Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

APPLICATION SECURITY RISK MANAGER

Target Labs

The Application Security Risk Manager (ASRM) is a multi-faceted security role responsible for the identification, tracking, mitigation, remediation, and verification of security vulnerabilities in software, systems, and application services. The successful candidate will combine experience in information security, software development, IT operations, and project management with strong interpersonal skills to ensure that security risks are effectively identified and appropriately addressed. Essential Job Functions: Security Risk Management: Monitor the security risk of the organization’s application portfolio. Ensure that all identified security exposures are properly handled. This includes issue awareness, risk determination, status tracking, and risk acceptance processing where appropriate. Proactively engage with security, software development, and product management stakeholders to ensure timely resolution of all security exposures. The ideal candidate will possess a combination of technical expertise in software and IT systems along with strong interpersonal skills to enable the clear and persuasive communication of risks with technical and business stakeholders as well as the effective validation of remediated vulnerabilities. Software and System Security Assessment: Oversee and actively support the security assessment of applications using tools and techniques such as source code analysis, web vulnerability scanning, and manual testing techniques. Project Management/Coordination: Coordinate departmental and cross-functional processes and projects. Champion application security program interests. Drive effective scheduling, risk and issue management, and change management for these initiatives. Participate in development and engineering efforts that include enhancements to tools, processes, and technologies in support of security operations, process and productivity improvements. Security Infrastructure Management: Develop, deploy, operate, maintain, support, and enhance security infrastructure and supporting tools such as Web Application Firewalls (WAFs), security assessment tools, issue tracking systems, and custom tools facilitating departmental processes. Other Job Functions: Participate in all aspects of technology security service delivery including business case development, requirements analysis, architecture, design, development, product/service selection & procurement, testing, technology infrastructure implementation and deployment, operational process and procedure documentation, training, and internal marketing of security services. Collaborate and coordinate with appropriate stakeholders throughout the organization to ensure that application security processes are appropriately engaged. Monitor policies and standards to ensure that application security interests are appropriately addressed. Essential Education/Experience Requirements: Bachelor’s degree in Computer Science, Information Systems or related discipline with at least five (5) years of related experience, or equivalent training and/or work experience; emphasis in application security a plus. Experience in coordinating or managing concurrent information technology projects. Strong communication, interpersonal, leadership, persuasion, and logical reasoning skills are a must. Candidate should have a demonstrated ability to foster productive working relationships with technical and business stakeholders across the organization while applying persistence and persuasion to ensure that risks are appropriately addressed. Candidate should have experience making and defending sound technical arguments that incorporate relevant technical and business considerations, as well as experience building consensus among stakeholders. Data analysis experience using SQL, Access, Excel, etc. Software development experience, preferably in Java/J2EE and/or C#/.NET. Candidate should expect to apply this expertise to understanding and communicating the risk of software security issues, to performing and coordinating small-scale software development in support of departmental systems supporting risk management and application security processes, and to performing ad hoc analysis of security, vulnerability, and risk data. Persuading and leadership qualities to set targets and accomplish goals. Other Desirable Experience: Experience evaluating the security of applications using both manual and automated techniques. Relevant tool experience may include code security scanners such as Fortify SCA, web vulnerability scanners such as HP WebInspect or IBM Rational AppScan, assessment support tools such as BurpSuite, Metasploit, Core Impact, etc. Security-related experience with the following: Web Application Firewalls, such as Imperva SecureSphere and Trustwave/Breach WebDefend. Design patterns and coding standards for secure software. Secure configuration and operation of Application Servers, Web Servers, Directory Servers, Media/Content Servers, Messaging Servers, Database Servers, and Integration Servers. Experience developing technical policies and standards, particularly as relates to information and technology security. Knowledge of and experience with built-in and add-on security capabilities of common application infrastructure components such as MS SQLServer, Oracle, MS IIS, iPlanet Directory, MS Active Directory, MQSeries, MSMQ, MS Exchange. Knowledge of general application security API's and protocols such as: MS CryptoAPI, Kerberos, SSL/TLS, SAML, S/MIME, and PKCS API's. End-to-end, hands-on experience in security solutions for complex enterprise architectures. Knowledge of cryptographic solutions for protection of data in use, in transit and at rest, such as: SSL/TLS, IPSec, format preserving encryption & sanitization (e.g. Voltage), etc. Knowledge of security considerations related to virtualization and cloud computing Formal experience leading/managing a small team is a plus. Financial services industry (Insurance, Banking, Investments) experience a plus. #J-18808-Ljbffr

