CybersecurityJobs.io
← Back to all jobs

Job Description

Bank of America is hiring a Product Manager for Tech Delivery focused on Application Security Adjudication & Risk Management within the BISO organization. In this role, you will act as a technical application security subject matter expert, helping partner with technology and risk stakeholders to make evidence-based decisions on application security findings and support secure software delivery across the SDLC.

Location: Washington, DC (onsite) | Schedule: 1st shift (United States of America) | Hours: 40 hours per week

What you’ll do

  • Apply deep application security expertise across software development methodologies, SDLC processes, software architecture, and secure coding practices.
  • Serve as the primary technical reviewer and adjudicator for application security findings produced by Checkmarx One and other approved security testing technologies.
  • Review, analyze, validate, and disposition findings using evidence-based technical analysis.
  • Independently validate vulnerabilities instead of relying only on automated scanner results, developer rationale, AI-generated recommendations, or prior dispositions.
  • Assess source code, application architecture, APIs, business logic, trust boundaries, data flows, and software design patterns to evaluate vulnerability validity and security impact.
  • Evaluate exploitability, reachability, attack paths, compensating controls, exposure conditions, and overall real-world risk.
  • Review and validate developer-submitted adjudication requests, including Proposed Not Exploitable determinations and supporting evidence packages.

Requirements

  • 10+ years of experience in Information Security, Application Security, Secure Software Development, or Technology Risk Management.
  • 5+ years of experience in Application Security, Secure Software Development, Vulnerability Management, Security Architecture, or Information Security Risk Management.
  • Strong experience performing source code analysis, vulnerability validation, application security assessments, and security testing.
  • Subject matter expertise in Application Security, Secure SDLC, Vulnerability Management, Threat Modeling, Secure Coding Practices, OWASP Top 10, and Common Weakness Enumerations (CWE).
  • Experience with Checkmarx One or comparable enterprise application security testing platforms.
  • Ability to evaluate, validate, and adjudicate complex SAST, SCA, API Security, and related findings using risk-based analysis.
  • Experience identifying false positives, exploitability constraints, compensating controls, and appropriate risk treatment strategies.
  • Strong understanding of modern application architectures, APIs, microservices, cloud-native technologies, and DevSecOps practices.
  • Experience evaluating application security controls across cloud, SaaS, PaaS, distributed, and on-premises environments.
  • Strong knowledge of NIST, ISO, PCI DSS, and related security frameworks.
  • Ability to communicate technical security findings, risk decisions, and remediation guidance to both technical and non-technical stakeholders.
  • Strong analytical, problem-solving, stakeholder management, and risk assessment skills.

Preferred / desired qualifications

  • Bachelor’s and/or Master’s degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field.
  • CISSP, CSSLP, CISM, CRISC, GIAC, OSCP, or equivalent industry certifications.
  • Experience supporting enterprise application security programs and secure software development initiatives.
  • Experience with AI-assisted development and code-analysis tools such as GitHub Copilot.

Tools and frameworks

  • Checkmarx One, SAST, SCA, OWASP Top 10, Common Weakness Enumerations (CWE)
  • NIST, ISO, PCI DSS
  • AI-generated recommendations (used in adjudication context)

Skills you’ll use

  • Financial Management, Influence, Stakeholder Management
  • Solution Delivery Process, Technical Strategy Development, Agile Practices
  • Analytical Thinking, Collaboration, Result Orientation
  • Risk Management, Business Acumen, Business Case Analysis, Data Management
  • Solution Design, Vendor Management

Similar Jobs