PowerPlan is looking for every opportunity to help our customers and prospects gain more value from our suite of software solutions. We are seeking a Senior Security Analyst / AppSec Specialist to join our Information Security & Compliance team. This is a hands-on high-impact role responsible for strengthening our application security posture driving vulnerability management maturity and supporting security operations across our cloud-hosted SaaS environment. The successful candidate will serve as a technical security practitioner embedded within our engineering and operations ecosystem partnering closely with DevOps product and compliance teams.
To be successful in this role you should have extensive experience with CrowdStrike Falcon including its Next-Gen SIEM Data Protection CSPM and Threat Intelligence capabilities as well as experience coordinating penetration tests and running vulnerability assessments with Qualys. You should have hands-on experience with Rapid7 CI/CD pipeline hardening cloud security in AWS and/or Azure and security architecture. Experience implementing process improvements and driving program maturity aligned with NIST CSF 2.0 is essential. You should also have excellent communication problem-solving and analytical skills as well as the ability to work independently and as part of a team.
COMPANY
PowerPlan specializes in enterprise software solutions used by organizations with complex financial regulatory and operational needs. We deliver secure cloudhosted SaaS products that help customers manage critical workflows with accuracy transparency and compliance.
The security team plays a central role in protecting customer trust enabling rapid product innovation and ensuring alignment with frameworks such as SOC 2 ISO 27001 and NIST CSF 2.0. We operate in a collaborative environment that values technical depth continuous improvement and responsible innovation.
KEY PERFORMANCE OBJECTIVES (First 12 Months)
OBJECTIVE 1: Implement a Centralized Application Vulnerability Management Platform (First 120 Days)
Outcome:
Deploy a consolidated platform (e.g. DefectDojo) that aggregates SAST DAST SCA penetrationtesting and manualreview findings within 120 days. Ensure all engineering teams have visibility into normalized prioritized findings with assignment and SLA workflows in place. Produce monthly reports showing coverage SLA adherence and remediation progress.
Impact:
Provides a single pane of glass that enables consistent prioritization eliminates fragmented tooling silos and measurably reduces MTTR for application vulnerabilities. Improves audit readiness and strengthens engineering alignment by creating a unified source of truth for risk decisions.
How:
Evaluate and implement the platform integrate scanning tools and pentest reports configure crossteam workflows onboard engineering groups define remediation SLAs and publish monthly dashboards to engineering and security leadership.
OBJECTIVE 2: Lead the Annual Application Cloud Penetration Testing Program (Annual Cycle)
Outcome:
Coordinate annual penetration testing for web applications APIs and cloud environments; ensure final reports are processed within 30 days. Track remediation and retesting and ensure all critical/highrisk findings are addressed within SLA. Maintain auditready documentation for compliance teams.
Impact:
Ensures independent validation of application and cloud security posture reduces exploitable weaknesses and directly supports SOC 2 and ISO 27001 evidence requirements. Builds leadership confidence through measurable remediation accountability.
How:
Manage vendor selection and scoping coordinate technical access and test data review findings facilitate engineering remediation validate fixes capture evidence and update Confluence with all required artifacts and timelines.
OBJECTIVE 3: Implement a Standardized Security Architecture Review Process (First 120 Days)
Outcome:
Establish and operationalize a designreview process for all major new product features and thirdparty integrations within 120 days. Produce documented review artifacts identified risks and required remediation actions for development teams. Ensure findings are incorporated before release.
Impact:
Reduces latecycle rework prevents designlevel security gaps and embeds security as a natural part of the product development lifecycle. Improves release confidence and accelerates secure deployment across the SaaS platform.
How:
Create templates facilitate threatmodel discussions (e.g. STRIDE) review integration risks track remediation items collaborate with engineering leads and maintain documented review outcomes in shared repositories.
OBJECTIVE 4: Drive Measurable Maturity Improvements Aligned to NIST CSF 2.0 (First 12 Months)
Outcome:
Deliver measurable improvements across NIST CSF functions through documented workflows baseline control assessments performance metrics and quarterly KPI reporting. Create repeatable processes and auditready artifacts across Identify Protect Detect Respond and Recover.
Impact:
Strengthens the formal structure and reliability of the security program reduces operational and compliance risk and enhances readiness for SOC 2 and ISO 27001 by demonstrating consistent evidencebased maturity growth.
How:
Assess current control gaps standardize repeatable workflows document runbooks and procedures collaborate with engineering and compliance automate where practical and present quarterly maturity dashboards.
OBJECTIVE 5: Strengthen CrossFunctional Collaboration Across Dev CloudOps IT & Compliance (First 69 Months)
Outcome:
Implement recurring crossteam security syncs remediation checkpoints and shared KPI dashboards. Drive measurable improvements in SLA adherence cloud misconfiguration reduction recurringvulnerability prevention and overall operational alignment.
Impact:
Builds unified organizationwide ownership of security responsibilities accelerates remediation cycles and reduces risk introduced by siloed decisions or inconsistent practices.
How:
Establish communication cadences run joint review sessions align remediation expectations publish shared dashboards and deliver clear visibility to leadership on crossteam security performance.
WHAT YOU BRING
PowerPlan is an EOE
Required Experience:
Senior IC
PowerPlan is an enterprise software company devoted to helping asset-centric businesses the utilities, oil and gas, transportation, telecommunications, and mining industries optimize their financial performance. PowerPlan combines purpose-built software for asset centric accounting, ... View more