Vacancy posted 13 hours ago
Similar jobs that could be interesting for youBased on the APPLICATION SECURITY RISK MANAGER in Rockville, MD vacancy
  •  ...have an exciting opportunity for a Security Program Senior Manager who will be responsible for leading...  ...of funding opportunities and grant applications, as well as cooperative agreement management...  ..., energy systems, engineering, risk management, or related discipline.... 
    Application
    Work at office
    2 days per week
    3 days per week

    American Public Power Association

    Rockville, MD
    5 days ago
  •  ...as MassTransit, Autofac, NEventStore Comfortable working on an old legacy application Exposure to CI/CD and AWS AWS Experience EC2/ECS, DMS, RDS/Aurora Postgres, SQS/SNS, S3, IAM (Security groups, VPC Config, etc) Splunk Dev Ops Jenkins, Git, Jira, Scala, Groovy... 
    Application

    The Consortium

    Rockville, MD
    3 days ago
  • $180k - $227.7k

     ...discuss qualifications and responsibilities. All applications will be submitted via our company career page, We...  ...X-energy is seeking professionals to join our Risk Informed Safety Analysis team in the role of Manager, Probabilistic Risk Assessment. This position is... 
    Application
    Full time
    Work at office

    Alumni Ventures

    Rockville, MD
    2 days ago
  •  ...Location: Rockville, MD Onsite Type- Contract Managing Co-lo and domestic data centers Windows Server...  ...Some Team and Project Management experince, co-rdination with application and business teams. ITSM certifications and leading major... 
    Application
    Contract work
    Work experience placement

    E-Solutions

    Rockville, MD
    2 days ago
  •  ...Leads and is accountable for Marketplace security and privacy support contract outcomes...  ...and metrics (monthly/quarterly as applicable), leveraging dashboards and standardized...  ...governance, cross-team prioritization, risk/issue management, and stakeholder management across... 
    Application
    Contract work
    Temporary work
    For contractors
    Flexible hours

    PRECISE SOFTWARE SOLUTIONS INCORPORATED

    Rockville, MD
    7 days ago
  • $197.3k - $225.1k

    Endpoint Security Product Manager Capital One is seeking a product owner to help deliver game-changing...  ...incorporating cyber and operational risk reduction outcomes and activities Act...  ...time, Capital One will not sponsor a new applicant for employment authorization, or offer... 
    Application
    Full time
    Part time
    H1b
    Local area

    Capital One

    Mc Lean, VA
    2 days ago
  •  ...owners for proper change and configuration management between Development, Pre-Production and...  .... Perform monthly and on-demand security patch/update testing and deployment....  ...and deployment with system administrator/application owner prior to deployment into the Development... 
    Application
    For contractors

    InstantServe LLC

    Rockville, MD
    5 days ago
  •  ...and design, engineer, furnish, install, secure, and test (EFIS&T) solutions to include...  ...). We have an opening for a Project Risk Manager primarily responsible for supporting COMPMOD...  ...the development of new systems and/or applications projects, the modification of existing... 
    Application
    Contract work
    Work at office
    Worldwide

    By Light Professional IT Services LLC

    Mc Lean, VA
    4 days ago
  • Risk Manager Capital One’s Enterprise Risk Management (ERM) Team has responsibility for helping the overall organization identify, manage...  .... At this time, Capital One will not sponsor a new applicant for employment authorization for this position. Capital One... 
    Application
    Work at office
    Local area

