Manager Of Application Security
Current• Team Leadership: Leads and mentors a Senior Application Engineer and Application Engineer team, fostering a collaborative and security-focused work environment.• Security Testing: Conduct comprehensive manual and automated application security testing using tools such as OWASP ZAP, BurpSuite, and Veracode.• Code Review & Cloud Security: Perform detailed code reviews and cloud infrastructure assessments, ensuring adherence to security design standards and reducing potential risks by 25%.• Risk Assessment: Execute thorough risk assessments for applications and solutions, present clear and actionable risk mitigation strategies to business stakeholders, and enhance overall security posture.• Training & Development: Administer annual Secure Coding Training using Veracode Security Labs, improving the development team’s understanding of security best practices and reducing security incidents by 15%.• CI/CD Integration: Develop and implement Azure CI/CD pipeline YAML integrations, streamlining deployment processes and increasing deployment efficiency by 20%.• Vendor Security: Conduct security assessments of third-party vendors, ensuring they meet stringent security requirements and mitigate supply chain risks.