This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Tier4 is looking for a Security Consultant who will be responsible for ensuring the security of the company’s infrastructure, networks, data and applications. Application Security manager will ensure that applications and services of an organization are secured and implemented with best security practices following the organization’s governance model.
Job Responsibility
Implement Data Security Management and Operation models
Establish various security compliance standards including (but not limited to) NIST(National Institute of Standards and Technology), FIPS(Federal Information Processing Standards), FedRAMP(Federal Risk and Authorization Management Program)
Engage with agency Privacy and Security office teams to exchange Compliance reports and obtain approvals as necessary
Involve with auditors as necessary to provide compliance reports as requested and implement mitigation steps as required
Implement process and tools for application vulnerability testing(SAST/DAST)
Establish and manage a vulnerability management including coordination of penetration testing and ongoing vulnerability remediation, tracking, and security compliance reporting
Setup requirements for penetration testing and engage with vendors and agencies to perform/report pen tests
Setup infrastructure audits and reports with the help of system admins and vendors as necessary
Maintaining the system integrity and security by following the industry standard IT Controls
Implement automation of systems administration and software migration for QA and Production
Develop relationships with QA and application teams to establish quality and application compliance based on Organization standards
Provide architecture and configuration recommendations to ensure hosted/deployed environments are security and best practices compliant
Provide technical assistance/recommendations to agency users and other agency personnel
Evaluate security and audit tools and support them as necessary
Identify and successfully troubleshoot problems in all environments and work across teams to ensure problems get resolved in a timely manner
Available for off-hour incidents and provide 24×7 on-call production support on a rotation basis
Provide training to teams on security and compliance as necessary
Work towards continuous process improvements
Requirements
10+ years of IT experience with at least 5+ years as a Security Manager/officer
Bachelor's degree in Information Technology or computer science or related field or equivalent experience
In-depth knowledge and experience working with common regulatory framework applications related to data security, including HIPAA, HITRUST, – General Data Protection Regulation (GDPR), National Institute of Standards & Technology (NIST) standards, and similar constructs are highly desired
Previous knowledge and experience in designing and architecting information technology and security controls across complex and diverse networks, applications, and infrastructures are strongly preferred
Technical aptitude, critical thinking skills, and the ability to think outside the box
Demonstrated ability to solve complex information security problems, observe security risks and weaknesses, and provide security recommendations to the respective project and delivery teams
Ability to translate technical risk issues to business leaders and upper management
Excellent verbal, written, and interpersonal communication skills
Detail-oriented and value teamwork
Ability to resolve problems as they arise and handle situations expediently
Must be able to work a flexible schedule according to business needs, including evenings, weekends, and holidays