drjobs Senior Security Maven (Remote)

Senior Security Maven (Remote)

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

The Senior Security Maven reports to Experian Health Product Security. You will work in a team of technologists that focus on the security aspects of our application portfolio. The Product Security team (aka Security Mavens) are responsible for the security of Experians Healths products including security by design vulnerability remediation and driving special security related programs.

  • Lead client incident readiness and escalation response and take an ownership in managing the security response for incidents
  • Lead client incident retrospectives and RCAs by collaborating with engineering operations and security teams to identify systemic breakdowns during client or internal incidents
  • Improve adoption of secure development practices and embed secure-by-design thinking in the SDLC
  • Accelerate threat modeling secure code reviews and initiative-taking security testing tailored to the teams architecture
  • Escalate organizational misalignments and champion resolutions
  • Safeguard client data and promote and oversee adherence to data protection standards
  • Provide risk-based practical security guidance that aligns with enterprise policies and balances delivery needs
  • Coordinate technical investigations interface with client-facing teams and help summarize messaging that is transparent and accurate
  • Be a Trusted Security Advisor and serve as the primary security contact for assigned application portfolios and product teams
  • Partner with application owners to ensure sensitive client data is stored transmitted and processed in accordance with regulatory and contractual obligations
  • Ensure resulting insights from all incidents leads to improvements in controls data flows and team processes
  • Operationalize corporate security Projects and translate central security programssuch as vulnerability management bug bounty operations access management and compliance requirementsinto clear implementation plans
  • Improve communication and agreement by anticipating the downstream impact of security programs and brief department leaders product teams and client partners
  • Mentor and multiply impacts by serving as a senior representative and role model for the Security Mavens program
  • Mentor junior Mavens and help establish a culture of continuous improvement knowledge-sharing and security ownership

Qualifications :

  • Experience directly supporting senior level partners
  • Certifications such as CISSP CSSLP CIPP/US CISM CISA or GCSA (or equivalent experience)
  • 7 years of experience supporting third-party client audits privacy assessments or compliance efforts (HIPAA SOC2 FedRAMP HITRUST)
  • 7 years of experience with frameworks like OWASP MITRE and DevSecOps toolchains


Additional Information :

Benefits/Perks:

Employment Type

Remote

Company Industry

Department / Functional Area

Product Development

Key Skills

  • Security Management
  • Sensitive Information Management
  • Pressure Management
  • Risk Analysis
  • Access Control
  • Safety Procedures
  • Security Measures
  • Security Training
  • Risk Assessment
  • Access Point
  • Security Checks
  • Detect Signs
  • Safe Environment
  • Security System
  • Security Reports

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.