Application Security Manager

Job Info

May 16, 2024


Posting Expiration Date: Jun 15, 2024

Schedule Type: Full-Time

Minimum Salary: $105000

Maximum Salary: $145000

Organization: IT Engineering & Operations

Department: Information Security

Section: IT ENG Cyber Security Ops

Location: NY-New York-4 Irving Pl Headquarters

Job Description

Mission Statement

  • Consolidated Edison Company of New York, Inc. (Con Edison), Orange & Rockland Utilities (O&R), and Consolidated Edison Transmission (CET) employees are required to follow health, safety, and environmental policies, EEO, Standards of Business Conduct, and all other applicable company policy and procedures. We all share a responsibility to advance the company’s mission by excelling at our three corporate priorities – safety of our people and the public, operational excellence in all that we do, and ensuring the best possible customer experience.

Core Responsibilities

  • Lead vulnerability management response efforts and events
  • Continuously build and implement improvements to application security workflows and processes, including vulnerability scanning, assessment, prioritization, and tracking/remediation
  • Develop new and update existing application vulnerability management policies, procedures, runbooks, and other documentation
  • Configure and run vulnerability scans of applications using industry-standard tools
  • Coordinate with application teams on scanning and application security practices, providing governance, oversight, and technical expertise
  • Remain up to date on cybersecurity news and emerging vulnerabilities
  • Assess and prioritize vulnerabilities for impact and cyber risk
  • Communicate vulnerability statuses and associated risk to stakeholders and leadership
  • Coordinate with stakeholders to remediate vulnerabilities timely, providing technical expertise and support as needed
  • Ensure proper escalation and communication of critical vulnerabilities or other issues to leadership in a timely fashion
  • Keep abreast of current developments in application security and vulnerability management and propose recommendations to mitigate risk
  • Perform validation that vulnerabilities have been remediated/mitigated, working with other teams as required
  • Collect, analyze, create dashboards, and report on vulnerability metrics
  • Continuously learn, improve, and hone your skills to deliver advanced assessments
  • Present to executive-level stakeholders
  • Conduct presentations and education efforts on application security/vulnerability management and best practices
  • Serve as a technical SME for more junior members of the vulnerability management team

Required Education/Experience

  • Master's Degree and 2 years of IT experience or
  • Bachelor's Degree and 3 years of IT experience or
  • Associate's Degree and 5 years of IT experience or
  • High School Diploma/GED and 7 years of IT experience

Preferred Education/Experience

  • Bachelor's Degree Computer Science, Cybersecurity, or similar field and 3 years of IT experience

Relevant Work Experience

  • Previous IT or cybersecurity experience
  • Required
  • Knowledge of cybersecurity tools
  • Required
  • Understanding of industry standard policies, processes, and procedures covering incident, problem, and change management
  • Required
  • Understanding of OWASP Top 10
  • Required
  • Familiarity with secure coding practices
  • Required
  • Software development experience
  • Preferred
  • Previous experience in application scanning and vulnerability management, including configuring and using DAST and CAST scanning technologies and performing vulnerability risk assessments/prioritization
  • Preferred
  • Ability to remain agile and work in a fast-paced environment Preferred
  • Knowledge of data/business intelligence tools is preferred (e.g., PowerBI, etc.) Preferred
  • Ability to communicate technical concepts to non-technical audiences Preferred

Skills & Ability

  • Strong verbal communication and listening skills
  • Effective interpersonal skills
  • Well organized, detail oriented and flexible to handle multiple assignments
  • Demonstrated analytical skills
  • Ability to simultaneously handle multiple priorities
  • Must be proficient in Microsoft Office including Word, Excel, Outlook and PowerPoint, etc.

Licenses & Certifications

  • Accredited Asset Management Specialist (AAMS)

Other Physical Demands

  • Must be able to respond to Company emergencies by performing a System Emergency Assignment to restore service to our customers.

Technical Difficulty Statement

Equal Opportunity Employer

  • Consolidated Edison Company of New York, Inc. (Con Edison), Orange & Rockland Utilities (O&R), and Consolidated Edison Transmission (CET) are equal opportunity employers. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of the individual’s actual or perceived disability, protected veteran status, race, color, creed, religion, sex, age, national origin, gender, gender identity, gender expression, genetic information, marital status, sexual orientation, citizenship, domestic violence victim status, or any other actual or perceived status protected by law.