Application Security - Security Champion
MetLife – Cary, NC
Job Location: United States : North Carolina : Cary
Role Value Proposition:
MetLifes Application Security Team within IT Risk & Security group leads the effort to secure the large and diverse application portfolio in the enterprise. The Consultant position coordinates the activities within the application security lifecycle which includes the security requirements and SDL alignment across global development teams, organizing and managing global testing effort leading to smooth and efficient testing cycles and remediation are performed according to best practices and performed on schedule. This is a position with high visibility and representation of the IT Risk & Security group to application development leaders both within the company and outside MetLife.
Key Responsibilities: Coordinate and monitor the compliance of global development teams adherence to the SDL process and the related processes Facilitate the execution of web application security testing requested by certain corporate customers on a recurring risk based review schedule. Coordinate with application development teams to evaluate web application vulnerabilities and offer necessary consulting help to remediation of vulnerabilities Oversee and manage the documentation of flaws into risk registry and track remediation activities Collaborate with the global IT Risk and Security team to ensure the alignment on global delivery Assist in the generation of metrics to drive the continuous improvement program and present current state of security status to management team
Essential Business Experience and Technical Skills:
Required: 5+ years of combined Application Security Management, Cyber Security or Application Security Testing experience Experience with JIRA or other defect tracking system in an Agile Scrum environment Experience within the SDLC or development projects Knowledge of OWASP Top 10 and SANS/CWE Top 25
Preferred: Experience managing several testing efforts concurrently Professional certifications preferred, such as CSSLP, CEH, or OSCP Experience with Archer Coding and/or Scripting skills
At MetLife, were leading the global transformation of an industry weve long defined. United in purpose, diverse in perspective, were dedicated to making a difference in the lives of our customers.