IS Consultant IV, Application Security
Kaiser Permanente
Job Description
Tech Summary
\nThe IS Consultant IV, Application Security position is a senior hands-on technical role responsible for leading complex application security assessments and advancing secure software development practices across the organization. The consultant will conduct secure code reviews, static and dynamic application security testing, open source component analysis, API and mobile application security assessments, threat modeling, security architecture reviews, vulnerability validation, and remediation guidance.
\nThe ideal candidate has advanced software development and application security experience using Java, Python, JavaScript, .NET, Swift, or similar technologies. The candidate should have practical experience with application security testing solutions, penetration testing tools such as Burp Suite or OWASP ZAP, and integrating security controls into CI/CD pipelines.
\nThis role requires the ability to independently lead complex assessments, define secure development standards and guardrails, evaluate third party applications, and influence architecture and engineering decisions. The consultant will collaborate with developers, architects, product owners, vendors, security leaders, and executive stakeholders to communicate technical risk clearly and provide actionable remediation recommendations. Experience with cloud native applications, APIs, mobile applications, AI enabled applications, DevSecOps automation, and healthcare or other regulated environments is preferred.
\n\n \n
\n\n \n
\n\n Job Summary: \n
\nIn addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate.
\n\n
Essential Responsibilities: \n
- \n
- Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities. \n
- Practices self-development and promotes learning in others by proactively providing information, resources, advice, and expertise with coworkers and customers; building relationships with cross-functional stakeholders; influencing others through technical explanations and examples; adapting to competing demands and new responsibilities; listening and responding to, seeking, and addressing performance feedback; providing feedback to others and managers; creating and executing plans to capitalize on strengths and develop weaknesses; supporting team collaboration; and adapting to and learning from change, difficulties, and feedback. \n
- Effectively communicates investigative findings to non-technical audiences. \n
- Collaborates with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture. \n
- Provides recommendations to management and business stakeholders on how to remediate issues identified through security testing processes. \n
- Identifies the impact of security test plans on upstream and downstream solution components. \n
- Supports information sharing and integration procedures across cyber security through the exchange of threat intelligence and cyber security vulnerability assessment data. \n
- Contributes to cyber security intellectual capital by making process or procedure improvements, conducting brown bag training sessions, and creating new training documents. \n
- Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis. \n
- Recommends business line or business technology team security process improvements which align with sustainable best practices, and the strategic and tactical goals of the business. \n
- Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across multiple business domains. \n
- Performs complex security test data analysis in support of security vulnerability assessment processes, including root cause analysis. \n
- Serves as an escalation point on issues, dependencies, and risks related to security testing. \n
- Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately to highly complex technology initiatives across multiple IT domains by analyzing business and technology requirements. \n
- Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems. \n
- Provides insight and consultation on the development of testing scope and approach, and collaborates with cross-functional IT and business stakeholders to review the overall testing approach. \n
- Validates security test scenarios across various SDLC phases (e.g., development, reproduction, production) for low- to moderately-complex projects. \n
- Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams and management as appropriate. \n
\n
\n Minimum Qualifications: \n
\n\n
- \n
- Minimum three (3) years software or application development experience. \n
- Minimum one (1) year experience in application security (e.g., source code analysis, dynamic analysis, etc.). \n
- Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum six (6) years experience in IT or a related field, including Minimum two (2) years in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement. \n
\n
\n
\n
\n
\n
\n Additional Requirements: \n
\n- Kaiser Permanente seeks a Cybersecurity Consultant IV, Application Security to lead advanced AppSec strategy and execution for critical healthcare systems. You will drive secure design, code review, and threat modeling across web and cloud applications, embedding security...Application
