Application Security Assurance Lead, Vice President
Sumitomo Mitsui Banking Corporation1 day ago
Charlotte, NC, USAStaff+
Responsibilities
- Partner with software engineering teams to identify, prioritize, and remediate application security vulnerabilities before production release.
- Review and explain security findings from code scans, including root causes and remediation options.
- Ensure applications are assessed through SAST, SCA, DAST, IAST, and container security scanning.
- Collaborate on secure design reviews, threat modeling, and application security improvements.
- Validate vulnerability findings and remediation against established service level agreements.
- Develop reporting on application security risk, remediation progress, and program effectiveness for leadership.
- Perform targeted manual validation and support application security testing.
- Improve secure development processes, security champion programs, and developer education initiatives.
Requirements
- 7+ years of experience in application security, application penetration testing, or a related cybersecurity discipline.
- Experience leading vulnerability remediation efforts and working directly with software engineering teams.
- Ability to analyze source code vulnerabilities and explain secure coding approaches.
- Experience maintaining secure software delivery processes within CI/CD environments and strong understanding of the SSDLC.
- Knowledge of common application security threats, attack techniques, and mitigation strategies.
- Experience creating process documentation, security standards, and operational procedures.
- Experience using Jira and Confluence.
- Software development experience with one or more of C#, C++, Java, Python, or .NET technologies.
- Ability to develop proof-of-concept fixes, remediation guidance, or automation scripts for cybersecurity operations.
- At least 5 years of application security testing experience, including SAST and/or DAST.
- Strong knowledge of OWASP Top 10, CWE, and secure coding practices.
- At least 2 years of experience securing containerized applications and working with container technologies.
- Preferred qualifications include security champion or developer outreach experience, application penetration testing, bug bounty participation, application security metrics and executive reporting, and automation experience.
Benefits
- Hybrid workforce model offering work from home and SMBC office work, with employees required to live within a reasonable commuting distance.
- Specific hybrid schedule provided during the interview process; some roles may require full-week in-office attendance.
- Reasonable accommodations are available during candidacy for applicants with disabilities.
About Sumitomo Mitsui Banking Corporation
Sumitomo Mitsui Banking Corporation provides corporate, investment, and commercial banking services—such as lending, capital markets, global trade finance, treasury/FX, and transaction banking—to corporate, institutional, and consumer clients. Headquartered in Tokyo, it is the core banking subsidiary of Sumitomo Mitsui Financial Group (SMFG), one of Japan’s three major banking groups, whose shares trade in Tokyo and as NYSE ADRs (SMFG). SMBC serves clients through a network spanning nearly 40 countries.