CybersecurityJobs.io
← Back to all jobs

Job Description

Build security into the way products ship. In this hybrid role in Lafayette, LA, you’ll help strengthen application security across a large financial services environment, with a focus on AWS and DevSecOps. CGI emphasizes continuous learning, strong benefits, and the support you need to deliver secure outcomes across the software development lifecycle.

You’ll partner with development and technology teams to identify, assess, and remediate security risks from design through release. The work is hands-on, combining application security testing, threat modeling, and secure coding guidance with CI/CD integrations and cloud security considerations.

Responsibilities

  • Perform manual and automated application and code security reviews to identify vulnerabilities and security risks.
  • Conduct threat modeling and security risk assessments for both new and existing applications.
  • Collaborate with development teams to determine appropriate remediation approaches for application security findings.
  • Use SAST, DAST, and Software Composition Analysis (SCA) tools as part of application security testing.
  • Support the integration of security controls and testing into CI/CD pipelines.
  • Evaluate application security considerations across AWS and containerized environments.
  • Apply knowledge of network protocols, encryption, secure coding practices, and common application vulnerabilities.
  • Partner with development and security teams to strengthen DevSecOps practices throughout the software development lifecycle.
  • Develop FAQs, guidance, and reusable security best practices for development and technology communities.

Requirements

  • 5+ years of experience in application security and secure software development practices.
  • Experience using SAST, DAST, and SCA tools to identify application vulnerabilities.
  • Experience conducting manual code reviews, threat modeling, and application security risk assessments.
  • Working knowledge of AWS security and securing applications deployed in cloud environments.
  • Experience with DevSecOps and integrating security testing into CI/CD pipelines.
  • Experience with GitHub, Jenkins, or comparable CI/CD platforms.
  • Understanding of container security and related application security risks.
  • Programming or code review experience with Java, Python, JavaScript, C#, or similar languages.
  • Strong understanding of network protocols, encryption, authentication, and common application security vulnerabilities.
  • Ability to clearly communicate security findings and remediation recommendations to developers and other technical stakeholders.
  • Experience in financial services or another highly regulated environment is preferred.
  • Relevant certifications may be beneficial, such as AWS Certified Security Specialty, CISSP, CSSLP, or GIAC application security certifications.
  • Bachelor’s degree in Computer Science, Information Systems, or a related field.

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • Matching contributions through the 401(k) plan and the share purchase plan
  • Paid time off for vacation, holidays, and sick time
  • Paid parental leave
  • Learning opportunities and tuition assistance
  • Wellness and Well being programs

Compensation: USD 97,300 - 123,800 per year.

Location: Lafayette, LA (hybrid). CGI also notes client site locations in Birmingham, AL, Knoxville, TN, and Columbia, SC; a hybrid working model is acceptable.

Additional information: In some jurisdictions, CGI is required to provide a reasonable estimate of the compensation range. A reasonable estimate of the current U.S. range for this role is $97,300.00 to $123,800.00.

Background checks: Employment offers in the U.S. are contingent upon successfully completing a background investigation; some investigations may include a credit check depending on role and/or federal government security clearance requirements.

Similar Jobs