- ...Permanente seeks a Systems Administrator IV to lead the design, implementation, and support... ...supporting mission-critical clinical applications. Responsibilities include performance tuning, automation, backup and recovery, security hardening, and incident response. You...Application
- ...Kaiser Permanente seeks an Architect IV, Applications, Enterprise Automation to design and lead scalable automation solutions for our IT platform... ...ll set technical standards, drive best practices, and ensure security and compliance. This role suits an experienced architect...Application
- ...bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see... ...work-related experience.Minimum of 7 years of experience in security engineering or related cybersecurity roles.Deep specialized...ApplicationFull timePart timeShift workDay shift
$45k - $54k
...firewalls, and wireless access points. Security Management: Implement and manage security... ...People First Culture Our philosophy is to support small- and medium-sized... ...owned and operated by a franchisee. Your application will go directly to the franchisee, and all...ApplicationWork at officeLocal areaRemote workFlexible hoursAfternoon shift- ...Tech Summary The Systems Administrator IV, Health Systems supports the Clinical Care... ..., and support of enterprise clinical applications. The role collaborates with clinical, operational... ..., network, databases, storage, security) by performing complex systems analysis...Application
$21.88k - $23.06k
...Previous experience working in higher education is not required, but would be considered favorably Special Instructions to Applicants For consideration, candidates should upload: Cover letter Resume List of references Applicants are required...ApplicationPermanent employmentPart timeWork at office- ...moderate understanding of general aspects of the job. Responsibilities and Functions: Communicates with Technical team using Teams application. Locates service centers for customers that require repair or maintenance on their generator. Maintains professionalism and...ApplicationFlexible hours
- ...Tech Summary: The Product Manager IV serves as a strategic piece within KP's Digital... ...initiatives used across web and mobile applications. Customer Experience Optimization :... ...product expertise, peer training, and consultation as appropriate; and adhering to enterprise...ApplicationWork experience placement
$48k - $50k
...Prior experience working in higher education or state/government operations will be considered favorably. Special Instructions to Applicants For consideration, candidates should upload: Cover letter (not to exceed one page), detailing qualifications as they...ApplicationPermanent employmentWork at office$67 per hour
...software, bulk email platforms (e.g., MailChimp or Emma), familiarity with posting to social media platforms. Alternate Option If no applicants meet required competency level, management may consider other applicants. Salary would be determined based on competencies,...ApplicationFull timeInternshipWork at officeMonday to Friday- ...knowledge, capability, and overall utility to the department. Daily application of the organization's shared values: Helpful, Humble, Hungry,... ...system) Cisco Queues (call routing and queue management) RightFax (secure faxing) Payrailz/Bill Pay (bill-pay operations)...ApplicationLive out
- ...manner. Correctly enters all receiving documents into the computer system, reconciles merchandise invoices to items received as applicable. Accurately and timely completes store-to-store transfers and Locate requests. Ensures the visual packet materials, props...ApplicationLocal areaFlexible hoursShift workNight shift
- ...development of integrated business and/or enterprise application solutions, and for providing consultation to help ensure new and existing software solutions... ...practices, to design, develop, and deliver resilient, secure, multi-channel, high-volume, high-transaction, on/...ApplicationWork experience placementWork at officeLocal areaRelocationFlexible hoursShift work
$20 - $45 per hour
...Protection, we're pioneering solutions that safeguard global food security while championing sustainable agriculture. As a world market... ...Contribute to the Team: Proficiency in Microsoft Office applications, especially Excel, Power BI, and PowerPoint. Critical thinker...ApplicationHourly paySummer workInternshipWork at office$16 per hour
...organized storage areas and ensure mail is handled accurately and securely. Assist with outbound mail processing and shipping as... ...accommodations to individuals with a disability in accordance with applicable law in both the application and employment stages. If you...ApplicationHourly payTemporary workSeasonal workLocal areaDay shift- ...Would Include Position Overview The Director of Information Security is responsible for developing and executing Centric Brands'... ...and objectives. • Partner with infrastructure, network, cloud, application, and end-user computing teams to implement and maintain enterprise...ApplicationSummer workWork at officeLocal areaRemote workFlexible hoursNight shift
