Kao Corporation

Federal Vulnerability Mgmt & App Security Engineer (US Citizen)

Kao Corporation$125K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of experience in cybersecurity, application security, or vulnerability management.
  • Strong understanding of information security risk measurement and prioritization.
  • Hands-on experience with application security testing methodologies (SAST, DAST, SCA).
  • Familiarity with OWASP Top 10 and application security attack patterns.
  • Expertise in vulnerability management lifecycle and remediation governance.

Responsibilities

  • Drive improvements in vulnerability management processes and tools through automation.
  • Stay updated on industry trends and emerging threats to enhance the program.
  • Evaluate and recommend effective vulnerability management tools and technologies.
  • Deliver regular reports and metrics to executive leadership on vulnerability management.
  • Build a comprehensive vulnerability management program that incorporates secure SDLC practices.
  • Conduct technical threat and vulnerability assessments and manage their lifecycle.
  • Collaborate with DevOps teams to integrate security into the CI/CD pipeline.

Benefits

  • 401(k) with employer contributions and pension options.
  • Enhanced paid time off policies.
  • Comprehensive medical insurance with additional coverage options (dental, vision, life).
  • Flexible Spending Accounts available in the US.
  • Confidential Employee Assistance Program (EAP).
  • Support for work-life balance with flexible work options.
  • Wellness initiatives promoting health and well-being.
  • Opportunities for personal and professional growth, including a Volunteer Day.
Full Job Description
Title: Vulnerability Mgmt. and Application Security Engineer

Location: Remote-US

Salary: $125K annually

The Threat, Vulnerability & Application Security Analyst is a dual-focus security practitioner responsible for identifying, assessing, and reducing risk across infrastructure, cloud, and application environments. This role combines enterprise threat and vulnerability management with hands-on application security oversight across the software development lifecycle (SDLC).

The analyst correlates threat intelligence, asset inventory, vulnerability data, and application risk to inform security priorities, guide remediation, and continuously improve the organization's security posture. A core responsibility is partnering closely with engineering, platform, and product teams to embed security earlier in development, reduce exploitable risk, and ensure compliance with internal security standards and external regulatory requirements.

This role emphasizes automation, scalability, and pragmatism-driving measurable risk reduction through tooling, process improvements, and actionable security guidance. Success requires persistence, strong technical depth across AppSec and vulnerability domains, and the ability to translate risk into clear, prioritized actions for technical and non-technical stakeholders.

Role Responsibilities
  • Drive continuous improvements in vulnerability management processes and tools by leveraging industry-leading technologies, automation, and data-driven insights.
  • Stay current on industry trends, emerging threats and best practices in vulnerability management and adapt the program accordingly.
  • Evaluate and recommend vulnerability management tools and technologies, ensuring the optimal balance of effectiveness and efficiency.
  • Develop and deliver regular metrics, reports, KPIs and presentations to executive leadership and key stakeholders, communicating the status and effectiveness of the vulnerability management program.
  • Assist in building a diverse vulnerability management program that covers secure software development lifecycle, patch governance, and application security.
  • Perform technical threat/risk and vulnerability assessments and manage vulnerabilities throughout their lifecycle.
  • Provide support and maintain tools required for the vulnerability management program.
  • Provide consultative support to operational teams on how to fix identified vulnerabilities.
  • Own and evolve the Application Security program, integrating findings into the broader vulnerability management lifecycle.
  • Perform and oversee application security assessments, including static (SAST), dynamic (DAST), software composition analysis (SCA), and manual secure code reviews where appropriate.
  • Partner with development and DevOps teams to embed security into the SDLC, including CI/CD pipeline integrations and secure design reviews.
  • Define and maintain application risk prioritization that considers exploitability, business impact, data sensitivity, and threat context.
  • Review application architectures and threat models to proactively identify design-level security weaknesses.
  • Establish and maintain secure coding standards aligned to OWASP Top 10 and industry best practices.
  • Triage, validate, and manage application vulnerabilities through remediation and verification.
  • Enable developer success through consultative AppSec support, clear remediation guidance, and security-by-design recommendations.

Knowledge, Skills and Experience Requirements

Core Security & Risk
  • Strong understanding of information security risk measurement (qualitative and quantitative) to support effective prioritization.
  • Working knowledge of industry security frameworks and standards (e.g., NIST CSF/800-53, ISO 27001, OWASP).
  • Ability to correlate threat intelligence with vulnerability and application risk.

Application Security (New / Expanded)
  • Solid understanding of secure application development, including common programming languages, frameworks, and architectural patterns.
  • Hands-on experience with Application Security testing methodologies, including:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
  • Familiarity with OWASP Top 10, API Security Top 10, and common application attack patterns.
  • Experience integrating security scanning tools into CI/CD pipelines.
  • Ability to perform threat modeling and design-level security assessments.
  • Strong understanding of authentication, authorization, session management, and data protection controls within applications.

Vulnerability & Threat Management
  • Expertise in vulnerability management programs, including lifecycle management and remediation governance.
  • Experience with vulnerability scanning and reporting tools (e.g., Qualys, Tenable, CrowdStrike, or equivalent).
  • Familiarity with cyber threat intelligence services and the application of threat data to prioritization decisions.
  • Broad technical knowledge of networks, operating systems, cloud platforms, and web applications

Education and Experience
  • 3+ years of combined experience in cybersecurity, application security, or vulnerability management.
  • Prior experience working closely with software engineering or DevOps teams is strongly preferred.
  • Ability to pass an IRS Clearance and Background Check REQUIRED

Benefits & Culture
    • Retirement Benefits: 401(k), pension, or country-specific retirement plans with employer contributions
    • Generous Time Off: Enhanced paid time off/annual leave policies
    • Health & Wellbeing Coverage: Medical insurance tailored to your region, plus:
      • US: Dental, vision, life, and short-term disability insurance
      • UK: Medical cashback plan including dental, vision, and income protection
    • Flexible Spending Accounts (US)
    • Employee Assistance Program (EAP): Confidential support whenever you need it
    • Work-Life Balance: We understand life happens outside of work, and we fully support flexibility
    • Wellness Culture: Regular global wellness initiatives to help you stay healthy and inspired
    • Future Planning: Tools and support to help you grow personally and professionally
    • Giving Back: Enjoy a Volunteer Day each year and opportunities to support our communities and industry
    • Alongside a competitive salary, we offer a comprehensive benefits package designed to support your well-being, your future, and your sense of purpose.

At PSI, we're more than just a workplace - we're a global team driven by shared values and real impact. If you're ready to be part of a company that's committed to your growth and well-being, we'd love to hear from you.

About Kao Corporation

Kao Corporation is a Japanese consumer goods company headquartered in Tokyo. It specializes in personal care, cosmetics, laundry and cleaning products, and has subsidiaries in several countries. The company was founded in 1887 and has a long history of innovation and sustainability. Kao is committed to reducing its environmental impact and has set ambitious targets for carbon reduction and waste reduction. The company is also known for its corporate social responsibility initiatives, including support for education and disaster relief.
Learn more about Kao Corporation
Size
33,000 employees
Industry

Similar Jobs

More Jobs at Kao Corporation

More Information Technology Jobs

Find similar Federal Vulnerability Mgmt & App Security Engineer (US Citizen) jobs: