EBMUD Job Title: Senior Information Technology Engineer, IT Security (IT/OT Firewall Administration) Salary Info: $157,488 - $191,424 Annually, Plus Excellent Benefits + Retirement Opens online at on Monday, July 27, 2026 Online applications must be received by 4:30 p.m., Friday, August 14, 2026 The East Bay Municipal Utility District's (EBMUD) Information Systems Department is currently seeking a Senior Information Technology Engineer with deep experience administering firewalls in mission-critical, highly available enterprise environments. The role focuses on securing both internal and perimeter networks, supporting business continuity and strengthening cyber resilience across business networks (IT) and operational technology networks (OT) and the implementation and oversight of cybersecurity policies, standards, and best practices. Applicants must reside within commuting distance of EBMUD's Oakland, CA Administration building. This is a hybrid position which requires office presence in accordance with EBMUD's telecommuting guidelines (minimum 2-day per week physical office presence currently required but is subject to change). Telecommuting policies are subject to change. EBMUD will not provide relocation assistance. We are seeking candidates with advanced IT/OT security experience and skills. Experience is desired in three or more of the following disciplines: At least five years of hands-on experience administering firewalls in enterprise-scale, high-availability production environments, including policy management, troubleshooting, and rule lifecycle maintenance. Experience with enterprise-grade firewalls: e.g. Palo Alto Networks, Cisco, FortiNet, Checkpoint. Expertise in troubleshooting network issues. Solid understanding of TCP/IP protocols. Experience configuring, supporting and managing routing- BGP, OSPF, EIGRP, static. Experience with analyzing firewall logs and packet captures. Experience managing virtual firewalls in AWS, Azure and/or GCP. Understanding of IAAS concepts. Experience implementing and supporting ssl-inspection in a production environment. Experience managing VPN's: IPSEC site to site and end user remote access. Experience working with firewall policies, implementing changes, testing changes, submitting changes through change control processes. Experience with automating firewall rule analysis or change workflows using scripts or APIs is a plus. And the ability to: Create and maintain network diagrams and documentation for new and existing firewall deployments- depicting logical and physical environments. Communicate complex topics to non-technical users. Ability and willingness to share knowledge and information with others. Create documentation detailing implementation steps, tracking changes. Work across teams to investigate and respond to incidents. Lead or participate in IT/OT security projects by creating project plans and technical requirements. Track and report on incident handling and response metrics. Participate in annual tabletop cyber incident response exercises. Establish and maintain positive working relationships; teamwork attitude. Balance project deliverables among day-to-day operational demands. Perform independent research and share knowledge effectively. Maintain calm and focus during emergency operations. Work in a hybrid work environment. The most competitive candidates for the Senior IT Security Engineer position will possess strong working knowledge of firewall administration in a highly available production environment; networking experience; threat intelligence; experience in critical infrastructure-including ICS/OT firewall management; and project management principles and practices and cybersecurity best practices. Your experience will include demonstrated success working in many of the following areas: Experience managing firewall changes including: NAT, routing, VPN, access policies, troubleshooting, deployment, upgrades. Experience reviewing, analyzing and responding to firewall alerts: security and operational. Ability to perform and analyze network captures utilizing wireshark. Experience working within a ticketing system to track requests, changes, approvals Experience participating in Blue/Red team exercises. Log and systems analysis, troubleshooting, documentation techniques and procedures. Change control concepts and procedures supporting a production environment. Knowledge of network based attack methods and defense: DDOS, C2, data exfiltration, brute-force attacks, OWASP, etc. Familiarity with Industrial Control Systems (ICS) and Operational Technology (OT) environments is a plus. Project management. The salary range is $13,124 per month increasing to $13,780, $14,469, $15,192, and $15,952 after 6, 18, 30, and 42 months, respectively. EBMUD is an Equal Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, religious creed, sex, gender, gender identity, gender expression, marital or registered domestic partnership status, age for individuals over forty years of age, national origin, ancestry, disability (mental or physical, including AIDS and HIV), medical condition (cancer and genetic characteristics), genetic information, sexual orientation, military and veterans status, family or medical leave status, pregnancy, pregnancy disability leave status, or any other status protected by federal, state and/or local laws. Requirements: 1. A bachelor's degree; and 2. Two years of experience in information technology engineering, one year of which was at a level comparable to or higher than the EBMUD class of Information Technology (IT) Engineer II. 3. Willingness to participate in a rotating on-call schedule to support 24/7 network security operations, including incident response and critical issue resolution. 