Sr Manager - Platform Security Scanning ( 578328-1A )
When you join Verizon
Verizon is a leading provider of technology, communications, information and entertainment products, transforming the way we connect across the globe. We’re a diverse network of people driven by our ambition and united in our shared purpose to shape a better future. Here, we have the ability to learn and grow at the speed of technology, and the space to create within every role. Together, we are moving the world forward – and you can too. Dream it. Build it. Do it here.
What you’ll be doing...
The Verizon Corporate Information Security (CIS) organization securely enables the business by protecting assets and information across Verizon networks, infrastructure and applications. CIS integrates cybersecurity governance, policies, technologies and operations across Verizon, and works to incorporate security into the design of technology systems and services.
The Platform Security team within Verizon’s Corporate Information Security (CIS) organization works to embed security seamlessly into the development and operations lifecycle of technology systems and services. We are looking for an experienced Senior Manager to lead the Security Scanning Center of Excellence across multiple delivery teams.
- Lead and grow a team of high performing individuals who partner across multiple teams to define, implement and improve Secure-SDLC standards, policies & processes.
- Drive adoption of Secure-SDLC policies and best practices by Security Mavens and Product teams, through training, certification, and automation.
- Lead security architecture and design, and build CoE for security reference architectures, frameworks and tools.
- Maintain roadmaps, service operational commitments and metrics across the delivery teams.
- Define cloud operating model, cloud security services and service metrics.
- Define and continually update security requirements to align with emerging architectures, technologies, regulatory and threat landscape.
- Define security standards (architecture, design, coding, cryptographic solutions, third-party components) for adoption by product development teams across the organization.
- Conduct Secure-SDLC activities including threat modeling to identify security vulnerabilities, determine risk and identify mitigations.
- Develop and improve metrics that drive desired behavior and security outcomes.
- Maintain a team culture of collaboration, openness and approachability while educating on security policies, and facilitating progress with product teams.
What we’re looking for...
You’ll need to have:
- This hybrid role will have a defined work location that includes work from home and assigned office days as set by the manager.
- Bachelor’s degree or four or more years of work experience.
- Six or more years of relevant work experience.
- Experience in Information Security and Full-stack Application Development,
- Experience managing teams of engineers and program managers.
Even better if you have one or more of the following:
- Application Security experience in production environments.
- Application architecture and development experience.
- A degree in Computer Science, Information Technology, Software Engineering, Information Security etc.
- Security certifications: CISSP, CISM, CRISC, GSEC or willingness to obtain within 12 months of hire.
- Experience implementing Agile methodologies and integrating security tools into CI/CD.
- Experience with various application security tools including SAST, SCA, DAST, IAST, RASP, Penetration testing, Fuzzing etc.
- Experience building secure software based on frameworks such as OWASP, CWE, SANS, OpenSAMM, BSIMM.
- Experience with methodologies and tools, for threat analysis of complex systems, such as threat modeling and software fuzzing.
- Experience leading application security vulnerability remediation and mitigation activities.
- Experience with common web application attack vectors and related mitigation strategies.
- Domain knowledge of common information security management frameworks and regulatory requirements and applicable standards such as ISO 27001, SOC 2, HIPAA, GDPR, PCI, Sarbanes-Oxley, etc.
- Ability to deal with ambiguity, make meaningful decisions and demonstrate concrete progress even with incomplete information.
- Experience coding in Java, Python, or Go, and at least one scripting language.
- Knowledge of web, mobile, API, Microservices, network and security architectures and design patterns.
- Knowledge of AWS, Azure, GCP and OCI native security tools.
- Knowledge of security best practices, principles, and common security frameworks, such as NIST, ISO, Common Criteria, TCSEC, OWASP, etc.
- Experience with data architecture, modeling and integration.
- Knowledge of current and emerging security technologies, threats and techniques for exploiting security vulnerabilities.
- Knowledge of developer tools and environments, project management and bug tracking systems.
- Ability to secure container-centric deployments using Docker & Kubernetes.
- Experience with process improvement, automation release management, and system development life cycles.
- Experience with Data security and Governance.
- Experience implementing quantitative risk methodologies.
Equal Employment Opportunity
We're proud to be an equal opportunity employer - and celebrate our employees' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status. At Verizon, we know that diversity makes us stronger. We are committed to a collaborative, inclusive environment that encourages authenticity and fosters a sense of belonging. We strive for everyone to feel valued, connected, and empowered to reach their potential and contribute their best. Check out our diversity and inclusion page to learn more.