$77k - $202k
...At PwC, our people in business application consulting specialise in consulting services for a variety of business applications, helping clients... ...members. We evaluate these factors thoughtfully to establish a secure and trusted workplace for all. Applications will be...ApplicationH1b$102k - $142k
...developing and/or implementing web-based applications. At least two years of experience... ...ensure our work and outputs meet KP IT security and development standards. Technologies... ...Applications Engineer, Web Java/NodeJS IV to support our Digital Experience Engineering...ApplicationFull timeWork experience placement- ...Instructions for more details.You must complete and submit an electronic application for employment to be considered. Resumes will not be accepted... ...divisions at North Carolina A&T State University. Our mission is to support the university through the enhancement and...ApplicationPermanent employmentFull timeWork experience placementWork at officeRemote workFlexible hours
$130k - $175k
...Permanente seeks an IT Infrastructure Engineer IV to design, implement, and optimize highly... ...healthcare systems. You will architect secure, scalable database platforms, automate... ...infrastructure. Collaborate with application, security, and Dev Ops teams to support...Application$44.51k - $54.59k
...Function of Organizational Unit The College of Engineering at North Carolina Agricultural andTechnical State University invites applications and nominations forthis key leadership position. North Carolina A&T StateUniversity is a public land grant university that enrolls...ApplicationPermanent employmentFull timeWork at officeRemote workMonday to FridayFlexible hours- Tech Summary: The Product Manager IV, Health Systems supports the Care Delivery & Digital... ..., and support of enterprise clinical applications that enhance care delivery, utilization... ...product expertise, peer training, and consultation as appropriate; and adhering to enterprise...ApplicationWork experience placement
- ...Engineer V to design, implement, and optimize secure, scalable infrastructure supporting... ...speed. You'll collaborate with security, application, and operations teams to ensure high availability... ...infrastructure issues and provide Tier IV escalation support. Mentor junior...Application
$15 - $21.16 per hour
...that may become available on campus. When a UNCG Department is in need of a temporary Administrative Support Associate, qualified applicants who have applied to this temporary pool will be considered. Duties and responsibilities could include, but are not limited to the...ApplicationHourly payTemporary workWork experience placementWork at office$45k - $50k
...place for employee to travel ie visas and passports. Assist employees in obtaining passports and securing renewals. Assist employees with the completing of the application and obtaining passport photos Update weekly on-call schedule, update online reporting for Answering...ApplicationWork at office$120k - $160k
...Kaiser Permanente seeks a Systems Administrator IV, Applications to support and optimize enterprise healthcare applications. In this senior... ...and integrations to ensure high availability, performance, and security. Responsibilities include monitoring, incident resolution,...Application$110k - $145k
...& Software environment. This role manages server and cloud infrastructure, ensuring high availability, security, and compliance for clinical and business applications. You will perform system upgrades, automation, monitoring, and incident response while collaborating with...Application- ...USEReady is seeking a Senior Analyst, SAP Security in Greensboro, NC. This role is on site in the office 4 days/week Mondays - Thursdays... .... Microsoft environment. Proficiency with standard computer applications including word processing and spreadsheets. Mandatory Skills...ApplicationWork at officeRemote workMonday to Friday
$43.21k - $50.83k
...5 research cluster areas of the COE are Autonomous Systems, Cybersecurity and Resilience, Energy and Sustainability, Healthcare Applications and Complex Systems and Networks. Additional information about the College and the University can be found at The Mechanical...ApplicationPermanent employmentFull timeH1bWork at officeRemote workMonday to FridayFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IS Consultant IV, Application Security. Be the first to apply!
- director of enterprise application services Greensboro, NC
- applications consultant Greensboro, NC
- application scientist Greensboro, NC
- app delivery Greensboro, NC
- senior application security Greensboro, NC
- application security lead Greensboro, NC
- cash application clerk Greensboro, NC
- application system administrator Greensboro, NC
- cash app Greensboro, NC
- cash application representative Greensboro, NC



