Job Duties:
· Evaluate and scope applications with the application development teams to identify criticality of the application and identify data sources and elements.
· Enforce application security requirements, Onboard Applications to Threat Modeler and Vulnerability Scanners.
· Configure Applications on Vulnerability Scanners to perform Static and Dynamic Scans. Configure and generate application vulnerability scan reports, Evaluate Application vulnerability scan reports.
· Document vulnerabilities found in scan reports and define vulnerabilities mitigation SLAs. Assess if the vulnerabilities found in scan reports are within Risk Appetite.
· Develop vulnerability mitigation strategy and mitigation controls to make the applications secure within the agency infrastructure environment.
· Evaluate mitigated vulnerabilities with development teams to perform security accreditation for production deployment.
· Evaluate application architecture to identify gaps in infrastructure security. Recommend use of Firewalls, WAF, Identity Management and Multi Factor Authentication.
· Develop and implement Secure Development Lifecycle (SDL) processes and automated / DEVOPS tools integration to CI/CD.
· Assist application development teams in performing Threat Modeling, identify application threats/vulnerabilities and recommend mitigation strategies.
· Assist application development teams in identifying mitigation approaches for of vulnerability and static/dynamic scan results.
· Identify technical solutions and security tools to help mitigate security vulnerabilities and automate repeatable tasks.
· Work on management requests to provide periodic updates, compiling risk registers, security reports and designing Dashboards showcasing current application risk scenarios.
Educational Requirement: A bachelor's degree in computer science or a closely related field.