3 часа назад
Information Protection Advisor (Product Security – DevSecOps)
103 100 - 171 900$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Protection Advisor (Product Security – DevSecOps) (Cybersecurity): Building automated security solutions across CI/CD pipelines and modern software development environments with an accent on application security testing, secure architecture, and cloud-native applications. Focus on integrating SAST, DAST, SCA, and MAST tools, conducting threat modeling and vulnerability analysis, and developing reusable security automation frameworks.
Location: Plano, Texas, United States
Salary: $103,100–$171,900 USD annually, depending on experience and geographic location. Eligible for an annual bonus plan.
Company
is a healthcare organization serving clients, customers, and patients through Cigna Healthcare and Evernorth Health Services.
What you will do
- Partner with engineering teams to embed secure development practices throughout the SDLC.
- Design and implement automated security solutions in CI/CD pipelines.
- Integrate and optimize SAST, DAST, SCA, and MAST tools across development environments.
- Contribute to secure architecture decisions for modern applications and platforms.
- Lead security assessments, threat modeling, and vulnerability analysis.
- Develop reusable security services, tooling, and automation frameworks while improving operational efficiency, performance, and cost.
Requirements
- 5+ years of cybersecurity experience focused on application or product security.
- Experience integrating and automating security tools in CI/CD pipelines.
- Strong knowledge of secure software development principles and modern SDLC practices.
- Hands-on experience with SAST, DAST, SCA, and MAST tools.
- Experience designing security solutions across complex development environments and securing cloud-native applications on AWS, Azure, or Google Cloud.
- Ability to influence and collaborate with engineering teams in Agile environments.
Nice to have
- Experience with security automation and orchestration frameworks.
- Knowledge of HIPAA, GDPR, and PCI-DSS compliance frameworks.
- Proficiency in Python, Java, or Shell.
- Experience securing applications built with Java or Angular.
- CISSP, CISM, CEH, or equivalent certification; an advanced degree in Computer Science, Information Security, or a related field.
Culture & Benefits
- Full-time employment with health, vision, dental, well-being, and behavioral health benefits starting on the first day.
- 401(k), company-paid life insurance, tuition reimbursement, paid holidays, and leaves of absence.
- At least 18 days of paid time off per year.
- If working from home occasionally or permanently, a cable broadband or fiber connection with at least 10 Mbps download and 5 Mbps upload is required.
- Tobacco-free workplace policy applies.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →