OCC
We clear and settle trades for the options industry.
Hybrid

Manager Security Penetration Testing

Sorry, this job was removed at 12:18 p.m. (CST) on Tuesday, July 7, 2020
Find out who's hiring in Chicago.
See all Cybersecurity + IT jobs in Chicago
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Summary

Working closely with other members of the Security Services, IT Development Team and Quality Assurance teams, to lead application and software security initiatives, projects, and operations. Responsibilities include the development and implementation of security best practices in the software development life cycle (SDLC), guiding application teams in the development of secure applications, and integrating custom and commercial software with security infrastructure to support the confidentiality, integrity and availability of enterprise applications.

Ability to think with a security mindset. The successful candidate has a strong information security and technology background with in-depth knowledge of several key security practice areas to include access control; privileged access management; application security; identity and access management; data security and governance; network security; security architecture; mobile security and various cloud-based security strategies.

Primary Duties and Responsibilities:

To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.

Conduct security review of technical architecture designs of systems and application.

Suggest security controls and practices to be integrated in the SDLC phases and participation in Security Assurance SDLC activities and toll gates.

Creates clear and concise reports of security analysis for SDLC artifacts and security review during change management process.

Collaborate and brainstorms with security assurance team on new information and security technologies in areas of application and application infrastructure components and propose ideas for new security service development

Develop, implement and execute control activities to ensure that security products, processes and procedures are working as intended; remediate any deficiencies detected; provide documentation and other artifacts.

Develop and collect metrics that measure the volume and trends of work activities and events within the security operations capability; provides regular reports to management.

Explores opportunities for updates to security assurance policies and standards

Coordinate development and periodic review of Security controls, policies and procedures in close coordination with Security managers.

Coordinate self-testing of Security controls and processes.

Coordinate execution of continuous testing roadmap exercises.

Assist in the remediation of security engineering vulnerability findings.

Manage the development of training on security best practices for application developers, architects and testers and coordinate the execution of training plans.

Work with development team and Q/A to create development lifecycle documentation, provides integrated systems planning which will enhance current systems and support corporate, business and system goals.

Participate in the change management process, able to evaluate the security impact, suggest controls and make conclusions to approve or reject the change requests.

Lead in designing penetration testing strategy and plan along with the testers.

Review reports of the testing and conduct security risk assessment of the findings.

Assist in risk prioritization of security vulnerabilities.

Conducts code scans using automated tools and risk rate the vulnerabilities according to the organization risk profile and mitigating controls.

Conduct security review of the baseline and proposed configuration changes to the baseline of devices and applications. Includes research on NVD, potential surface area for risk exposure and validation of controls.

Supervisory Responsibilities: Small Team

Qualifications:

The requirements listed are representative of the knowledge, skill, and/or ability required.

Highly motivated individual that assumes ownership of their projects

Must have a deeply inquisitive nature

Ability to act as a liaison between security and the development, IT and QA teams.

Strong desire and capacity to learn and support new technical applications

Exceptional verbal communication skills that include the ability to articulate ideas clearly and concisely

Excellent listening skills

Ability to facilitate meetings and conversations

Ability to write clear and concise documentation including technical specifications as well as business oriented approaches and process descriptions

Highly collaborative – comfortable sharing ideas and asking questions with all levels of staff

Ability to work both independently or on a team with tight timelines and minimal supervision

Security industry knowledge preferred.

Technical Skills:

Experience with Java programming including Java Servlets, JSP, J2EE, Spring.

Experience with J2EE applications and infrastructure including IBM WebSphere Application Server, WebSphere Portal, BEA Weblogic solutions and development.

Familiarity with application frameworks and their built-in security services and API’s (i.e., Sun J2EE, MS .NET, OMG CORBA, Spring, etc.)

General knowledge of scripting languages (Python, etc.)

Knowledge of security architecture design and principles including confidentiality, integrity and availability.

Automated code scanning tools and development pipeline tools

Understanding of security concepts and practices, including those for authentication, authorization, access control and auditing as well as best practices (e.g. OWASP).

Familiarity with application authentication and authorization systems (i.e., CA SiteMinder, RSA SecurID/ACE, NS Active Directory and LDAP)

General knowledge of cryptography (symmetric and asymmetric encryption, digital signatures, message digests, certificates, PKI, SSL/TLS, etc.)

Fundamental understanding of network and data communications technologies

Knowledge of security in Cloud concepts

Knowledge of Secure DevOps concepts

Education and/or Experience:  

Bachelors degree in Computer Science, Management Information Systems, or related field or the equivalent combination of education and/or relevant experience

Two or more years of security assurance experience.

Experience with SDLC and working with business users, database analysts, system architects, etc., to identify and prioritize requirements.

Exposure to security architecture design through application development or knowledge of security concepts/best practices. 

Previous work in development, architecture or quality assurance testing may be applicable to the position requirements. 

Certificates or Licenses:

Professional network and/or security certifications a plus (i.e., GIAC, CISSP, CISA, CISM, CRISC)

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are OCC Perks + Benefits

OCC Benefits Overview

Educational Assistance and Student Debt Forgiveness, 12-week paid parental leave, BYOD program with technology stipend up to $2,000 every three years, $35 per month pay to offset costs of mobile data plans. Open offices, online health coaching.

Culture
Volunteer in local community
Each year, OCC employees select a locally-based charitable organization for each of our three offices (Chicago, Dallas and Washington, D.C.). We offer multiple opportunities to get involved.
Partners with nonprofits
OCC Partners with local organizations in Dallas, Chicago and DC to raise funds and support their missions. Employees select the charity and are eligible for up to 8 hours of paid time to volunteer.
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Flexible work schedule
OCC provides employees with a flexible work schedule that includes Flexible start and end times.
Remote work program
2 days per week work from home program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity employee resource groups
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
HSA or FSA accounts available for those enrolled in medical plans.
Life insurance
Wellness programs
Includes back-up child or elder care along with other wellness programs.
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
OCC provides employees with a 401(k) matching plan managed by Fidelity. We match 50% of contributions up to 12% of an employee's annual gross pay.
Performance bonus
Charitable contribution matching
Child Care & Parental Leave
Generous parental leave
12-week paid parental leave
Vacation + Time Off
Generous PTO
OCC employees receive between 22 and 32 days per year of paid time off based on years of service.
Paid volunteer time
Sabbatical
Eligible employees get 30 days of paid sabbatical after their first 10 years of working at the company.
Paid holidays
Paid sick days
Office Perks
Commuter benefits
OCC Offers pre-tax commuter benefits for employees in Chicago and Washington, D.C.
Company-sponsored happy hours
Relocation assistance
OCC offers relocation assistance which varies based on the position level and location.
Home-office stipend for remote employees
Professional Development
Job training & conferences
OCC offers employees professional development opportunities including onsite training courses and the ability to attend job related certification courses, conferences and seminars.
Tuition reimbursement
Our tuition reimbursement plan offers an annual max of $10000.
Lunch and learns
OCC hosts leadership lunches on a regular basis so you can learn about your colleagues and their unique backgrounds.
Promote from within
Online course subscriptions available
Customized development tracks
Paid industry certifications
Employees are strongly encouraged to stay current in relevant technologies and supports certification programs.

Additional Perks + Benefits

We were recently recognized as one of LinkedIn's Top Company in Financial Services! Take a look at our blog post here: https://www.theocc.com/newsroom/press-releases/2022/06-23-linkedin-list…

More Jobs at OCC

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about OCCFind similar jobs like this