Senior Associate - Application Security and Vulnerability Management Specialist
Remote, NY, US
Location Designation: Hybrid - 3 days per quarter
As part of Technology, you'll have the opportunity to contribute to groundbreaking initiatives that shape New York Life's digital landscape. Leverage cutting-edge technologies like Generative AI to increase productivity, streamline processes, and create seamless experiences for clients, agents, and employees. Your expertise fuels innovation, agility, and growth — driving the company's success
Role Overview:
This role involves supporting the tools used within these programs as well as providing technical guidance, conducting, and reviewing application security testing, and integrating security best practices into the software development lifecycle in support of secure coding standards. The specialist will be hands on and oversee vulnerability identification and remediation, perform threat modeling, conduct security design reviews, and provide day-to-day guidance to a team of consultants. Additionally, they will offer technical direction to other security teams, evaluate system performance, perform risk assessments, and manage enhancement projects.
We are searching for a highly motivated Security professional with 5 years of experience to play a pivotal role in safeguarding our organization's data and systems. As the Vulnerability & Application Security Specialist, you will be responsible for supporting a comprehensive program that ensures the security of our on-premises and cloud environments.
What You’ll Do:
Application Security:
- Conduct manual application security testing to identify vulnerabilities and recommend remediation strategies.
- Manage and prioritize vulnerabilities using tools such as Checkmarx and HCL AppScan
- Implement and maintain robust cloud security practices to protect our cloud-based infrastructure.
- Collaborate with development teams to integrate security best practices into the software development lifecycle.
- Conduct regular security assessments and code reviews to ensure applications are secure.
- Provide security training and awareness to development teams.
Vulnerability Management:
- Manage the end-to-end vulnerability management lifecycle, including identification, assessment, remediation, and reporting of security vulnerabilities.
- Oversee the build of new elements of the vulnerability management technology strategy.
- Lead planning activities for vulnerability management security areas, providing insight into future trends and challenges.
- Conduct regular vulnerability scans to identify security weaknesses.
- Ensure compliance with security policies, standards, and regulations.
- Provide oversight and guidance to a team of technical security professionals responsible for managing the engineering of vulnerability and configuration management processes.
Leadership & Collaboration:
- …
This job isn't fresh anymore!
Search Fresh JobsJob Profile
Hybrid Hybrid work model
Benefits/PerksAdoption Assistance Annual discretionary bonus Benefits Collaboration Discretionary bonus Discretionary bonus eligible Employee giving Financial Security Hybrid work Incentive Program Innovation Leave programs Overtime eligible Sales bonus Sales bonus eligible Student Loan Repayment Student loan repayment programs Volunteerism
Tasks- Collaborate with teams
- Collaboration
- Compliance
- Ensure compliance
- Manage vulnerabilities
- Perform risk assessments
- Provide technical guidance
- Reporting
- Training
AI Application Security Cloud Cloud Security Collaboration Communication Communications Compliance Engineering Generative AI Innovation Interpersonal IT Leadership Mentorship Planning Qualys Reporting Risk assessments Sales Secure coding Security Security Best Practices Security Training ServiceNow Software Development Technical Technical Guidance Technology Threat modeling Training Vulnerability Management Vulnerability scans
Experience5 years
Education TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9