symplr logo
symplr
Posted 79 days agoVerified live 1d ago

Product Security Manager

Brief overview

Remote
UndergradOr in progress
$120k–$140k/yrStated range
4+ yrsMinimum
AWSAzureOWASP web application security vulnerabilitiesCross-site scriptingCross-site request forgerySQL injectionDenial of Service attacksXML/SOAPAPI attacksThreat modelingMicrosoft Threat Modeling toolBurpsuiteGitHub Advanced SecurityQualysTenableNIST standardsHIPAA compliance

About the company

Symplr is a provider of healthcare governance, risk, and compliance solutions and services.

Job description

Summary

Symplr is a company focused on information security, and they are seeking a Product Security Manager. In this role, you will support security initiatives for commercial software products, collaborating with cross-functional teams to protect products and users from emerging security threats throughout the development lifecycle.

Responsibilities

  • Define and enforce security requirements for software products, features, and components. Ensure security considerations are included in the product roadmap and development plans
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle including controls assessments, threat modeling, privacy impact assessments, SAST, DAST, and third-party application penetration testing
  • Identify, assess, and prioritize product security risks
  • Collaborate with cross-functional teams to perform vulnerability management of identified risks and implement strategies for mitigating identified risks
  • Work cross-functionally to ensure that security tooling is embedded in the product CI/CD pipelines to adopt shift left security
  • Collaborate with the product, engineering, and other stakeholders to lead WAF deployments and adoption initiatives as it relates to commercial product
  • Track and report on product security performance, including effectiveness of security measures, incidents, and ongoing security improvements
  • Participate in incident response activities as they relate to application security

Skills

  • University degree in Information Security, Computer Science, Computer Engineering, Information Technology (or equivalent of education and work experience)
  • Minimum of 4-5 years of relevant corporate information security industry experience
  • One or more of the following certifications: CISSP, CSSLP, CISM, CCSP
  • Knowledge of cybersecurity frameworks and relevant regulatory requirements
  • Proven technical experience in Threat Modeling, Risk Assessment, and Security Lifecycle Management
  • Technical understanding of systems, applications, and databases
  • Technical expertise in cloud infrastructure and services platforms (AWS and Azure preferred)
  • Excellent communication skills at all organizational levels
  • Strong project management and time management skills
  • High level of personal integrity and ability to professionally handle confidential matters
  • Capable of acting calmly and managing incidents under high pressure and stress
  • Capable of multitasking in a fast paced, multifaceted environment
  • Ability to work well with customers, peers, and management
  • Proficient with the Microsoft Office Suite, Visio, and SharePoint
  • Technical proficiency with software engineering methodologies such as peer reviews and continuous integration
  • Technical experience in OWASP web application and web services security vulnerabilities including cross-site scripting, cross-site request forgery, SQL injection, DoS attacks, XML/SOAP, and API attacks
  • Experience with technical threat assessments and threat modeling of software applications and hardware devices using tools such as Microsoft Threat Modeling tool
  • Experience with technical vulnerability discovery using tools such as Burpsuite, GitHub Advanced Security, Qualys, and Tenable
  • Experience with industry standards and compliance standards such as NIST, HIPAA, and OWASP
  • Experience with penetration testing tools and methodologies
  • Experience with vulnerability management
  • Experience with scripting languages such as PowerShell, Python, or Perl
  • Solid understanding of web applications, web servers, application firewalls, and protocols with respect to web application development, deployment, and operation
  • Knowledge of web technologies and concepts
  • Understanding of AWS and Azure cloud technologies
  • Understanding of Web Application Firewalls including Barracuda, AWS, and Cloudflare
  • Understanding of TCP/IP, web protocols and networking concepts
  • Understanding of PKI Technology
  • Understanding of incident response processes
  • Bachelor's degree in Information Security, Computer Science, Computer Engineering, Information Technology (or equivalent of education and work experience)
  • 5-7 years of relevant corporate information security industry experience
  • AWS Cloud Security and/or Microsoft Azure Security certifications are a plus
  • Familiarity with DevOps toolchain (e.g. Terraform, Jenkins)
  • Familiarity with cloud security, including but not limited to CSPM, CASB, DLP, IAM, and vulnerability management
  • Familiarity with technical skills in enterprise security and networking protocols
  • Demonstrated experience and knowledge of relevant regulatory and security framework requirements, such as The U.S. Health Insurance Portability and Accountability Act (HIPAA) and NIST 800 and ISO/IEC 27001/27002
  • Previous working experience in healthcare technology environments

Qualifications

Must Haves

  • University degree in Information Security, Computer Science, Computer Engineering, Information Technology (or equivalent of education and work experience)
  • Minimum of 4-5 years of relevant corporate information security industry experience
  • One or more of the following certifications: CISSP, CSSLP, CISM, CCSP
  • Knowledge of cybersecurity frameworks and relevant regulatory requirements
  • Proven technical experience in Threat Modeling, Risk Assessment, and Security Lifecycle Management
  • Technical understanding of systems, applications, and databases
  • Technical expertise in cloud infrastructure and services platforms (AWS and Azure preferred)
  • Excellent communication skills at all organizational levels
  • Strong project management and time management skills
  • High level of personal integrity and ability to professionally handle confidential matters
  • Capable of acting calmly and managing incidents under high pressure and stress
  • Capable of multitasking in a fast paced, multifaceted environment
  • Ability to work well with customers, peers, and management
  • Proficient with the Microsoft Office Suite, Visio, and SharePoint
  • Technical proficiency with software engineering methodologies such as peer reviews and continuous integration
  • Technical experience in OWASP web application and web services security vulnerabilities including cross-site scripting, cross-site request forgery, SQL injection, DoS attacks, XML/SOAP, and API attacks
  • Experience with technical threat assessments and threat modeling of software applications and hardware devices using tools such as Microsoft Threat Modeling tool
  • Experience with technical vulnerability discovery using tools such as Burpsuite, GitHub Advanced Security, Qualys, and Tenable
  • Experience with industry standards and compliance standards such as NIST, HIPAA, and OWASP
  • Experience with penetration testing tools and methodologies
  • Experience with vulnerability management
  • Experience with scripting languages such as PowerShell, Python, or Perl
  • Solid understanding of web applications, web servers, application firewalls, and protocols with respect to web application development, deployment, and operation
  • Knowledge of web technologies and concepts
  • Understanding of AWS and Azure cloud technologies
  • Understanding of Web Application Firewalls including Barracuda, AWS, and Cloudflare
  • Understanding of TCP/IP, web protocols and networking concepts
  • Understanding of PKI Technology
  • Understanding of incident response processes

Nice to Haves

  • Bachelor's degree in Information Security, Computer Science, Computer Engineering, Information Technology (or equivalent of education and work experience)
  • 5-7 years of relevant corporate information security industry experience
  • AWS Cloud Security and/or Microsoft Azure Security certifications are a plus
  • Familiarity with DevOps toolchain (e.g. Terraform, Jenkins)
  • Familiarity with cloud security, including but not limited to CSPM, CASB, DLP, IAM, and vulnerability management
  • Familiarity with technical skills in enterprise security and networking protocols
  • Demonstrated experience and knowledge of relevant regulatory and security framework requirements, such as The U.S. Health Insurance Portability and Accountability Act (HIPAA) and NIST 800 and ISO/IEC 27001/27002
  • Previous working experience in healthcare technology environments

More jobs like this