4. Overtime will be required on an as needed basis. Working environment is indoors and may require sitting for prolonged periods of time and repetitive hand motions. Additional years of experience (beyond the minimum requirement) may be substituted for the education on a year for year basis, only if the experience is at the level of the job for which the applicant is applying. (i.e., Four additional years of experience, at the level of the Senior IT Engineer classification, will be considered equivalent to a bachelor's degree). A graduate level degree in a directly related field may be substituted for one year of experience. To be considered under the "equivalent combination of education and experience" provision, it is your responsibility to include in your application materials written evidence of employment performed at the level of the typical duties of this position and/or coursework in subject areas directly related to this position. For more information, see our FAQ page at Submit a completed EBMUD application and the required supplemental questions responses online at by 4:30 p.m., Friday, August 14, 2026. Only application materials submitted online during the filing period will be accepted. EBMUD is an Equal Opportunity Employer: Females/Minorities/Veterans/Disability Job Hotline:
08/08/2026
Full time
EBMUD Job Title: Senior Information Technology Engineer, IT Security (IT/OT Firewall Administration) Salary Info: $157,488 - $191,424 Annually, Plus Excellent Benefits + Retirement Opens online at on Monday, July 27, 2026 Online applications must be received by 4:30 p.m., Friday, August 14, 2026 The East Bay Municipal Utility District's (EBMUD) Information Systems Department is currently seeking a Senior Information Technology Engineer with deep experience administering firewalls in mission-critical, highly available enterprise environments. The role focuses on securing both internal and perimeter networks, supporting business continuity and strengthening cyber resilience across business networks (IT) and operational technology networks (OT) and the implementation and oversight of cybersecurity policies, standards, and best practices. Applicants must reside within commuting distance of EBMUD's Oakland, CA Administration building. This is a hybrid position which requires office presence in accordance with EBMUD's telecommuting guidelines (minimum 2-day per week physical office presence currently required but is subject to change). Telecommuting policies are subject to change. EBMUD will not provide relocation assistance. We are seeking candidates with advanced IT/OT security experience and skills. Experience is desired in three or more of the following disciplines: At least five years of hands-on experience administering firewalls in enterprise-scale, high-availability production environments, including policy management, troubleshooting, and rule lifecycle maintenance. Experience with enterprise-grade firewalls: e.g. Palo Alto Networks, Cisco, FortiNet, Checkpoint. Expertise in troubleshooting network issues. Solid understanding of TCP/IP protocols. Experience configuring, supporting and managing routing- BGP, OSPF, EIGRP, static. Experience with analyzing firewall logs and packet captures. Experience managing virtual firewalls in AWS, Azure and/or GCP. Understanding of IAAS concepts. Experience implementing and supporting ssl-inspection in a production environment. Experience managing VPN's: IPSEC site to site and end user remote access. Experience working with firewall policies, implementing changes, testing changes, submitting changes through change control processes. Experience with automating firewall rule analysis or change workflows using scripts or APIs is a plus. And the ability to: Create and maintain network diagrams and documentation for new and existing firewall deployments- depicting logical and physical environments. Communicate complex topics to non-technical users. Ability and willingness to share knowledge and information with others. Create documentation detailing implementation steps, tracking changes. Work across teams to investigate and respond to incidents. Lead or participate in IT/OT security projects by creating project plans and technical requirements. Track and report on incident handling and response metrics. Participate in annual tabletop cyber incident response exercises. Establish and maintain positive working relationships; teamwork attitude. Balance project deliverables among day-to-day operational demands. Perform independent research and share knowledge effectively. Maintain calm and focus during emergency operations. Work in a hybrid work environment. The most competitive candidates for the Senior IT Security Engineer position will possess strong working knowledge of firewall administration in a highly available production environment; networking experience; threat intelligence; experience in critical infrastructure-including ICS/OT firewall management; and project management principles and practices and cybersecurity best practices. Your experience will include demonstrated success working in many of the following areas: Experience managing firewall changes including: NAT, routing, VPN, access policies, troubleshooting, deployment, upgrades. Experience reviewing, analyzing and responding to firewall alerts: security and operational. Ability to perform and analyze network captures utilizing wireshark. Experience working within a ticketing system to track requests, changes, approvals Experience participating in Blue/Red team exercises. Log and systems analysis, troubleshooting, documentation techniques and procedures. Change control concepts and procedures supporting a production environment. Knowledge of network based attack methods and defense: DDOS, C2, data exfiltration, brute-force attacks, OWASP, etc. Familiarity with Industrial Control Systems (ICS) and Operational Technology (OT) environments is a plus. Project management. The salary range is $13,124 per month increasing to $13,780, $14,469, $15,192, and $15,952 after 6, 18, 30, and 42 months, respectively. EBMUD is an Equal Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, religious creed, sex, gender, gender identity, gender expression, marital or registered domestic partnership status, age for individuals over forty years of age, national origin, ancestry, disability (mental or physical, including AIDS and HIV), medical condition (cancer and genetic characteristics), genetic information, sexual orientation, military and veterans status, family or medical leave status, pregnancy, pregnancy disability leave status, or any other status protected by federal, state and/or local laws. Requirements: 1. A bachelor's degree; and 2. Two years of experience in information technology engineering, one year of which was at a level comparable to or higher than the EBMUD class of Information Technology (IT) Engineer II. 3. Willingness to participate in a rotating on-call schedule to support 24/7 network security operations, including incident response and critical issue resolution. 4. Overtime will be required on an as needed basis. Working environment is indoors and may require sitting for prolonged periods of time and repetitive hand motions. Additional years of experience (beyond the minimum requirement) may be substituted for the education on a year for year basis, only if the experience is at the level of the job for which the applicant is applying. (i.e., Four additional years of experience, at the level of the Senior IT Engineer classification, will be considered equivalent to a bachelor's degree). A graduate level degree in a directly related field may be substituted for one year of experience. To be considered under the "equivalent combination of education and experience" provision, it is your responsibility to include in your application materials written evidence of employment performed at the level of the typical duties of this position and/or coursework in subject areas directly related to this position. For more information, see our FAQ page at Submit a completed EBMUD application and the required supplemental questions responses online at by 4:30 p.m., Friday, August 14, 2026. Only application materials submitted online during the filing period will be accepted. EBMUD is an Equal Opportunity Employer: Females/Minorities/Veterans/Disability Job Hotline:
Butcher Power Products (BPP) designs and manufactures mission critical and industrial power solutions for essential infrastructure nationwide. Headquartered in Sacramento, CA, our teams collaborate closely across engineering, manufacturing, and operations to build reliable, high quality systems and take pride in delivering work that truly matters. Job Summary: Butcher Power Products (BPP) is seeking a Senior Infrastructure & Security Engineer to join our growing Information Technology team. This is a unique opportunity for an experienced technology professional to help shape the future of IT operations within a rapidly evolving organization. BPP has recently completed a significant transformation to a modern Microsoft enterprise platform, including Microsoft 365 E5, Entra ID, Intune, Defender, Azure services, and a Cisco-based network infrastructure. The successful candidate will serve as the primary technical owner and subject matter expert for networking, infrastructure, cloud operations, identity security, and cybersecurity initiatives. Working alongside existing IT staff and strategic service providers, this individual will help establish internal ownership of critical technology platforms and reduce long-term reliance on managed service providers. This is a highly visible, hands-on engineering role that combines architecture, administration, operational support, security, project leadership, and technology strategy. Key Responsibilities: Infrastructure & Network Engineering: Own and administer Cisco Meraki networking environments, including switching, wireless, SD-WAN, VPN, and firewall services. Manage Cisco Umbrella, Duo MFA, and related network security technologies. Design, implement, and maintain network architecture standards. Manage network performance, availability, monitoring, and troubleshooting. Lead network expansion and modernization initiatives. Serve as primary escalation point for complex infrastructure issues. Maintain network diagrams, standards, and technical documentation. Security Engineering & Operations: Own operational administration of Microsoft Defender security solutions. Administer Microsoft Entra ID security controls, Conditional Access, and identity protection capabilities. Manage privileged access controls, RBAC, and security governance processes. Coordinate vulnerability management and remediation activities. Partner with eSentire and other security providers for incident response and threat management. Conduct risk assessments and security reviews. Lead implementation of security best practices aligned to Zero Trust principles. Develop and maintain cybersecurity policies, standards, and operational procedures. Microsoft Cloud & Identity Administration: Administer Microsoft 365, Entra ID, Intune, and Azure environments. Support cloud architecture and platform governance initiatives. Manage identity lifecycle processes and authentication services. Support compliance, device management, and endpoint security initiatives. Participate in future cloud modernization and automation projects. Evaluate and implement improvements to Microsoft security and infrastructure platforms. Technical Leadership & MSP Transition: Act as technical owner for infrastructure and security vendors. Develop plans to transition operational responsibilities from managed service providers to internal IT resources. Validate vendor recommendations and architectural decisions. Identify opportunities to improve service quality, operational efficiency, and cost effectiveness. Provide technical mentorship to engineers and support staff. Service Delivery & Support: Serve as Tier III escalation resource. Participate in troubleshooting complex user and infrastructure issues. Support major incidents and problem management activities. Contribute to continuous improvement of support processes and documentation. Utilize Jira Service Management and established ITIL-style processes. Qualifications: Required: 7+ years of experience in systems, infrastructure, networking, or cybersecurity roles. Experience administering Microsoft 365 environments. Experience with Microsoft Entra ID and identity security. Experience with Microsoft Defender security platforms. Strong networking fundamentals including routing, switching, VLANs, VPNs, wireless, and firewall technologies. Experience supporting Cisco or Meraki environments. Strong troubleshooting and analytical skills. Experience creating technical documentation and operational procedures. Ability to work independently and drive technical initiatives. Preferred: Experience transitioning services from MSP-supported environments to internal ownership. Experience with Cisco Meraki, Cisco Umbrella, and Duo. Experience with Microsoft Intune and endpoint management. Experience supporting Azure environments. Security Operations Center (SOC) collaboration experience. Manufacturing or multi-site environment experience. Certifications Preferred: CCNA Security+ SC-300 AZ-500 CISSP Meraki certifications Core Competencies: Technical Infrastructure & Networking Cybersecurity & Risk Management Microsoft Cloud & Endpoint Management Technical Leadership & Strategic Ownership Operational Excellence & Service Delivery CompensationThe base pay range for this role is $150,000 - $160,000 per year. Equal Opportunity Employer Butcher Power Products is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic. If you require a reasonable accommodation during the application or interview process, please let us know. Compensation ranges are provided in accordance with applicable state and local pay transparency laws. PI4bf-4263
08/07/2026
Full time
Butcher Power Products (BPP) designs and manufactures mission critical and industrial power solutions for essential infrastructure nationwide. Headquartered in Sacramento, CA, our teams collaborate closely across engineering, manufacturing, and operations to build reliable, high quality systems and take pride in delivering work that truly matters. Job Summary: Butcher Power Products (BPP) is seeking a Senior Infrastructure & Security Engineer to join our growing Information Technology team. This is a unique opportunity for an experienced technology professional to help shape the future of IT operations within a rapidly evolving organization. BPP has recently completed a significant transformation to a modern Microsoft enterprise platform, including Microsoft 365 E5, Entra ID, Intune, Defender, Azure services, and a Cisco-based network infrastructure. The successful candidate will serve as the primary technical owner and subject matter expert for networking, infrastructure, cloud operations, identity security, and cybersecurity initiatives. Working alongside existing IT staff and strategic service providers, this individual will help establish internal ownership of critical technology platforms and reduce long-term reliance on managed service providers. This is a highly visible, hands-on engineering role that combines architecture, administration, operational support, security, project leadership, and technology strategy. Key Responsibilities: Infrastructure & Network Engineering: Own and administer Cisco Meraki networking environments, including switching, wireless, SD-WAN, VPN, and firewall services. Manage Cisco Umbrella, Duo MFA, and related network security technologies. Design, implement, and maintain network architecture standards. Manage network performance, availability, monitoring, and troubleshooting. Lead network expansion and modernization initiatives. Serve as primary escalation point for complex infrastructure issues. Maintain network diagrams, standards, and technical documentation. Security Engineering & Operations: Own operational administration of Microsoft Defender security solutions. Administer Microsoft Entra ID security controls, Conditional Access, and identity protection capabilities. Manage privileged access controls, RBAC, and security governance processes. Coordinate vulnerability management and remediation activities. Partner with eSentire and other security providers for incident response and threat management. Conduct risk assessments and security reviews. Lead implementation of security best practices aligned to Zero Trust principles. Develop and maintain cybersecurity policies, standards, and operational procedures. Microsoft Cloud & Identity Administration: Administer Microsoft 365, Entra ID, Intune, and Azure environments. Support cloud architecture and platform governance initiatives. Manage identity lifecycle processes and authentication services. Support compliance, device management, and endpoint security initiatives. Participate in future cloud modernization and automation projects. Evaluate and implement improvements to Microsoft security and infrastructure platforms. Technical Leadership & MSP Transition: Act as technical owner for infrastructure and security vendors. Develop plans to transition operational responsibilities from managed service providers to internal IT resources. Validate vendor recommendations and architectural decisions. Identify opportunities to improve service quality, operational efficiency, and cost effectiveness. Provide technical mentorship to engineers and support staff. Service Delivery & Support: Serve as Tier III escalation resource. Participate in troubleshooting complex user and infrastructure issues. Support major incidents and problem management activities. Contribute to continuous improvement of support processes and documentation. Utilize Jira Service Management and established ITIL-style processes. Qualifications: Required: 7+ years of experience in systems, infrastructure, networking, or cybersecurity roles. Experience administering Microsoft 365 environments. Experience with Microsoft Entra ID and identity security. Experience with Microsoft Defender security platforms. Strong networking fundamentals including routing, switching, VLANs, VPNs, wireless, and firewall technologies. Experience supporting Cisco or Meraki environments. Strong troubleshooting and analytical skills. Experience creating technical documentation and operational procedures. Ability to work independently and drive technical initiatives. Preferred: Experience transitioning services from MSP-supported environments to internal ownership. Experience with Cisco Meraki, Cisco Umbrella, and Duo. Experience with Microsoft Intune and endpoint management. Experience supporting Azure environments. Security Operations Center (SOC) collaboration experience. Manufacturing or multi-site environment experience. Certifications Preferred: CCNA Security+ SC-300 AZ-500 CISSP Meraki certifications Core Competencies: Technical Infrastructure & Networking Cybersecurity & Risk Management Microsoft Cloud & Endpoint Management Technical Leadership & Strategic Ownership Operational Excellence & Service Delivery CompensationThe base pay range for this role is $150,000 - $160,000 per year. Equal Opportunity Employer Butcher Power Products is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic. If you require a reasonable accommodation during the application or interview process, please let us know. Compensation ranges are provided in accordance with applicable state and local pay transparency laws. PI4bf-4263
Tech Summary The IS Consultant IV, Application Security position is a senior hands-on technical role responsible for leading complex application security assessments and advancing secure software development practices across the organization. The consultant will conduct secure code reviews, static and dynamic application security testing, open source component analysis, API and mobile application security assessments, threat modeling, security architecture reviews, vulnerability validation, and remediation guidance. The ideal candidate has advanced software development and application security experience using Java, Python, JavaScript, .NET, Swift, or similar technologies. The candidate should have practical experience with application security testing solutions, penetration testing tools such as Burp Suite or OWASP ZAP, and integrating security controls into CI/CD pipelines. This role requires the ability to independently lead complex assessments, define secure development standards and guardrails, evaluate third party applications, and influence architecture and engineering decisions. The consultant will collaborate with developers, architects, product owners, vendors, security leaders, and executive stakeholders to communicate technical risk clearly and provide actionable remediation recommendations. Experience with cloud native applications, APIs, mobile applications, AI enabled applications, DevSecOps automation, and healthcare or other regulated environments is preferred. Job Summary: In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate. Essential Responsibilities: Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities. Practices self-development and promotes learning in others by proactively providing information, resources, advice, and expertise with coworkers and customers; building relationships with cross-functional stakeholders; influencing others through technical explanations and examples; adapting to competing demands and new responsibilities; listening and responding to, seeking, and addressing performance feedback; providing feedback to others and managers; creating and executing plans to capitalize on strengths and develop weaknesses; supporting team collaboration; and adapting to and learning from change, difficulties, and feedback. Effectively communicates investigative findings to non-technical audiences. Collaborates with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture. Provides recommendations to management and business stakeholders on how to remediate issues identified through security testing processes. Identifies the impact of security test plans on upstream and downstream solution components. Supports information sharing and integration procedures across cyber security through the exchange of threat intelligence and cyber security vulnerability assessment data. Contributes to cyber security intellectual capital by making process or procedure improvements, conducting brown bag training sessions, and creating new training documents. Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis. Recommends business line or business technology team security process improvements which align with sustainable best practices, and the strategic and tactical goals of the business. Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across multiple business domains. Performs complex security test data analysis in support of security vulnerability assessment processes, including root cause analysis. Serves as an escalation point on issues, dependencies, and risks related to security testing. Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately to highly complex technology initiatives across multiple IT domains by analyzing business and technology requirements. Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems. Provides insight and consultation on the development of testing scope and approach, and collaborates with cross-functional IT and business stakeholders to review the overall testing approach. Validates security test scenarios across various SDLC phases (e.g., development, reproduction, production) for low- to moderately-complex projects. Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams and management as appropriate. Minimum Qualifications: Minimum three (3) years software or application development experience. Minimum one (1) year experience in application security (e.g., source code analysis, dynamic analysis, etc.). Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum six (6) years experience in IT or a related field, including Minimum two (2) years in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement. Additional Requirements:
