Назад
Company hidden
3 дня назад

Senior Information Security Administrator (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Information Security Administrator (Cybersecurity): Strengthening security across enterprise applications, cloud services, APIs, and development practices with an accent on secure code review, application risk assessment, and DevSecOps controls. Focus on threat modeling, cloud security validation, vulnerability remediation, and integrating SAST, DAST, SCA, container, IaC, and secrets scanning into the SDLC.

Location: Frisco, Texas, USA. Office attendance is expected five days per week, with up to three flexible remote days per month.

Company

hirify.global is a large self-storage owner and operator with facilities across the United States and Europe and is a member of the S&P 500 and FT Global 500.

What you will do

  • Assess internally developed, third-party, SaaS, cloud-hosted, web, mobile, and API-based applications.
  • Perform secure code reviews and provide remediation guidance for authentication, authorization, input validation, secrets, dependencies, APIs, logging, and configuration risks.
  • Partner with development, DevOps, architecture, infrastructure, and business teams on threat modeling, design reviews, secure coding, and release readiness.
  • Operate and improve SAST, DAST, SCA, container, IaC, secrets, API security, and CI/CD security tooling.
  • Review cloud architectures and controls across Azure, AWS, or GCP, including IAM, networking, logging, encryption, storage, and policy-as-code.
  • Prioritize vulnerabilities, support incident response and audits, maintain security standards and documentation, and mentor technical teams.

Requirements

  • Bachelor’s degree in information security, computer science, software engineering, information technology, or a related field, or equivalent experience.
  • 5–8+ years of experience in cybersecurity, application security, secure software development, DevSecOps, cloud security, or related technology roles.
  • Practical development experience reading, reviewing, or writing Java, C#, JavaScript/TypeScript, Python, Go, or similar code.
  • Hands-on experience with secure code reviews, application risk assessments, vulnerability validation, remediation guidance, and web/API security.
  • Knowledge of cloud security, CI/CD pipelines, repositories, release controls, DevSecOps automation, authentication, authorization, encryption, and secure data handling.
  • Must be authorized to work in the United States without restrictions or requiring sponsorship now or in the future.

Nice to have

  • Certifications such as CSSLP, CISSP, GWAPT, GWEB, CASE, Security+, CISM, or a cloud security certification.
  • Experience with OWASP risks, threat modeling, API or mobile security, Kubernetes, container security, and software supply chain security.
  • Experience with SOX, PCI DSS, NIST, ISO 27001, SOC 2, secure SDLC standards, security champions programs, or application security metrics.
  • Familiarity with OAuth, OIDC, SAML, JWT, MFA, PAM, secrets vaulting, and key management.

Culture & Benefits

  • In-person collaboration is emphasized while limited flexible remote work is available.
  • Up to three flexible remote days per month.
  • Equal opportunity workplace with a focus on diversity and inclusion.
  • Career growth and work culture recognition.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →