Lead Manager of Application Security Engineering at USAA focusing on application security throughout SDLC. Managing risks and compliance across information security domains.
Responsibilities
Lead Application Security Engineering (ASE) Team responsible for protecting and securing USAA applications.
Identify emerging risks, document, and build business cases to address them.
Develop, design, and implement security governance and assurance processes within security domains.
Responsible for implementing and managing enterprise information security policies and processes.
Plan and organize activities of professional and administrative staff providing information security/cyber security services.
Partner with lines-of-business, Enterprise Risk and Compliance, Audit Services, and Legal to support information security risk and compliance initiatives.
Promote information security awareness within teams and across Enterprise Security Group.
Build and oversee a team through recruiting, development, retention, coaching, performance management, and managerial activities.
Requirements
Bachelor’s degree in Information Security, Information Technology, Computer Science, Business Administration, Information Systems/Management or related field; OR 4 years of related experience may be substituted in lieu of degree.
6 years of related information security experience in one or more domains, e.g.: Cybersecurity, Identity and Access Management, Information Assurance and Governance, Operational Risk Management and/or Information Technology.
2 years of direct team lead, supervisory, or management experience in an Information Security or Information Technology domain.
2 years of researching, designing, or implementing technology, information security or cybersecurity solutions in a large financial institution or large enterprise information security program.
Working knowledge of relevant regulations and standards related to risk management and information security.
Strong written and verbal communication skills, including the ability to communicate technical analyses to a non-technical audience.
Strong knowledge of security technologies to include cryptography, authentication, authorization, and controls.
Strong knowledge of IT risks and experience implementing security solutions.
Knowledge of threats, vulnerabilities, attack methods and countermeasures for web-based applications, networks, and cyber security solutions.
Expertise in risk management processes and principles.
Familiarity with budgets, forecasting, and executing on the budgets for the applicable information security, cybersecurity, or technology support function.
Benefits
comprehensive medical, dental and vision plans
401(k)
pension
life insurance
parental benefits
adoption assistance
paid time off program with paid holidays plus 16 paid volunteer hours
Regional Security Manager responsible for security operations at EMEA Data Centers. Collaborating with cross - functional teams for compliance and incident management.
Chargé.e d’Etudes et Travaux en systèmes électromécaniques de sécurité at RATP Infrastructures. Responsible for ensuring technical compliance and supervising project activities on - site.
Senior Infrastructure Security Engineer handling cloud security and infrastructure lifecycle for Zocks, a fintech startup. Responsible for security initiatives and compliance readiness in a rapidly growing team.
Data Center Security Officer ensuring safety and security for data center clients through patrols and monitoring. Conducting reports and maintaining client security requirements.
Cybersecurity Specialist overseeing the protection of clients' technology systems and networks. Implementing cybersecurity policies and conducting evaluations against cyber threats in a supportive working environment.
Senior Cybersecurity Incident Responder at ZEISS handling technical incident response activities. Collaborating with cyber defense teams to ensure effective incident management and resolution.
Information Security Manager responsible for steering InfoSec programs globally at ZEISS. Leading cross - functional initiatives and risk management strategies in a high - tech environment.
Providing security incident management for industrial environments at Telefónica Tech. Utilizing various monitoring platforms to enhance security posture.
Endpoint Security Engineer at Booz Allen designing and operationalizing data protection controls. Safeguarding sensitive data across enterprise systems and leading technical operations.