|
Associate, Information Security - Quincy Massachusetts
Company: Santander Holdings USA Inc Location: Quincy, Massachusetts
Posted On: 01/28/2025
Associate, Information SecurityDallas, United States of AmericaWe are seeking a Cloud Application Security Tester to manage and operate security services that assess, prioritize, and mitigate information security and technology risks. This role involves conducting regular security assessments, vulnerability scans, and in-depth application security testing, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), API testing, and mobile security assessments. Utilizing tools like AWS GuardDuty, AWS Inspector, and AWS Config, the tester will analyze security issues, provide actionable remediation recommendations, and perform comprehensive web and mobile penetration testing. Ensuring compliance with OWASP Top Ten and CIS benchmarks for AWS, developing security policies, and managing security monitoring solutions with Splunk and SysDig are key responsibilities. The role also includes monitoring security alerts, conducting root cause analysis of incidents, and collaborating with development, QA, and operations teams to integrate security best practices into the SDLC.Essential Functions/Responsibility Statements: - Conducts regular security assessments and vulnerability scans using tools such as AWS GuardDuty, AWS Inspector, and AWS Config.
- Performs Static and Dynamic Application Security Testing (SAST and DAST) on web applications, APIs, and mobile applications to identify security risks and vulnerabilities.
- Conducts web and mobile penetration testing to assess the robustness of applications and identify weaknesses.
- Analyzes and interprets security issues identified by these tools, providing detailed and actionable recommendations for remediation.
- Performs comprehensive code reviews to identify and mitigate potential vulnerabilities.
- Ensures compliance with industry standards and frameworks, including OWASP Top Ten and CIS benchmarks for AWS.
- Develops, maintains, and enforces security policies, procedures, and documentation to support compliance efforts.
- Conducts thorough audits and assessments to ensure ongoing adherence to security policies and standards.
- Implements and manages advanced security monitoring solutions using Splunk and SysDig.
- Monitors security alerts and incidents, coordinating response efforts to effectively mitigate risks.
- Conducts in-depth root cause analysis of security incidents and implements robust measures to prevent recurrence.
- Collaborates closely with development, QA, and operations teams to integrate security best practices into the SDLC.
- Stays abreast of the latest security trends, threats, and technologies.
- Continuously improves security processes and controls to enhance the overall security posture of the organization.Qualifications: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.Education: Bachelor's Degree or equivalent work experienceWork Experience: 5-9 years; Experience in Information security, Cloud governance, IT audit, or risk management.Skills and Abilities:
|
|