Strategic Planning:
- Align application security initiatives with business goals; refine Product Security processes and tools.
Technical Leadership:
- Stay updated on the latest trends and advancements in application security and apply them to continually improve the organizations security program.
- Recommend mitigations for vulnerabilities; manage third-party and open-source software risk.
Architecture and Design:
- Review application designs for security best practices.
- Design, enhance, and advocate for the threat modelling process. Conduct threat modelling and advise product teams on implementing appropriate security controls.
Security Reviews:
- Conduct security assessments throughout the development lifecycle.
- Collaborate with development teams to remediate security vulnerabilities.
Code Review and Analysis:
- Conduct code reviews and implement automated code analysis tools.
Secure Development Practices:
- Enforce secure coding practices, train developers in secure coding.
Incident Response/Customer Escalations:
- Lead incident response efforts related to application security incidents.
- Work with cross-functional teams to investigate and remediate security breaches.
Policy and Standards:
- Develop and enforce application security policies; ensure compliance with industry standards.
Security Testing:
- Oversee the implementation of security testing methodologies
- Conduct Penetration Testing activity for applications/systems
Security Awareness:
- Promote security awareness across engineering; conduct training for development teams on Static Application Security Testing (SAST) and Agile Application Security Testing (DAST).
Collaboration:
- Collaborate with cross-functional teams, including development, operations, GIS, etc., to integrate security into all aspects of the software development lifecycle and improve security maturity.
Documentation and Reporting:
- Maintain comprehensive documentation of security processes/policies; produce maturi