Sr. Information Security Consultant (AppSec Enablement and Insights)
Job Description
Senior Application Security Consultant responsible for strengthening application security across the development lifecycle, coordinating remediation, and integrating security into CI/CD with DevOps. This role is onsite in Charlotte, NC, with hub locations in Atlanta, Charlotte, or Raleigh and requires five days per week.
Responsibilities
- Perform control testing and validate controls across application security domains.
- Analyze vulnerabilities and coordinate remediation for applications.
- Advise application teams on remediation efforts and drive vulnerability burndown as needed.
- Assist with remediation support, vulnerability analysis, and metrics across AppSec domains.
- Produce program metrics including burndown, aging, trend, and adoption.
- Contribute to development and refinement of application security standards, procedures, and intake workflows.
- Collaborate with DevOps teams to embed security into CI/CD pipelines.
- Stay current with emerging application security threats, vulnerabilities, and technologies.
Requirements
- Bachelor's degree in Computer Science, Information Systems, or related field.
- Minimum of 7 years of professional information security experience.
- Advanced knowledge of data security, privacy laws, regulatory compliance, and advanced security technologies.
- Experience in threat analysis, vulnerability testing, incident response, and forensic methodologies.
TECHNOLOGIES
- ServiceNow Vulnerability Response
TECHNICAL SKILLS
- Strong understanding of application security and scanning disciplines, including SAST, SCA, secrets, API, container, and IaC.
- Ability to interpret vulnerability data, including severity, CVSS, exploitability, and false positives.
- Experience with control testing, control validation, and evidence collection.
- Programming or scripting proficiency.
- Experience with vulnerability management platforms, including ServiceNow Vulnerability Response.
- Understanding of secure SDLC, CI/CD, and DevSecOps.
- Strong communication, analytical, technical writing, and documentation skills.
PREFERRED QUALIFICATIONS
- Security certifications such as CISSP, CISM, GIAC, or equivalent.
- Familiarity with vulnerability management tools, including ServiceNow Vulnerability Response.
- Familiarity with cloud and container security tools.
BENEFITS
- Medical
- Dental
- Vision
- Life insurance
- Disability
- Accidental death and dismemberment
- Tax-preferred savings accounts
- 401k plan
- Vacation days (min 10 days per year, prorated)
- Sick days (min 10 days, prorated)
- Paid holidays
- Defined benefit pension plan
- Restricted stock units
- Deferred compensation plan
WORK DETAILS
- Employment type: Regular
- Work shift: 1st shift (United States of America)
- Location: Charlotte, NC (onsite); hub locations in Atlanta, GA or Raleigh, NC; five days per week onsite
- Language: English required