Kforce - Phoenix, AZ

posted 2 months ago

Full-time - Senior
Phoenix, AZ
Administrative and Support Services

About the position

Kforce has a client in Phoenix, AZ that is seeking a Senior Technical Project Manager. This role is pivotal in ensuring the security of APIs within the organization. The Senior Technical Project Manager will perform ongoing governance and follow-through with API owners to ensure the implementation of threat-based requirements. This includes developing, delivering, and keeping up-to-date API security standard requirements and design patterns. The individual will validate the implementation of API security controls against outputs of vulnerability testing tools to enable auditability and verifiability. As an API security technical advisor, the Senior Technical Project Manager will serve application teams and evangelize API security design principles throughout the organization. Collaboration as an API security subject matter expert is also a key aspect of this role, ensuring that best practices are shared and implemented across teams.

Responsibilities

  • Perform ongoing governance and follow-through with API owners to ensure implementation of threat-based requirements
  • Develop, deliver and keep up-to-date API security standard requirements and design patterns
  • Validate implementation of API security controls against outputs of vulnerability testing tools to enable auditability and verifiability
  • Serve as an API security technical advisor to application teams
  • Evangelize API security design principles
  • Collaborate as API security subject matter expert within the organization

Requirements

  • Information security professional certifications such as SANS GIAC, CISSP, CISM
  • Security and Technical experience
  • Experience with service-oriented architectures and web services security
  • Direct hands-on experience developing and securing web APIs and web applications: REST, SOAP, gRPC
  • Direct hands-on experience with security testing of web services and web APIs
  • Solid hands-on experience with leading threat modeling exercises for applications and services
  • Solid understanding of risk management, security architecture and secure SDLC practices
  • Strong experience and understanding of API identity and access management controls: OAuth 2.0, OIDC, JWT
  • Strong experience and understanding of familiarity with cryptography controls: Data at rest, in motion and in-use
  • Experience with industry standards and frameworks: NIST 800-53, NIST CSF, OWASP, SANS Top 25
  • Experience with Java, JavaScript and mobile application development
  • Familiarity with database architectures: Oracle, SQL and NoSQL Databases

Nice-to-haves

  • Experience mentoring application security and secure development practices to team
  • Experience with DevOps processes in a Cloud/SaaS environment
  • Experience architecting, securing, and operating one or more public cloud environments: Amazon Web Services, Google App Engine, Azure, and Oracle Cloud
  • Experience with one or more emerging programming languages: Go, Rust

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Health Savings Account (HSA)
  • Flexible Spending Account (FSA)
  • 401(k)
  • Life insurance
  • Disability insurance
  • Accidental Death and Dismemberment (ADD) insurance
  • Paid time off for salaried personnel
  • Paid sick leave for hourly employees on Service Contract Act projects
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service