Senior Application Security Engineer
Current• Assist the Head of Global Application Security and CISO in developing an application security organization capable of scaling to the dimensions of the global 25K+ people company and handling applications involving high financial stakes and matching levels of technical innovation and business complexity, as well as the diverse dev culture resulting from SS&C’s M&A activity.• Emphasis on shifting security left, automation of security testing, security-as-code, laying down safety guardrails, and making threat modeling an integral part of the SSDLC. This includes implementing robust governance for generative AI, providing guardrails for secure and compliant use of LLM models. By managing risks like prompt injections, PII exposure, and hallucinations, we ensure every AI interaction is secure and aligned with business needs.• Ensure the SSDLC follows the global information security and privacy policies and strategies, initiates necessary compliance programs and changes in the global SSDLC realm.• Research threats and attack vectors that may impact SS&C’s web, enterprise, and mobile applications and infrastructure. Stay up-to-date with current offensive and defensive tactics, techniques, and procedures.• Advice engineering teams with the configuration, tuning, and operation of SAST and DAST tools, and their integration into the development process.• Validate and interpret SAST, DAST, bug bounty program, and penetration test findings, demonstrate identified vulnerabilities, assess risks, evaluate possible fixes, and verify successful remediation.• Create and deliver training for engineering team members on secure code development and other security literacy topics.• Develop and collect metrics to measure the success of the application security program.