Job Description - Application Security Manager

Title PrimaryJob Responsibilities

Job Requirements

Manager,ApplicationSecurity PayPalistheleading,securewaytopayandbepaid.PayPal customerstrustthattheirtransactionsandprivateinformationare securebecauseofthehighstandardsofsecurityenforcedforPayPal technology.Theapplicationsecurityprogramisdesignedtoensure thatanysoftwaredevelopedoracquiredmeetsthesestringent standardswhileenablingrapidinnovationtomeetcustomers'ever- changingneeds. Themanageroftheapplicationsecurityprogramwillberesponsible for:

1. Integratingsecuritytools,standards,andprocessesintothe productlifecycle(PLC).

2. EnsuringthatdevelopersandQApersonnelaretrainedwith theappropriatelevelofsecurityknowledgetoperformtheir dailyactivities.

3. Improvingandsupportingapplicationsecuritytool deploymentsincludingstaticanalysisandruntimetesting tools.

4. Improvingandmaintainingsecuredevelopmentstandards. 5. Supportingtheincidentresponseandarchitecturereview

processeswheneverapplicationsecurityexpertiseisneeded. 6. Managingannualpenetrationtestingservices,includingboth

expertconsultingandmanagedservices. 7. Providingmanualpenetrationtestingandstandardsgap

analysisservicestointernalbusinessandtechnologypartners. 8. Managingapplicationframeworkandperimetersecurity

improvementprojects. 9. SupportingVendorSecurityactivitiestoensure3rd-party

softwareanddevelopmentmeetsPayPalsecuritystandards. 10. Integratingthreatmodelingpracticesintotheproductlife

cycle. 11. Providingsecurityrequirementsfortest-drivendesign. 12. Producingmetricsreportingthestateofapplicationsecurity

programsandperformanceofdevelopmentteamsagainst requirements. Successfulcandidateswillbesecurityevangelistswhocantranslate securityconceptsintolanguagethatismeaningfultomany

Education

audiences,includingbusinessandtechnicalleadersandindividual contributors.Candidatesmustbeabletoapproachapplication securityfromtheperspectiveofriskmanagementandavoidpurely academicthinkingaboutsoftwaresecurity.Demonstrableabilityto influencedecision-makingprocessesatalllevelsofalarge organizationwillbecriticaltosuccess. Candidatesmusthavestrongleadershipskillsandbeeffective managersofhighlytechnicalindividuals. Candidatesmusthaveexcellentverbalandwrittencommunication skills,includingexperiencespeakinginpublicforumsand writing/contributingtotechnicalpublications. Candidatesshouldbefamiliarwithwaterfallandagiledevelopment processesandhaveexperienceintegratingsecuredevelopment practicesintobothmodels. Theidealcandidatehasexperiencewritingandtestingweb applicationsandwebservicesinthefollowingprogramming languages:C/C++,Java,andJavaScript.Thecandidateshouldhave familiaritywithavarietyofdevelopmentandtestingtools,including: Eclipse,GIT,GCC,JIRA,Subversion,Maven,ClearQuest/Case,Silk, FindBugs,HP/FortifySCA,IBMAppScan,andHPWebInspect Candidatesmustbeabletoexplainallvulnerabilitiesandweaknesses intheOWASPTop10,WASCTCv2,andCWE25toanyaudience,and discusseffectivedefensivetechniques. Candidatesmusthaveexperiencemanaging$1M+budgetsand planningmulti-yearroadmaps. FamiliaritywithindustrystandardsandregulationsincludingPCI, FFIEC,SOX,andISO27001isdesired. BachelorsdegreeorhigherinComputerSciencepreferred

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download