Senior Application Security Compliance Lead
Sumitomo Mitsui Banking Corporation2 hours ago
Charlotte, NC, USAStaff+
Responsibilities
- Partner with application development teams to review security findings and drive timely vulnerability remediation.
- Monitor and support SAST, SCA, DAST, IAST, and container security assessments.
- Review code across multiple programming languages and explain security risks, root causes, and remediation approaches.
- Collaborate with application security, security architecture, and development teams to improve secure software development and threat mitigation.
- Validate findings, track remediation progress, and ensure compliance with established SLAs.
- Create reports and presentations covering application security posture, trends, risks, and remediation progress.
- Perform targeted manual validation and testing of security findings, including vulnerability and penetration testing results.
- Contribute to process improvements, documentation, automation, and application security program maturity initiatives.
Requirements
- 5+ years of experience in application security, application penetration testing, or a related cybersecurity discipline.
- 5+ years of experience with SAST, DAST, or similar application security technologies.
- Strong knowledge of SSDLC principles, OWASP Top 10, CWE, and common application security threats and mitigations.
- Experience managing vulnerability remediation programs and engaging development teams to improve security outcomes.
- Ability to read, analyze, and explain code-level security issues and remediation approaches.
- Experience with one or more of C#, C++, Java, Python, or .NET technologies.
- Ability to develop remediation examples, automation scripts, and tooling for cybersecurity initiatives.
- Experience integrating security controls within CI/CD pipelines.
- Experience securing containerized environments and addressing container security risks.
- Experience using Jira and Confluence for project tracking, documentation, and collaboration.
- Strong attention to detail and ability to create and maintain clear process documentation.
- Preferred experience includes building or leading security champion programs, application security awareness and developer outreach, bug bounty participation, application penetration testing, and presenting security metrics to senior leadership.
Benefits
- Hybrid workforce model allowing employees to work from home and from an SMBC office.
- Employees must live within a reasonable commuting distance of their office location.
- Specific hybrid work schedules are discussed during the interview process.
- Reasonable accommodations are provided during candidacy for applicants with disabilities.