Oklahoma City, OK, USA
13 days ago
Application Security Analyst III

The Application Security Analyst III position exists to protect the security posture of the Paycom application through tasks such as advanced web application penetration testing, code review, tool use, and other as-needed security reviews. Additional tasks include work to develop or improve existing projects that contribute to application security, and user education.

RESPONSIBILITIES

Perform and lead advanced web penetration test assessments and manual code review. Work closely with Software Development Delivery teams, Product Owners and Development Project Managers to identify module-specific risks through threat modeling and provide mitigation recommendations to meet business and security requirements. Provide guidance and train members of the software development teams on security best practices and encourage a culture of security awareness. Participate in threat modeling processes and document module risks and potential mitigation techniques. Contribute to the development of in-house security solutions, utilized for security testing and to meet compliance/regulatory requirements, as needed. Work with the DevOps team on the integration of security tools into the DevOps lifecycle. Research 3rd party tools, software libraries, APIs, and other incoming technology for security viability and document any concerns prior to application integration. Interface with other departments to gain insight into new technology and initiatives as needed. Train and guide other Application Security Analysts on threat modeling, advanced penetration testing, and development processes within Application Security. Analyze complex or recurring issues within the application and work with the software development teams on remediation. Act as a SME on assigned modules, advanced vulnerabilities, and automation technologies. Attend trainings, pursue certifications, and research vulnerabilities, remediations, and new technology to learn and stay up to date on security best practices. Contribute to the creation, maintenance, and improvement of documentation around security, policies, standards, guides, and procedures where applicable.
Confirm your E-mail: Send Email