Application Security Associate/Analyst
Job Description
As an Application Security Associate or Analyst at the Federal Reserve Bank of Cleveland, you will lead efforts to safeguard the confidentiality, integrity, and availability of web and mobile Treasury Services applications. You will define security requirements, review secure coding, monitor for breaches, and support security testing and awareness across the software development lifecycle.
Location: Cleveland, OH (onsite). This is a full-time, regular, exempt position with a salary range of USD 73,400 to 102,300 per year. Education requirement: Master’s degree.
Responsibilities
- Identify security related issues and establish security requirements across all stages of the application development lifecycle.
- Review program and development documents to ensure alignment with secure coding standards, guidelines, and security requirements.
- Coordinate with developers to enable secure and resilient design, prototyping, development, testing, support, and documentation of moderately complex application software.
- Monitor for atypical usage of information system accounts and other abnormalities to identify potential breaches.
- Support FISMA initiatives, including updating security plans to fulfill ISSO responsibilities.
- Coordinate the identification of security-related issues and definition of security requirements throughout the SDLC.
- Perform penetration testing to verify that web applications within Treasury Services are free from vulnerabilities.
- Analyze cybersecurity trends and emerging risks, quantify potential impact, and develop actionable application security responses.
- Perform other duties as assigned or requested.
Requirements
- Educational pathways include: an associate degree with 2 years of related experience; a bachelor’s degree with no related experience; an associate degree with 5 years of related experience; a bachelor's degree with 3 years of related experience; or a master’s degree with 0-1 year of related experience.
- Ability to analyze highly complex business requirements.
- Thorough understanding of industry-based security controls related to applications, services, and systems.
- Knowledge of cloud-based platforms and technologies.
- Strong grasp of security controls related to access control, authentication, and auditing.
- Demonstrated knowledge of information security industry trends and emerging technologies, especially as they relate to application security vulnerabilities.
- Proficient in testing web applications for security vulnerabilities, including those in the OWASP Top 10, and familiar with the tools used for testing.