07/30/2026
Full time
Tech Summary The IS Consultant IV, Application Security position is a senior hands-on technical role responsible for leading complex application security assessments and advancing secure software development practices across the organization. The consultant will conduct secure code reviews, static and dynamic application security testing, open source component analysis, API and mobile application security assessments, threat modeling, security architecture reviews, vulnerability validation, and remediation guidance. The ideal candidate has advanced software development and application security experience using Java, Python, JavaScript, .NET, Swift, or similar technologies. The candidate should have practical experience with application security testing solutions, penetration testing tools such as Burp Suite or OWASP ZAP, and integrating security controls into CI/CD pipelines. This role requires the ability to independently lead complex assessments, define secure development standards and guardrails, evaluate third party applications, and influence architecture and engineering decisions. The consultant will collaborate with developers, architects, product owners, vendors, security leaders, and executive stakeholders to communicate technical risk clearly and provide actionable remediation recommendations. Experience with cloud native applications, APIs, mobile applications, AI enabled applications, DevSecOps automation, and healthcare or other regulated environments is preferred. Job Summary: In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate. Essential Responsibilities: Completes work assignments and supports business-specific projects by applying expertise in subject area; supporting the development of work plans to meet business priorities and deadlines; ensuring team follows all procedures and policies; coordinating and assigning resources to accomplish priorities and deadlines; collaborating cross-functionally to make effective business decisions; solving complex problems; escalating high priority issues or risks, as appropriate; and recognizing and capitalizing on improvement opportunities. Practices self-development and promotes learning in others by proactively providing information, resources, advice, and expertise with coworkers and customers; building relationships with cross-functional stakeholders; influencing others through technical explanations and examples; adapting to competing demands and new responsibilities; listening and responding to, seeking, and addressing performance feedback; providing feedback to others and managers; creating and executing plans to capitalize on strengths and develop weaknesses; supporting team collaboration; and adapting to and learning from change, difficulties, and feedback. Effectively communicates investigative findings to non-technical audiences. Collaborates with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture. Provides recommendations to management and business stakeholders on how to remediate issues identified through security testing processes. Identifies the impact of security test plans on upstream and downstream solution components. Supports information sharing and integration procedures across cyber security through the exchange of threat intelligence and cyber security vulnerability assessment data. Contributes to cyber security intellectual capital by making process or procedure improvements, conducting brown bag training sessions, and creating new training documents. Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis. Recommends business line or business technology team security process improvements which align with sustainable best practices, and the strategic and tactical goals of the business. Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across multiple business domains. Performs complex security test data analysis in support of security vulnerability assessment processes, including root cause analysis. Serves as an escalation point on issues, dependencies, and risks related to security testing. Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately to highly complex technology initiatives across multiple IT domains by analyzing business and technology requirements. Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems. Provides insight and consultation on the development of testing scope and approach, and collaborates with cross-functional IT and business stakeholders to review the overall testing approach. Validates security test scenarios across various SDLC phases (e.g., development, reproduction, production) for low- to moderately-complex projects. Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams and management as appropriate. Minimum Qualifications: Minimum three (3) years software or application development experience. Minimum one (1) year experience in application security (e.g., source code analysis, dynamic analysis, etc.). Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum six (6) years experience in IT or a related field, including Minimum two (2) years in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement. Additional Requirements:
