S&P Global - Trenton, NJ

posted 4 months ago

Full-time - Senior
Remote - Trenton, NJ
10,001+ employees
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services

About the position

The Director of Application Security Engineering at S&P Global is a senior-level position responsible for leading a team of security engineers and analysts to develop and implement security architecture and engineering best practices across S&P Ratings technology platforms. The primary mission of the S&P Ratings Security team is to protect clients and users from modern-day security threats by safeguarding systems and data through innovative solutions. This role requires a combination of managerial and technical capabilities, focusing on driving the Secure Software Development Life Cycle (SDLC) roadmap and Cloud security architecture. The successful candidate will work closely with software development, QA, SRE, and Operations teams to identify technical risks, evaluate critical failure points, and implement security controls to mitigate risks while aligning with application development timelines. In this role, the Director will provide architectural guidance on best practices regarding security in software development, shared services, and user interface design frameworks. They will also be responsible for developing, implementing, and maintaining application security and GenAI security strategies, performing threat modeling, secure code reviews, and secure design reviews for high-risk applications. The Director will serve as a technical security advisor for new technology and applications developed by S&P Ratings, guiding development and SRE teams in building secure Cloud Native applications by incorporating best practices and industry standards. This position also involves mentoring team members, developing security tooling, and maintaining knowledge of current and emerging technologies related to security architectural solutions.

Responsibilities

  • Lead a team of security engineers and analysts to provide security engineering and architecture consultation.
  • Identify component and system-level technical risks and evaluate critical failure points.
  • Determine technical security controls to mitigate risks and prioritize controls with application development timelines.
  • Drive the Secure SDLC roadmap and Cloud security architecture.
  • Assist in maturing the security engineering program and develop security tooling.
  • Provide architectural guidance on best practices regarding security in software development and shared services.
  • Perform threat modeling, secure code reviews, and secure design reviews for high-risk applications.
  • Evaluate new technology stacks and frameworks for security implications.
  • Develop and implement application security and GenAI security strategies.
  • Consult on security incident response processes and application penetration tests.

Requirements

  • Bachelor's degree in Computer Science or a related field, or relevant work experience.
  • 6 or more years of progressive experience in security engineering roles.
  • Experience managing security engineering teams.
  • Demonstrated expertise in Application Security, Web services security, and GenAI/LLM security.
  • Experience with threat modeling, risk analysis, and control design.
  • In-depth knowledge of network security, authentication, and authorization.
  • Advanced understanding of vulnerability exploitation chaining and remediation.
  • Expertise in product/application security architecture, including SOA and network security.
  • Knowledge of TCP/IP stack, encryption, TLS, DTLS, ECC, and PKI/Certificates.
  • Experience with Identity & Access Management (AD/LDAP).

Nice-to-haves

  • Programming expertise in Java and Python.
  • Knowledge of AWS cloud architecture and virtualization technologies like Containers and Kubernetes.
  • Experience with automation tools associated with DevOps and CI/CD pipelines.
  • Familiarity with SAST/DAST/SCA tools like Fortify and Whitesource.
  • Database knowledge including Postgres, Oracle, Databricks, and Snowflake.
  • Familiarity with Secure SDLC frameworks such as NIST SSDF and OpenSAMM/BSIMM.
  • Experience with AI technologies and services, including security of Gen AI models.

Benefits

  • Continuing education credits
  • Health insurance
  • Referral program
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service