Search by job, company or skills

Application Security Risk Manager

8-15 Years
  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

We are seeking an experienced Application Security Risk Manager to provide risk oversight and challenge across application security and technology controls.

The role will partner with Technology, Cybersecurity and Engineering teams to identify security risks and ensure applications are designed, developed and operated securely.

Key Responsibilities:

  • Provide risk oversight and challenge across application security and software development activities.
  • Conduct security risk assessments for new applications, major technology changes and critical systems.
  • Assess security controls across the SDLC, including secure design, development, testing, deployment and production.
  • Review risks relating to application vulnerabilities, APIs, integrations, authentication, access management and data protection.
  • Assess DevSecOps and CI/CD controls, including SAST, DAST, penetration testing and vulnerability management.
  • Review security exceptions, risk assessments and remediation plans and provide independent challenge where required.
  • Assess application security across on-premise, cloud and hybrid environments.
  • Conduct thematic reviews to identify systemic risks and control weaknesses.
  • Oversee significant application security incidents and remediation.
  • Develop risk metrics and contribute to application security policies, standards and control frameworks.
  • Monitor emerging application security threats and advise stakeholders on relevant risks.

Requirements:

  • 8-15 years of experience across application security, cybersecurity, technology risk, security architecture or technology assurance.
  • Strong understanding of application security, SDLC and secure software development.
  • Knowledge of DevSecOps, CI/CD, APIs, IAM, vulnerability management and cloud security.
  • Experience assessing application security controls and technology risks.
  • Familiarity with SAST, DAST, penetration testing and frameworks such as OWASP, NIST and ISO 27001.
  • Financial services and regulatory experience would be advantageous.
  • Strong analytical, communication and stakeholder management skills.
  • Certifications such as CISSP, CISM, CRISC, CSSLP or CCSP would be advantageous

To apply:

If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.

Reg: R1876389

Lic: 16S8060

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152550119

Beware of Scammers

We don’t charge money for job offers