Lead Application Security Analyst
Cleveland, OH 
Share
Posted 10 days ago
Job Description
Strategy & Planning
  • Acquire and interpret business requirements and functional specifications to create security non-functional requirements.
  • Work with the security architects to validate potential architectures through techniques like threat modeling.
  • Maintain knowledge of best security practices through training, research, involvement with local IT security groups, and collaboration with internal cybersecurity teams.
  • Identify areas for improvement by recommending the use of reusable code libraries introduced in standard build/deploy pipelines.
  • Assist development teams in updating the CMDB records to reflect current state.
  • Validate that OS, middleware, and images are being scanned for vulnerabilities at regular intervals and any reported vulnerabilities are tied back to the appropriate application(s).
  • Work with development and QA teams to ensure the use of secure coding practices and verification methods.
  • Work with dev-ops teams and engineers to integrate security solutions into continuous delivery frameworks.
  • Mitigate security risks associated with projects, which have a high technical complexity and/or involve significant challenges to the business.
  • Work with delivery teams and product owners to reduce application security risks by assisting with code remediation before production delivery.
Acquisition & Deployment
  • Work with architects and developers to design optimal security practices when developing new application functionality.
Operational Management
  • Support and maintain automated application security testing within the devops pipelines.
  • Provide input in updating security standards on an annual basis.

Ensure that all applications are using effective security monitoring, and work with the endpoint security team to test configurations.

Incidental Functions
  • Deciding new technologies including tools, components, and frameworks.
  • Project and task management and reporting as necessary.
  • Make presentations to management, clients, and peer groups as requested.
  • Participate in hiring activities and fulfilling affirmative action obligations and ensuring compliance with the equal employment opportunity policy.

This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa.

This position has a hybrid work schedule with three days in the office and the option for working remotely two days.

Formal Education & Certification
  • Bachelor's degree (or foreign equivalent) in a Computer Science, Computer Engineering, or Information Technology field of study (e.g., Information Technology, Electronics and Instrumentation Engineering, Computer Systems Management, Mathematics) or equivalent experience.
  • GIAC GWAPT, or CISSP certifications are a plus.
Knowledge & Experience
  • 8+ years of total IT and/or cybersecurity experience
  • Experience working on all phases of the Software Development Lifecycle.
Preferred Experience
  • 3+ year(s) of experience in securing web services
  • 3+ years of coding experience, preferably Java
  • Detailed understanding of authentication/authorization best practices
  • Working knowledge of oAuth 2.0 flows
  • Understanding of integrating security practices with container-based deployments
  • Understanding of web application firewall technology
  • Mentoring software engineers in writing secure code.
Personal Attributes
  • Strong analytical, conceptual, and problem-solving abilities.
  • Good written and oral communication skills.
  • Good presentation and interpersonal skills.
  • Ability to present ideas in user-friendly language.
  • Able to prioritize and execute tasks in a high-pressure environment.
  • Ability to work in a team-oriented, collaborative environment.
  • Strong commitment to inclusion and diversity
  • Minimal travel is required.
  • Work outside the standard office 7.5-hour workday may be required.

Sherwin-Williams is proud to be an Affirmative Action, Equal Employment Opportunity, Inclusion and Diversity Supportive Employer. All qualified candidates will receive consideration for employment and will not be discriminated against based on race, color, religion, sex, sexual orientation, gender identify, national origin, protected veteran status, disability, age, pregnancy, genetic information, creed, marital status or any other consideration prohibited by law or by contract.

VEVRAA Federal Contractor requesting priority referral of protected veterans.

 

Job Summary
Start Date
As soon as possible
Employment Term and Type
Regular, Full Time
Salary and Benefits
$103,301.38 - $133,336.05 Annually
Required Education
Bachelor's Degree
Required Experience
8+ years
Email this Job to Yourself or a Friend
Indicates required fields