Application Security Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Manager (Cybersecurity): Leading and implementing enterprise data security, compliance, and risk management programs with an accent on establishing security standards and managing vulnerability programs. Focus on strengthening security posture through architectural guidance, regulatory adherence (NIST, FedRAMP), and ensuring operational resilience.
Location: Onsite in Boston, MA
Company
Professional services firm specializing in innovative technologies and advanced technology management.
What you will do
- Design and implement enterprise data security management and operational models.
- Establish and enforce security standards aligned with NIST, FIPS, and FedRAMP frameworks.
- Manage regulatory requirements and coordinate internal and external audits for HIPAA, HITRUST, and GDPR.
- Oversee vulnerability management programs, including SAST, DAST, and penetration testing.
- Implement automation for security processes, system administration, and deployment activities.
- Collaborate with application, QA, and infrastructure teams to ensure security compliance.
Requirements
- Bachelor’s degree in IT, Computer Science, or equivalent work experience.
- 10 or more years of IT experience, with 5+ years in security leadership roles.
- Strong experience with NIST, HIPAA, HITRUST, GDPR, and FedRAMP frameworks.
- Proven experience with vulnerability management tools and processes (SAST, DAST).
- Must be based in or able to work onsite in Boston, MA.
- Strong written and verbal communication skills for technical and executive stakeholders.
Nice to have
- Experience with AWS security architecture and compliance.
- Professional certifications such as CISSP, CISA, CISM, or CCSP.
- Experience working in highly regulated or government environments.
- Experience implementing automated security and compliance solutions.
Culture & Benefits
- Competitive salary.
- Opportunity to lead enterprise-level security programs across complex IT environments.
- Collaborative work environment with cross-functional teams.
- Focus on continuous improvement and professional growth in cybersecurity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →