Role description
Job Description
Job Title Application Security Assessment
Location : New York , NY
Key Responsibilities
Application Security Assessments
Conduct end to end security design reviews and related validationverification tasks for 50 applications across SaaS onpremises and IaaS environments.
Conduct fullstack security assessments and provide control requirements based on the applications activity scope capabilities and boundaries with focus areas and other areas as applicable with context to the application being assessed.
Frontend Clientside security.
Backend Platform security.
Identity Access Management IAM.
Encryption in transit and at rest.
Network security.
Data security.
Logging monitoring and SIEM integration.
Evaluate security controls against each applications activity scope capabilities and trust boundaries.
Document findings control gaps and recommendations in standardized Word or Excel templates
Control Management Tracking
Identify track and maintain the status of critical security controls for each application in scope
Apply security standards and control frameworks eg NIST CIS ISO 27001 to rationalize and map control requirements
Maintain accurate and uptodate deliverable tracking in Asana across all active reviews
Stakeholder Engagement
Identify and engage application owners using the enterprise application management portfolio or through direct outreach
Interview application owners and obtain necessary access to assess current security posture
Provide clear prioritized mitigation guidance for identified gaps aligned to enterprise policies and standards
Engage thirdparty application vendors as required to support assessment activities
Serve as a direct point of contact for application owners and crossfunctional enterprise teams seeking guidance or information
Reporting Cadence
Participate in weekly checkins to report on assessment progress blockers and completed reviews
Report directly to the VP of Information Security
Communicate findings and recommendations in a clear businessappropriate manner to both technical and nontechnical stakeholders
Required Qualifications
5 years of experience in information security with a focus on application security architecture or security assessments
Demonstrated experience conducting security design reviews or threat modeling for enterprise applications SaaS IaaS and onpremises
Strong working knowledge of security control frameworks NIST CSF NIST SP 80053 CIS Controls ISO 27001
Familiarity with fullstack application security concepts including authentication authorization encryption API security network segmentation and data protection
Experience working directly with application owners product teams and vendors in an enterprise environment
Strong written communication skills ability to produce clear structured assessment documentation in Word and Excel
Highly organized with demonstrated ability to manage multiple concurrent assessments and track deliverables Asana or similar project management tools
Preferred Qualifications
Relevant certifications CISSP CCSP CISM CSSLP or equivalent
Familiarity with cloud security principles across AWS Azure or GCP
Experience applying security standards to vendorthirdparty risk assessments
Prior experience working within media entertainment or largescale enterprise environments
What Success Looks Like
By the end of this engagement you will have delivered
50 completed security design reviews and validationverification tasks with documented control assessments and findings
A maintained uptodate control tracking register across all applications in scope
Mitigation guidance provided to application owners with clear actionable remediation steps
All deliverables logged and tracked in Asana with review documentation available in Word or Excel