CybersecurityJobs.io
← Back to all jobs

Job Description

Kaiser Permanente is seeking a Cybersecurity Consultant IV, Application Security for an onsite role in Greensboro, NC, offering a salary of USD 121,000 per year.

Responsibilities

  • Conduct source code reviews to identify security vulnerabilities and perform manual and automated testing on live applications (DAST).
  • Collaborate with DevOps teams to embed application security services into the development lifecycle.
  • Train DevOps personnel and developers on using application security tools effectively.
  • Provide one-on-one guidance to developers to understand vulnerabilities and craft remediation plans.
  • Recommend targeted application security training paths for teams.
  • Protect production apps through continuous assessment of existing and emerging threats.
  • Assess web application firewall configurations and tune WAF rules as needed.
  • Monitor security alerts and identify issues requiring escalation or resolution.
  • Plan and execute work assignments, align with business priorities, and develop work plans to meet deadlines while ensuring policy compliance; coordinate resources and collaborate cross-functionally to address complex problems and escalate high-priority risks.
  • Foster self-development and mentor others by sharing knowledge, building cross-functional relationships, and communicating technical concepts clearly; respond to feedback and implement improvement plans.
  • Communicate investigative findings effectively to non-technical audiences.
  • Partner with technology risk teams and business stakeholders to remediate identified issues and strengthen security posture.
  • Offer management with remediation recommendations derived from security testing processes.
  • Evaluate the impact of security test plans on upstream and downstream components of solutions.
  • Support information sharing and integration across cybersecurity through threat intelligence and vulnerability assessment data exchange.
  • Contribute to cybersecurity knowledge capital by improving processes, leading brown bag sessions, and creating training materials.
  • Follow established processes to achieve KPI goals and maintain ongoing performance metrics.
  • Suggest security process improvements for business lines or technology teams aligned with sustainable best practices and strategic goals.
  • Support continuous process improvement by participating in the development and maintenance of standardized security tools, templates, and processes across multiple domains.
  • Perform complex security test data analysis to support vulnerability assessment activities and root cause analysis.
  • Serve as an escalation point for issues, dependencies, and risks related to security testing.
  • Execute vulnerability assessment and penetration testing plans for moderately to highly complex initiatives across multiple IT domains by analyzing business and technical requirements.
  • Stay current with industry trends, emerging threats, and best practices to identify vulnerabilities and propose security solutions for technology systems.
  • Offer guidance on testing scope and approach, collaborating with IT and business stakeholders to review the overall strategy.
  • Validate security test scenarios across SDLC phases for low- to moderately complex projects.
  • Generate scheduled reports and provide security metrics to IT teams and management as appropriate.

Requirements

  • Minimum three years of software or application development experience.
  • Minimum one year of experience in application security, including activities such as source code analysis or dynamic analysis.
  • Bachelor's degree in Business Administration, Computer Science, Social Science, Mathematics, or a related field, plus at least six years of IT or related experience, including at least two years in information security, network engineering, or application development. Additional equivalent work experience may substitute for the degree requirement.

Similar Jobs