PPL - Providence, RI

posted 15 days ago

Full-time
Remote - Providence, RI
Utilities

About the position

The Application Security Lead Engineer at PPL Corporation plays a crucial role in ensuring the security and integrity of applications and software products within the Cybersecurity organization. This position involves conducting security assessments, providing expert guidance, and shaping the security posture of products, all while collaborating closely with the Product Cybersecurity Manager. The ideal candidate will have a strong background in application security and modern software development practices.

Responsibilities

  • Conduct security assessments of applications, including vulnerability scanning, penetration testing, and fuzzing.
  • Complete static and dynamic application security testing to identify vulnerabilities and weaknesses.
  • Participate in code reviews to identify potential vulnerabilities, weaknesses, defects, etc.
  • Complete Threat Modeling assessments, analyze impact, and develop mitigation strategies.
  • Perform review and testing around Application Programming Interface security.
  • Assist relevant parties on identified gaps based on analysis and execute strategies to mitigate/address the risk.
  • Integrate security into the software development pipeline using secure software development lifecycle processes.
  • Create and/or Improve Data Flow Mapping and System Interface Tracking in conjunction with the Product Development and Enterprise Architecture teams.
  • Collaborate with business and technical owners, while engaging relevant SMEs, to establish compliance standards and trackable metrics.
  • Maintain knowledge and stay up to date on developing security technologies and integrate new technologies into architecture designs, where applicable.
  • All other duties and projects as assigned.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field or equivalent work experience.
  • A minimum of 7+ years of experience in cybersecurity with a focus on software development, secure by design principles, and/or security architecture.
  • Proficiency in conducting security testing, including vulnerability scanning, and static and dynamic code analysis.
  • Expertise in system hardening, including vulnerability assessment, penetration testing, and configuration management.
  • Expertise in designing secure architectures using established frameworks.
  • Experience in application security tools and IDE Plug-in environments, including HP Fortify.
  • Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25.
  • Experience in the use of threat modeling tools, and understanding of frameworks such as STRIDE and PASTA.
  • Demonstrate a working knowledge of various enterprise technology stacks used to build applications in the cloud.
  • Possess working knowledge and practical experience in security testing within cloud platforms, particularly Azure.
  • Experience in Cloud Native Security practices and technologies including Container security, Serverless security, Kubernetes security and Threat detection.
  • Experience in utilizing Cloud Native Security Tools and Platforms such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Cloud Access Security Brokers (CASB).
  • Knowledge of federal compliance standards, including NIST 800-53 and NIST CSF.
  • Experience working in Agile teams and knowledge of Agile principles and practices.
  • Strong analytical skills to assess risks and vulnerabilities in complex systems.
  • Strong leadership, communication, and interpersonal skills.
  • Collaborative and effective in cross-functional team environments.

Nice-to-haves

  • Professional certifications such as CISSP, CSSLP, or CEH.
  • Proficiency in scripting and automation for security testing.
  • Experience with AWS and Google Cloud services.
  • Experience utilizing the Scaled Agile Framework (SAFe).
  • Experience in securing Artificial Intelligence, Machine Learning, etc., and maintaining integrity of those powered solutions.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service