Cybersecurity Consultant III, Application Security (Greensboro, NC)
@ Kaiser PermanenteCybersecurity Consultant III, Application Security (Greensboro, NC)
About the job
The company focuses on cybersecurity, providing application security assessments, secure development practices, and risk management to protect digital assets and ensure security compliance.
Requirements
- 2+ years software or application development
- Experience in IT or related field
- Knowledge of security testing tools
- Ability to analyze security vulnerabilities
Qualifications
- Bachelor's in CS, Business, Math
- Minimum 1 year in information security
- Strong communication skills
- Familiar with security assessments
Full job description
The IS Consultant III, Application Security position is a hands-on technical role responsible for supporting application security assessments and secure software development practices under the guidance of senior application security consultants. The role performs source code reviews, manual and automated security testing, vulnerability assessments, and security test data analysis for moderately complex technology initiatives.
The consultant works with developers, DevOps teams, technology risk teams, and business stakeholders to integrate application security services, validate security findings, provide remediation guidance, and communicate risks to technical and nontechnical audiences. The role also supports continuous application assessment, security tool adoption, standardized security processes, metrics, reporting, and ongoing improvements across assigned business domains.
In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities under the guidance of more senior application security consultants by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate.
Essential Responsibilities:
- Completes work assignments by applying up-to-date knowledge in subject area to meet deadlines; following procedures and policies, and applying data and resources to support projects or initiatives; collaborating with others, often cross-functionally, to solve business problems; supporting the completion of priorities, deadlines, and expectations; communicating progress and information; identifying and recommending ways to address improvement opportunities when possible; and escalating issues or risks as appropriate.
- Pursues self-development and effective relationships with others by sharing resources, information, and knowledge with coworkers and customers; listening, responding to, and seeking performance feedback; acknowledging strengths and weaknesses; assessing and responding to the needs of others; and adapting to and learning from change, difficulties, and feedback.
- Effectively communicates investigative findings to non-technical audiences.
- Works with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture.
- Provides recommendations to team or department leadership on how to remediate issues identified through security testing processes.
- Identifies the impact of security test plans on upstream and downstream solution components.
- Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis.
- Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across assigned business domain(s).
- Performs security test data analysis in support of security vulnerability assessment processes, including root cause analysis.
- Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately complex technology initiatives across multiple IT domains by analyzing business and technology requirements.
- Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems.
- Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams as appropriate.
- Minimum two (2) years software or application development experience.
- Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum three (3) years experience in IT or a related field, including Minimum one (1) year in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement.
- N/A
Similar jobs in Greensboro, NC
- K
Cybersecurity Consultant III, Application Security (Greensboro, NC)
Kaiser Permanente · North Carolina, Greensboro, Greensboro Administration
Posted 4 days ago - K
Cybersecurity Consultant IV, Application Security (Greensboro, NC)
Kaiser Permanente · North Carolina, Greensboro, Greensboro Administration
Posted 4 days ago - C
Sales Consultant - Full Time
Carmax · Greensboro, NC, United States
Posted 4 days ago - C
Automotive Sales Consultant
Carmax · Greensboro, NC, United States
Posted 2 days ago - K
IT Consultant V - Cloud, Azure, Databricks
Kaiser Permanente · North Carolina, Greensboro, Greensboro Administration
Posted 1 day ago - C
Verizon Sales Consultant
Cellular Sales Verizon Authorized Retailer · Burlington, North Carolina
Posted 3 weeks ago