Tech Summary: The IS Consultant III, Application Security position is a hands-on technical role responsible for supporting application security assessments and secure software development practices under the guidance of senior application security consultants. The role performs source code reviews, manual and automated security testing, vulnerability assessments, and security test data analysis for moderately complex technology initiatives. The consultant works with developers, DevOps teams, technology risk teams, and business stakeholders to integrate application security services, validate security findings, provide remediation guidance, and communicate risks to technical and nontechnical audiences. The role also supports continuous application assessment, security tool adoption, standardized security processes, metrics, reporting, and ongoing improvements across assigned business domains. Job Summary: In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities under the guidance of more senior application security consultants by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate. Essential Responsibilities: Completes work assignments by applying up-to-date knowledge in subject area to meet deadlines; following procedures and policies, and applying data and resources to support projects or initiatives; collaborating with others, often cross-functionally, to solve business problems; supporting the completion of priorities, deadlines, and expectations; communicating progress and information; identifying and recommending ways to address improvement opportunities when possible; and escalating issues or risks as appropriate. Pursues self-development and effective relationships with others by sharing resources, information, and knowledge with coworkers and customers; listening, responding to, and seeking performance feedback; acknowledging strengths and weaknesses; assessing and responding to the needs of others; and adapting to and learning from change, difficulties, and feedback. Effectively communicates investigative findings to non-technical audiences. Works with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture. Provides recommendations to team or department leadership on how to remediate issues identified through security testing processes. Identifies the impact of security test plans on upstream and downstream solution components. Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis. Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across assigned business domain(s). Performs security test data analysis in support of security vulnerability assessment processes, including root cause analysis. Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately complex technology initiatives across multiple IT domains by analyzing business and technology requirements. Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems. Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams as appropriate. Minimum Qualifications: Minimum two (2) years software or application development experience. Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum three (3) years experience in IT or a related field, including Minimum one (1) year in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement. Additional Requirements: N/A
07/30/2026
Full time
Tech Summary: The IS Consultant III, Application Security position is a hands-on technical role responsible for supporting application security assessments and secure software development practices under the guidance of senior application security consultants. The role performs source code reviews, manual and automated security testing, vulnerability assessments, and security test data analysis for moderately complex technology initiatives. The consultant works with developers, DevOps teams, technology risk teams, and business stakeholders to integrate application security services, validate security findings, provide remediation guidance, and communicate risks to technical and nontechnical audiences. The role also supports continuous application assessment, security tool adoption, standardized security processes, metrics, reporting, and ongoing improvements across assigned business domains. Job Summary: In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities under the guidance of more senior application security consultants by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate. Essential Responsibilities: Completes work assignments by applying up-to-date knowledge in subject area to meet deadlines; following procedures and policies, and applying data and resources to support projects or initiatives; collaborating with others, often cross-functionally, to solve business problems; supporting the completion of priorities, deadlines, and expectations; communicating progress and information; identifying and recommending ways to address improvement opportunities when possible; and escalating issues or risks as appropriate. Pursues self-development and effective relationships with others by sharing resources, information, and knowledge with coworkers and customers; listening, responding to, and seeking performance feedback; acknowledging strengths and weaknesses; assessing and responding to the needs of others; and adapting to and learning from change, difficulties, and feedback. Effectively communicates investigative findings to non-technical audiences. Works with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture. Provides recommendations to team or department leadership on how to remediate issues identified through security testing processes. Identifies the impact of security test plans on upstream and downstream solution components. Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis. Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across assigned business domain(s). Performs security test data analysis in support of security vulnerability assessment processes, including root cause analysis. Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately complex technology initiatives across multiple IT domains by analyzing business and technology requirements. Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems. Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams as appropriate. Minimum Qualifications: Minimum two (2) years software or application development experience. Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum three (3) years experience in IT or a related field, including Minimum one (1) year in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement. Additional Requirements: N/A