Senior Application Security Engineer III

INFORMATION SECURITY ENGINEER III

WHAT IS THE OPPORTUNITY?

The Application Security Engineer is responsible for addressing legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation.

As issues are uncovered, the Application Security Engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk.

This position is also responsible for assessing the security of internally developed, third party developed, commercial off the shelf (COTS), and open source software applications.

This includes performing architecture reviews to steer projects in the right direction early, participating in security code reviews, and performing penetration testing against products prior to shipping.

Technology and Innovation Division
As a member of City National’s Technology & Innovation group, you will drive, develop, and maintain solutions for clients and colleagues.

This is an exciting time of technology advancement and innovation across the bank, particularly within our technology teams.

WHAT WILL YOU DO?

  • Lead a range of application security assessment activities such as penetration testing and reviewing SAST and DAST reports
  • Create threat models and leverage them to prioritize resource allocation
  • Consult, advise or oversee the secure design and configuration requirements of key application projects to ensure compliance with bank and regulatory standards
  • Participate in strategic initiatives designed to identify and reduce the attack surface across applications and systems
  • Educate and train application teams on security topics and skills to build strong relationships within the development community
  • Collaborate with security groups such as red teams, threat intelligence and risk management to form a holistic team dedicated to thwarting attackers and reducing attack surface

WHAT DO YOU NEED TO SUCCEED

Must-Have*

  • Bachelor’s Degree business, computer science or equivalent
  • Minimum of 5 years’ experience in Information/Cyber Security field
  • Minimum of 5 years’ experience as an engineer or administrator of enterprise security technology platform

Skills and Knowledge

  • Experience performing black box, grey box, or white box security testing and communicating results to developers
  • A strong understanding of Web and API application security concepts and practices
  • BA/BS Degree or equivalent combination of training and experience
  • Experience with at least one of the following cloud providers: AZURE, AWS, or GCP
  • Strong written and verbal communication skills, as well as the ability to work well with a diverse mix of stakeholders

*To be considered for this position you must meet at least these basic qualifications
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification.

It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.

INCLUSION AND EQUAL OPPORTUNITY EMPLOYMENT
City National Bank is an equal opportunity employer committed to diversity and inclusion.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status or any other basis protected by law.

ABOUT CITY NATIONAL

We start with a basic premise: Business is personal.

Since day one we’ve always gone further than the competition to help our clients, colleagues and community flourish.

City National Bank was founded in 1954 by entrepreneurs for entrepreneurs and that legacy of integrity, community and unparalleled client relationships continues to drive phenomenal growth today.

City National is a subsidiary of Royal Bank of Canada, one of North America’s leading diversified financial services companies.

City National Bank requires all colleagues to be fully vaccinated against COVID-19 to work on-site at any of our locations.

Related Post