    Capital One National Association

    Mc Lean, VA
    12 hours ago
  • $126k - $190k

     ...have extensive experience with operational risk, strong analytical and interpersonal...  ...will work in conjunction with SFA Risk Management business leaders to optimally handle the...  ...or any other characteristic protected by applicable law. We will ensure that individuals with... 
    Application
    Work at office

    Fairygodboss

    Mc Lean, VA
    4 days ago
  •  ...A technology services company in Rockville is seeking a Developer specialized in migrating Java/J2EE applications to the cloud. The role involves taking ownership of modernizing applications and migrating them to AWS, emphasizing architectural design, application modernization... 
    Application

    Quantum Technologies USA

    Rockville, MD
    13 hours ago
  •  ...design, develop, and maintain end-to-end applications spanning modern front-end frameworks,...  ...(FastAPI, Flask, Django) Design and manage relational and NoSQL data stores including...  ...design, microservices architecture, and secure coding practices ~ Excellent problem-solving... 
    Application

    Experis/Manpower Group

    Rockville, MD
    2 days ago
  •  ...Rockville, MD. This hybrid role requires 3 days onsite and 2 days remote work. The candidate will engage in designing and maintaining applications in a regulated financial environment. Key skills include Java Spring Boot, Python frameworks, Angular or Vue.js, and AWS... 
    Application
    Remote work

    Eliassen Group

    Rockville, MD
    13 hours ago
  •  ...Deployment SCCM Engineer Splunk SIEM Security Engineer Security Engineer Azure Cloud...  ...for an opportunity the employment manager will provide the job description and requirements...  ...requirements mandated by contract, applicable law or regulation. By applying to a... 
    Application
    Full time
    Contract work
    Temporary work
    Local area
    Night shift

    TekSynap

    Rockville, MD
    6 days ago
  •  ...such as Microsoft Endpoint Configuration Manager (MECM) and the Microsoft Deployment...  ...packages, to include updates to software applications to be applied to desktops, laptops, tablets...  ...Windows Update/MECM that applies mandatory security updates to enterprise systems.... 
    Application
    Full time
    Work at office
    Remote work
    Flexible hours

    Contact Government Services LLC

    Rockville, MD
    8 days ago
  •  ...A leading technology firm is seeking a Developer specializing in migrating Java/J2EE applications to AWS. The role involves leading cloud architecture and migration projects, modernizing applications, and utilizing AWS services. Candidates should have significant experience... 
    Application

    Robotics Prcocess Automation, LLC

    Rockville, MD
    13 hours ago
  • $164.8k - $188.1k

    Overview Manager, Risk Data Product Manager. Product Management at Capital One is a booming, vibrant craft that requires reimagining the...  ...Information At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The minimum and... 
    Application
    Full time
    Part time
    Local area

    Information Technology Senior Management Forum

    Mc Lean, VA
    12 hours ago
  • $138.3k - $315.9k

     ...and Public Sector - Assurance - Tech Risk - Senior Manager - TS SCI Clearance Location: McLean...  ...disciplines with defense and national security, civilian, health, and international...  ...assist in the testing of IT general and application controls, prepare for and potentially... 
    Application
    Summer holiday
    Work at office
    Local area
    Flexible hours

    Ernst & Young Advisory Services Sdn Bhd

    Mc Lean, VA
    4 days ago
  •  ...reliability of all systems. Manage data center infrastructure technology...  ...Soft/AD/Azure AD SSO, Azure Security Policy/PKI/Windows & Linux...  .../Linux/AD/DNS/DHCP/Azure AD Application Management/VxRail/VMWare...  ...Client of any data losses or risks. Perform data and file backups... 
    Application
    Work experience placement
    Local area
    Remote work

