Software Security Specialist enabling developers to build secure software and mitigate vulnerabilities at PNC. Focus on coaching, mentoring, and providing security expertise to software development teams.
Responsibilities
Responsible for enabling developers to create more secure software through coaching and mentoring developers and provides subject matter expertise to Application Security programs
Works with developers to help them create more secure code
Manages projects and tasks related to developer
Sets secure coding standards and requirements with team
Coaches developers on language specific coding techniques to avoid or remediate coding flaws.
Requirements
Deep expertise guiding development teams in remediating common application vulnerabilities, including OWASP Top 10, API security, and secure design principles
Proven hands-on experience performing threat modeling to identify and mitigate risks in software
Practical experience building and implementing strong authentication solutions
A genuine passion for secure software development, with the ability to clearly articulate its importance
Strong analytical skills to identify gaps in the Software Development Lifecycle (SDLC) and recommend actionable improvements
Hands-on experience with secure design, security architecture, and implementing software security solutions
Ability to work both independently and collaboratively within cross-functional teams
Familiarity with Agile development methodologies (e.g., Scrum, Kanban)
Experience with SAST, DAST, RASP, and integrating security into CI/CD pipelines
Excellent communication and relationship-building skills
Hands-on experience with secure coding and secure by design practices
Knowledge of software security frameworks such as BSIMM or SAMM
Strong technical skills in application security, product security
Relevant certifications such as CSSLP, SANS GWAPT
Experience securing public cloud environments (e.g., AWS, Azure, GCP)
Background in software development
Familiarity with tools like SD Elements or similar platforms
Ability to define and track security metrics and reporting
Proven hands-on experience designing, building, and securing AI systems in production environments
Led or contributed to a Security Champions program to promote secure development practices and foster cross-functional security awareness.
Benefits
medical/prescription drug coverage (with a Health Savings Account feature)
dental and vision options
employee and spouse/child life insurance
short and long-term disability protection
401(k) with PNC match
pension and stock purchase plans
dependent care reimbursement account
back-up child/elder care
adoption, surrogacy, and doula reimbursement
educational assistance, including select programs fully paid
a robust wellness program with financial incentives
paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 8 occasional absence days each year; between 15 to 25 vacation days each year, depending on career level; and years of service.
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.
Principal Information Security Consultant at Westpac focusing on security protocols and employee benefits for staff. Hybrid role centrally located with opportunities for professional development and employee perks.
Engineer supporting secure development lifecycle processes for product lines in the energy sector. Collaborating with R&D on security requirements and compliance audits.
Automation Oversight Engineer providing oversight of compliance in automated device configurations for Comcast Business. Managing configuration checks and reporting, ensuring reliable oversight and improvement strategies.
Principal Systems Engineer - Cybersecurity role in protecting our nation's products as part of Integrated Platform Solutions team. Develop solutions utilizing RMF, Anti - Tamper, Software Assurance, and more.
Agent de Sécurité assurant la sécurité des usagers du réseau de transport TBM. Rattaché au Manager de Proximité Sûreté, garantissant la qualité de service public de transport en commun.