Product Manager – Tech Delivery - Application Security Adjudication & Risk Management
Job Description
Bank of America is hiring a Product Manager for Tech Delivery focused on Application Security Adjudication & Risk Management within the BISO organization. In this role, you will act as a technical application security subject matter expert, helping partner with technology and risk stakeholders to make evidence-based decisions on application security findings and support secure software delivery across the SDLC.
Location: Washington, DC (onsite) | Schedule: 1st shift (United States of America) | Hours: 40 hours per week
What you’ll do
- Apply deep application security expertise across software development methodologies, SDLC processes, software architecture, and secure coding practices.
- Serve as the primary technical reviewer and adjudicator for application security findings produced by Checkmarx One and other approved security testing technologies.
- Review, analyze, validate, and disposition findings using evidence-based technical analysis.
- Independently validate vulnerabilities instead of relying only on automated scanner results, developer rationale, AI-generated recommendations, or prior dispositions.
- Assess source code, application architecture, APIs, business logic, trust boundaries, data flows, and software design patterns to evaluate vulnerability validity and security impact.
- Evaluate exploitability, reachability, attack paths, compensating controls, exposure conditions, and overall real-world risk.
- Review and validate developer-submitted adjudication requests, including Proposed Not Exploitable determinations and supporting evidence packages.
Requirements
- 10+ years of experience in Information Security, Application Security, Secure Software Development, or Technology Risk Management.
- 5+ years of experience in Application Security, Secure Software Development, Vulnerability Management, Security Architecture, or Information Security Risk Management.
- Strong experience performing source code analysis, vulnerability validation, application security assessments, and security testing.
- Subject matter expertise in Application Security, Secure SDLC, Vulnerability Management, Threat Modeling, Secure Coding Practices, OWASP Top 10, and Common Weakness Enumerations (CWE).
- Experience with Checkmarx One or comparable enterprise application security testing platforms.
- Ability to evaluate, validate, and adjudicate complex SAST, SCA, API Security, and related findings using risk-based analysis.
- Experience identifying false positives, exploitability constraints, compensating controls, and appropriate risk treatment strategies.
- Strong understanding of modern application architectures, APIs, microservices, cloud-native technologies, and DevSecOps practices.
- Experience evaluating application security controls across cloud, SaaS, PaaS, distributed, and on-premises environments.
- Strong knowledge of NIST, ISO, PCI DSS, and related security frameworks.
- Ability to communicate technical security findings, risk decisions, and remediation guidance to both technical and non-technical stakeholders.
- Strong analytical, problem-solving, stakeholder management, and risk assessment skills.
Preferred / desired qualifications
- Bachelor’s and/or Master’s degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field.
- CISSP, CSSLP, CISM, CRISC, GIAC, OSCP, or equivalent industry certifications.
- Experience supporting enterprise application security programs and secure software development initiatives.
- Experience with AI-assisted development and code-analysis tools such as GitHub Copilot.
Tools and frameworks
- Checkmarx One, SAST, SCA, OWASP Top 10, Common Weakness Enumerations (CWE)
- NIST, ISO, PCI DSS
- AI-generated recommendations (used in adjudication context)
Skills you’ll use
- Financial Management, Influence, Stakeholder Management
- Solution Delivery Process, Technical Strategy Development, Agile Practices
- Analytical Thinking, Collaboration, Result Orientation
- Risk Management, Business Acumen, Business Case Analysis, Data Management
- Solution Design, Vendor Management
Similar Jobs
T
A