Overview
On Site
Compensation information provided in the description
Full Time
Skills
Microsoft Excel
Security QA
Testing
Penetration Testing
Threat Analysis
Science
IT Infrastructure Management
IT Infrastructure
Software Architecture
Data Architecture
Middleware
IT Operations
Project Management
Continuous Integration
Continuous Delivery
DevOps
Incident Management
Regulatory Compliance
Technology Integration
Emerging Technologies
Software Security
Fortify
Synopsys
INSPECT
SCA
Mobile Security
Master Data Management
Mobile Device Management
Vulnerability Management
Risk Management
Software Licensing
Evaluation
IT Audit
Asset Management
Change Control
Training Delivery
Technical Writing
Documentation
Information Security
IT Architecture
Auditing
Network
Internet Security
Information Assurance
Java
Groovy
Python
API
SQL
Database
ISS
Recruiting
Boost
Finance
Health Care
Life Insurance
Law
Internet
Immigration
LOS
Insurance
OFAC
SAFE
Policies and Procedures
Job Details
At U.S. Bank, we're on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at-all from Day One.
Job Description
U.S Bank is seeking an Application Security Engineer that specializes in Vulnerability Management. This Application Security Engineer will implement, and support solutions/technologies used for Static code analysis (SCA), Dynamic & Static security testing (DAST SAST), Interactive application security testing (IAST) & Pen testing. The engineer will be leading initiatives to improve application security posture by implementing policies, execute vulnerability management program and evangelizing practices that shift security left.
Top 3 Skills:
Experience with SAST, SCA, and DAST toolset
Experience with Vulnerability Management and Threat Assessment
Development/Automation experience with Java, Python, API & Database Technology
Preferred Qualifications:
Typically Bachelor's degree in engineering or science, or equivalent work experience
Typically three to five years of experience in information security
Typically two or more years of experience in IT infrastructure management, application architecture, risk management, data architecture, middleware technology, and IT operations and project management
Job Duties:
Preferred Skills and Experience:
This role offers a hybrid/flexible schedule, which means there's an in-office expectation of 3 or more days per week and the flexibility to work outside the office location for the other days.
#ISS
If there's anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants.
Benefits:
Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following (some may vary based on role, location or hours):
U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.
E-Verify
U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program.
The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $98,175.00 - $115,500.00 - $127,050.00
U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.
Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.
Posting may be closed earlier due to high volume of applicants.
Job Description
U.S Bank is seeking an Application Security Engineer that specializes in Vulnerability Management. This Application Security Engineer will implement, and support solutions/technologies used for Static code analysis (SCA), Dynamic & Static security testing (DAST SAST), Interactive application security testing (IAST) & Pen testing. The engineer will be leading initiatives to improve application security posture by implementing policies, execute vulnerability management program and evangelizing practices that shift security left.
Top 3 Skills:
Experience with SAST, SCA, and DAST toolset
Experience with Vulnerability Management and Threat Assessment
Development/Automation experience with Java, Python, API & Database Technology
Preferred Qualifications:
Typically Bachelor's degree in engineering or science, or equivalent work experience
Typically three to five years of experience in information security
Typically two or more years of experience in IT infrastructure management, application architecture, risk management, data architecture, middleware technology, and IT operations and project management
Job Duties:
- Perform the daily operation and execution of security-related tools, processes and controls related to cyber defense initiatives.
- Works with development teams to onboard projects to SAST, OSA, DAST & IAST tools. Collaborates with pipeline/CI-CD/DevOps team
- Help coordinate and drive remediation of identified risks and control deficiencies.
- Look for ways to optimize security processes and recommend opportunities and solutions for improvement and automation.
- Serve as technical and function subject matter expert across multiple security domain areas, raising awareness and communicating security risks within the company.
- Support and participate in incident response and technical investigations as needed.
- Ensures adherence to compliance regulations and policies.
Preferred Skills and Experience:
- Extensive knowledge of IT environment including service-oriented and IT architecture, industry trends and direction, system and technology integration, and IT standards, procedures and policies, and emerging technologies
- Hands on experience with Application security toolsets like Fortify, Checkmarx, Synopsis, Fossa, Web Inspect other tools in the space of SAST, SCA, IAST & DAST
- Knowledge on application, API & mobile security with tools such as data theorem, MTD & MDM is desirable.
- Demonstrable experience running vulnerability management and risk management programs across organization and evangelizing best development practices.
- Extensive knowledge of software licensing, product and vendor evaluation, technical troubleshooting, and software processing improvement
- Working knowledge of IT audit and control, governance, asset management, change control, training delivery, and technical writing/documentation.
- Extensive knowledge of information security technologies and administration
- Working knowledge of IT architecture, audits, network and internet security, information assurance, and computer crime.
- Development/Automation experience with Java, Groovy, Python, API & SQL Database Technology
This role offers a hybrid/flexible schedule, which means there's an in-office expectation of 3 or more days per week and the flexibility to work outside the office location for the other days.
#ISS
If there's anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants.
Benefits:
Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following (some may vary based on role, location or hours):
- Healthcare (medical, dental, vision)
- Basic term and optional term life insurance
- Short-term and long-term disability
- Pregnancy disability and parental leave
- 401(k) and employer-funded retirement plan
- Paid vacation (from two to five weeks depending on salary grade and tenure)
- Up to 11 paid holiday opportunities
- Adoption assistance
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.
E-Verify
U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program.
The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $98,175.00 - $115,500.00 - $127,050.00
U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.
Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.
Posting may be closed earlier due to high volume of applicants.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.