Job Description:
The Product Manager – Tech Delivery will be a member of the Business Information Security Officer's (BISO) organization and work closely with Line of Business (LOB) Chief Information Officers (CIOs), Chief Technology Officers (CTOs), application development teams, architects, and technology partners.
In this role, you will develop a deep understanding of business applications, technology platforms, and software delivery processes to support specialized information security and application security risk discussions. This partnership helps ensure focus on the most critical security priorities while enabling secure software delivery across the Software Development Lifecycle (SDLC).
The role serves as a technical Application Security subject matter expert responsible for reviewing, validating, analyzing, and adjudicating application security findings identified through enterprise security testing platforms, including Checkmarx One. This includes performing detailed source code analysis, vulnerability validation, exploitability assessments, risk evaluations, and disposition decisions to ensure security findings are accurately assessed, consistently governed, and aligned with enterprise security standards and risk-management objectives.
The successful candidate will partner closely with development teams, architects, security engineers, product owners, and risk partners to drive secure development practices, vulnerability remediation, and risk-based security decision making across the enterprise.
Responsibilities:
• Possess a strong application security background with extensive knowledge of software development methodologies, SDLC processes, software architecture, and secure coding practices.
• Serve as the primary technical reviewer and adjudicator for application security findings generated through Checkmarx One and other approved security testing technologies.
• Review, analyze, validate, and disposition application security findings using evidence-based technical analysis.
• Independently validate vulnerability findings rather than relying solely on automated scanner results, developer rationale, AI-generated recommendations, or previous dispositions.
• Analyze source code, application architecture, APIs, business logic, trust boundaries, data flows, and software design patterns to assess vulnerability validity and security impact.
• Evaluate exploitability, reachability, attack paths, compensating controls, exposure conditions, and real-world security risk.
• Review and validate developer-submitted adjudication requests, including Proposed Not Exploitable determinations and supporting evidence packages.
Required Qualifications:
• 10+ years of Information Security, Application Security, Secure Software Development, or Technology Risk Management experience.
• 5+ years of experience in Application Security, Secure Software Development, Vulnerability Management, Security Architecture, or Information Security Risk Management.
• Strong experience performing source code analysis, vulnerability validation, application security assessments, and security testing.
• Subject matter expertise in Application Security, Secure SDLC, Vulnerability Management, Threat Modeling, Secure Coding Practices, OWASP Top 10, and Common Weakness Enumerations (CWE).
• Experience with Checkmarx One or comparable enterprise application security testing platforms.
• Ability to evaluate, validate, and adjudicate complex SAST, SCA, API Security, and related application security findings using risk-based analysis.
• Experience identifying false positives, exploitability constraints, compensating controls, and appropriate risk treatment strategies.
• Strong understanding of modern application architectures, APIs, microservices, cloud-native technologies, and DevSecOps practices.
• Experience evaluating application security controls across cloud, SaaS, PaaS, distributed, and on-premises environments.
• Strong knowledge of NIST, ISO, PCI DSS, and related security frameworks.
• Ability to communicate technical security findings, risk decisions, and remediation guidance to both technical and non-technical stakeholders.
• Strong analytical, problem-solving, stakeholder management, and risk assessment skills.
Desired Qualifications:
• Bachelor's and/or Master's degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field.
• CISSP, CSSLP, CISM, CRISC, GIAC, OSCP, or equivalent industry certifications.
• Experience supporting enterprise application security programs and secure software development initiatives.
• Experience with AI-assisted development and code-analysis tools such as GitHub Copilot.
Skills:
Shift:
1st shift (United States of America)
Hours Per Week:
40
Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range
$135,000.00 - $217,100.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.