prioritize application vulnerabilities, security weaknesses, and coding flaws, and provide recommendations for remediation.

Collaborate with development teams to integrate security testing tools and methodologies into the software development lifecycle. Secure Coding Practices: Promote and enforce secure coding practices among developers, ensuring adherence to industry standards and best practices. Provide guidance and training to development teams on secure coding principles, secure design patterns, and secure development methodologies. Review application source code to identify potential security

vulnerabilities and recommend necessary code changes. Vulnerability Management: Manage and track vulnerabilities identified in applications, coordinate with development teams to prioritize and address them in a timely manner.

Stay updated with the latest security vulnerabilities and threats, and actively monitor vulnerability databases and security advisories. Implement vulnerability management processes to ensure effective tracking, remediation, and mitigation of identified vulnerabilities. Security Architecture and Design: Collaborate with architects and development teams to integrate security into the application architecture and design phases. Review application design documents, identify security gaps, and propose appropriate security controls and countermeasures.

Assist in the selection and implementation of security technologies, tools, and frameworks to enhance application security. Incident Response and Threat Management: Participate in incident response activities related to application security incidents, collaborating with incident response teams to investigate and mitigate threats. Develop incident response plans specific to application security incidents and conduct post-incident analysis to improve security practices. Monitor and analyze application logs and security events to detect and respond to potential security incidents and anomalies.

Compliance and Standards: Ensure that applications comply with relevant security standards, regulations, and industry best practices, such as OWASP Top 10, PCI DSS, or HIPAA. Participate in security audits and backssments, working with auditors to address findings and ensure compliance. Stay abreast of evolving application security trends, emerging threats, and regulatory changes to provide guidance and recommendations. Desired Characteristics: Strong analytical skills - strong problem-solving skills, communicates in a clear and succinct manner and effectively evaluates information/data to make decisions; anticipates obstacles and develops plans to resolve.

Change oriented - actively generates process improvements; supports and drives change and confronts difficult circumstances in creative ways. Self-motivated, self-directed, flexible, and able to work under pressure and in fast paced team environment. Strong functional team player with experience working seamlessly across a matrix structure. Excellent interpersonal, written/verbal communication and leadership skills with the ability to make recommendations to all levels of the organization.

Requirements: 5+ years' experience with Dev Ops and Security practices , with a strong understanding of application vulnerabilities and secure coding practices. Product Security experience - solid digital product experience. Consumer digita l experience. Strong knowledge of cloud platforms (AWS, Azure, GCP, etc. ). Expertise in using CI/CD tools (e. g. Jenkins, Travis CI). Familiarity with risk management and compliance. Familiarity with web application security concepts, technologies, and frameworks (e. g. HTTP, SSL/TLS, OWASP, etc.

). Experience with security testing tools and methodologies, such as SAST, DAST, or secure code review tools. Proficiency in programming languages commonly used in application development, such as Java,NET, Python, or Java Script. Strong analytical and problem-solving skills, with the ability to effectively backss and communicate application security risks. Excellent written and verbal communication skills, with the ability to collaborate with cross-functional teams and explain complex security concepts to non-technical stakeholders. Knowledge of application security controls: Secure coding practices , Authentication and Authorization , Input Validation , Encryption , Logging and Auditing , Vulnerability Management , Penetration Testing , Secure Software Development Lifecycle (SDLC) , Access Control , Patch Management , Artificial Intelligence (AI) and Machine Learning (ML).

Knowledge of various technical frameworks and concepts ( MITRE ATT&CK, CIS, Kill Chain, etc ) Experience working in a highly regulated environment. Ability to express complex technical concepts in business terms. Organized and detail-oriented, able to work well under deadlines in a changing environment and complete multiple projects effectively and concurrently.

Evaluate effectiveness of the internal security control framework and recommend adjustments as business needs change. Regularly interact with all levels of management to present and discuss control effectiveness. Review and coordinate changes to cyber security policies, procedures, and standards. Sentara Benefits As the third-largest employer in Virginia, Sentara Health was named by Forbes Magazine as one of America's best large employers. We offer a variety of amenities to our employees, including, but not limited to: Medical, Dental, and Vision Insurance Paid Annual Leave, Sick Leave Flexible Spending Accounts Retirement funds with matching contribution Supplemental insurance policies, including legal, Life Insurance and AD&D among others Work Perks program including discounted movie and theme park tickets among other great deals Opportunities for further advancement within our organization Sentara employees strive to make our communities healthier places to live.

We're setting the standard for medical excellence within avibrant, creative, and highly productive workplace. For information about our employee benefits, please visit: Benefits - Sentara () Join our team!

We are committed to quality healthcare, improving health every day, and provide the opportunity for training, development, and growth! Note: Sentara Healthcare offers employees comprehensive health care and retirement benefits designed with you and your family's well-being in mind. Our benefits packages are designed to change with you by meeting your needs now and anticipating what comes next. You have a variety of options for medical, dental and vision insurance, life insurance, disability, and voluntary benefits as well as Paid Time Off in the form of sick time, vacation time and paid parental leave.

Team Members have the opportunity to earn an annual flat amount Bonus payment if established system and employee eligibility criteria is met. For applicants within Washington State, the following hiring range will be applied: $106,563 to $177,606annually. keywords: Talroo-IT, Indeed, Monster, Circa, Linked In, " Cyber Security" Job Summary Designs and develops new systems, applications, and solutions for enterprise-wide cyber systems and networks. Ensures system security needs are established and maintained for operations development, security requirements definition, security risk backssment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability testing, and scanning, incident response, disaster recovery, and business continuity planning and provides analytical support for security policy development and analysis.

Integrates new architectural features into existing infrastructures, designs cyber security architectural artifacts, provides architectural analysis of cyber security features and relates existing systems to future needs and trends, embeds advanced forensic tools and techniques for attack reconstruction, provides engineering recommendations, and resolves integration and testing issues.

May interface with external entities including law enforcement, intelligence, and other government organizations and agencies. An Expert Professional is a recognized master in professional discipline typically obtained through advanced education and work experience. Responsibilities typically include: Establishing operational plans for the job area. Developing and implementing new products, processes, standards, or operational plans that will have an impact on the achievement of functional results.

Requires communication with leadership. Experience in lieu of Bachelor s Degree8+ years of relevant experience with a degree10+ years of relevant experience without a degree Qualifications: BLD - Bachelor's Level Degree Skills Sentara Healthcare prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves. Per Clinical Laboratory Improvement Amendments (CLIA), some clinical environments require proof of education; these regulations are posted at ecfr.

gov for further information. In an effort to expedite this verification requirement, we encourage you to upload your diploma or transcript at time of application. In support of our mission to improve health every day, this is a tobacco-free environment. Associated topics: air force, cavalry scout, defense, military intelligence, missile defense, northrop grumman, secret clearance, ts sci clearance, ts sci required, weapon

View Jobs by Category >>

Related Jobs