    Genpact

    Rockville, MD
    4 days ago
  • $130k - $160k

     ...seeking an experienced Release and Deployment Management Lead to oversee software release and...  ...awareness of release dependencies, risks, and change control requirements Collaborate with infrastructure, application, and security teams to ensure successful and timely releases... 
    Application
    Local area
    Flexible hours

    R3-LL

    Rockville, MD
    4 days ago
  • $145k - $165k

     ...Overview CVP seeks a Technical Project Manager with a demonstrated experience leading large...  ...schedules/milestones, identifying risks, and working with customers. The ideal candidate...  ...standards and principles for software applications to promote standardization, reuse, and... 
    Application

    Customer Value Partners

    Rockville, MD
    4 days ago
  • $138.3k - $315.9k

     ...responsibilities As a member of our Technology Risk (IT Audit) team, you will serve as a...  ...in the testing of IT general and application controls, prepare for and...  ...general and application controls, risk management, information security, and information assurance Take a practical... 
    Application
    Summer holiday
    Work at office
    Local area
    Flexible hours

    Ernst & Young Oman

    Mc Lean, VA
    3 days ago
  • $142k - $212k

     ...across the nation. We are looking for a Multifamily Counterparty Risk Management Manager to join the Servicer Compliance group within the...  ...disability status or any other characteristic protected by applicable law. We will ensure that individuals with differing abilities... 
    Application
    Full time
    Work at office

    Fairygodboss

    Mc Lean, VA
    1 day ago
  •  ...experience in Java, Python, and modern frameworks like Angular or Vue.js. The ideal candidate will excel in designing scalable applications and using AI-assisted development tools. This role involves thorough collaboration in Agile teams, building responsive interfaces... 
    Application

    ManpowerGroup Global, Inc.

    Rockville, MD
    3 days ago
  • $138.1k - $157.7k

    Risk Manager, Script Governance Capital One is one of the fastest growing organizations in...  ..., and perform independent tests of our security and technology risk. Role Description...  ...time, Capital One will not sponsor a new applicant for employment authorization for this position... 
    Application
    Full time
    Part time
    Local area

    Capital One

    Mc Lean, VA
    12 hours ago
  • $135k - $140k

     ...Job Summary The Regional Director of Security (Senior Portfolio Manager) is the key management...  ...standards, contractual requirements, and applicable regulatory requirements. Support...  ...disruption during incidents or events. Risk Awareness & Mitigation: Timely identification... 
    Application
    Contract work
    Temporary work
    Seasonal work
    Work at office
    Local area
    Flexible hours
    Weekend work

    Admiral Security Services

    Bethesda, MD
    2 days ago
  •  ...production environments that support application testing, infrastructure...  ...network configurations, and security tooling to ensure stable and...  ...provisioning, configuration baseline management, and system refresh...  ...software infrastructure; execute risk assessments; develop... 
    Application

    ActioNet

    Rockville, MD
    13 hours ago
  • A technology solutions provider is seeking a Developer to specialize in migrating Java/J2EE applications to AWS. The role requires leading cloud migration efforts, modernizing applications, and ensuring effective use of AWS services. Candidates should have strong Java... 
    Application

    Robotics Technologies LLC

    Rockville, MD
    1 day ago
  • $151.9k - $173.4k

    Strategic Risk Manager We are seeking a Strategic Risk Oversight Manager to join the Strategic Risk team. This exciting, high visibility...  ...skills At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The minimum and... 
    Application
    Full time
    Part time
    Local area

    Capital One

    Mc Lean, VA
    4 days ago
  •  ...full stack developer to build and maintain applications across UI, services, and data layers in...  .... The work will support scalable, secure solutions and collaboration within Agile...  ...as FastAPI, Flask, or Django. Design and manage relational and NoSQL data stores including... 
    Application
    Remote work

    Eliassen Group

    Rockville, MD
    14 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to APPLICATION SECURITY RISK MANAGER. Be the first to apply!