Lead Application Security Engineer

Sorry, this job was removed at 12:18 p.m. (CST) on Friday, December 20, 2019
Find out who's hiring remotely in Chicago.
See all Remote Cybersecurity + IT jobs in Chicago
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Cvent's Information Security team is rapidly growing and seeks a Lead / Senior Application Security Engineer focused on driving and owning our application security programs with the Cvent product and development teams. This person will be conducting regular security reviews (e.g. threat modeling, SAST, DAST), working closely with our internal product and development teams to ensure timely resolution of found security gaps, and providing security assurance to our external clients. This position requires both strong technical and communication skills, with experience in finding and advising on fixes for application security vulnerabilities, and excellent oral and written communication skills to coherently relay security information to both business clients and technical audiences. This person must be able to handle multiple deadlines and high priority issues at the same time, be able to adapt quickly against shifting priorities, and drive security resolution in a fast-paced and high-profile technology landscape.

Position Duties:

  • Drive our secure SDLC program with product development teams ensuring secure coding practices, SAST, DAST, and pentesting activity occurs on a regular basis
  • Conduct threat modeling and static/dynamic application security testing with automated and manual testing techniques
  • Report and triage vulnerabilities; provide metrics, track, plan, and ensure timely remediation of open issues
  • Collaborate and communicate effectively with product and development teams to ensure security is championed throughout their processes
  • Provide remediation plans and status updates on vulnerability closure to clients on a regular basis
  • Coordinate and negotiate security pentesting activity with clients and 3rd party vendors
  • Assist in technical audit activity to ensure compliance with security policies and other industry standards (e.g. PCI, ISO27001, SOC1/SOC2)

Candidate Requirements:

  • 6+ years of experience in application security, preferably with a coding/development background
  • Bachelor's degree in an Information Technology related field of study or equivalent experience; relevant, industry recognized security certification such as CISSP, CEH, GWAPT
  • Strong knowledge of secure coding and application security testing practices
  • Experience testing web applications with common application security testing tools such as Checkmarx, Burpsuite, and AppScan; experience testing mobile/API applications a plus
  • Exceptional communication, teamwork, and influencing skills that foster a collaborative and continuous-improvement environment
  • Ability to communicate technical issues to both technical and non-technical audiences
  • Ability to adapt to a hyper-growth pace and changing priorities
  • Ability to manage multiple, concurrent projects, activities, and tasks under tight time constraints
  • Self-motivation and the ability to work under minimal supervision
Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Location

Located on the Chicago River across from Merchandise Mart, Kapow’s offices are close to public transportation, bars and restaurants.

Similar Jobs

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Kapow!Find similar jobs