Application Security Specialist

hace 1 mes


Monterrey, Nuevo León, México CHUBB A tiempo completo
Job Title: Application Security Specialist

Chubb is seeking an experienced Application Security Specialist to join our Information Security team. The successful candidate will be responsible for identifying and mitigating security vulnerabilities in our global application portfolio.

Key Responsibilities:

  • Manage the overall vulnerability remediation status of the global application portfolio.
  • Primary point of contact with IT application development teams for remediation related matters.
  • Accurately track vulnerability remediation efforts.
  • Hold regular status calls with portfolio leads as necessary to maintain a consistent channel of communication.
  • Follow up on overdue vulnerabilities with portfolio leads.
  • Manage global application risk rating processes.
  • Ensure timely risk scoring of new and changing applications.
  • Ensure enterprise application repository information is up to date with security and risk information.
  • Create and distribute regular vulnerability status reports to portfolio leads and CIOs.
  • Provide recommendations for automation or other process improvement suggestions for operational processes.

Requirements:

  • Prior experience with managing Information Security projects.
  • Bachelor's degree in computer science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience.
  • Minimum of 2 years' professional experience performing web application pen testing, API endpoint testing and, mobile penetration testing (IOS & Android).
  • Knowledge with prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets.
  • Knowledge of industry standards regarding vulnerability management including Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring System (CVSS).
  • Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening and security baselines, web server and database security.
  • Knowledge of penetration testing principles, tools, and techniques.
  • Working experience with industry frameworks (OWASP, NIST, etc.).
  • Comfortable working outside their comfort zone with a willingness to learn.
  • Excellent verbal and written communication skills.
  • Strong analytical skills.
  • Strong team player with ability to work independently.
  • Strong project management skills and ability to multi-task.
  • Self-motivated with strong initiative.
  • Knowledge of computer networking concepts and protocols, and application security methodologies.
  • Skill in performing impact/risk assessments.

Preferred Qualifications:

  • Good understanding of secure SDLC, data protection, information security principles and exploit/attack techniques.
  • Familiar with all basic concepts related to networking, applications, operating system functionality and be able to apply application logic manipulation, bypassing security controls and exploit development.
  • Assist with scoping engagements, leading from kickoff through remediation, and track vulnerabilities as per timelines.
  • Improve operational efficiency by building and evaluating workflow processes, procedures, checklists, automation, and tooling.
  • Security testing tools including Kali Linux, Metasploit, Nmap, Burp Suite, OWASP ZAP Proxy, Santoku, MSF, GenyMotion, Appie, APK tool, JD-GUI, SQL Map, etc.
  • Skilled in identifying OWASP TOP 10 (Web & Mobile) vulnerabilities.
  • Develop secure coding checklist to applications based on OWASP ASVS (Application Security Verification Standards).
  • Lead and execute security assessments to identify business risk, likelihood and impact an attacker may have on the system due to bad coding errors and weak or missing security controls.
  • Experience with conducting reverse engineering on mobile applications, identifying hard coded passwords, SQLi and key chain distributions including applications with anti-emulator and obfuscation protections.
  • Experience conducting full-scope assessments and penetration tests including - social engineering, reverse engineering, server & client-side attacks and web & mobile application exploitation.
  • Identify and prioritize key risk areas balancing the business risk and cyber threats.
  • Code analysis for control flow, bypass application logics and security flaws.
  • Utilize attacker tools, tactics, and procedures used to perform analysis and identify vulnerabilities.
  • Validate security weaknesses, research new attack techniques, develop custom scripts, exploits, tools, and methodologies to enhance penetration testing processes etc.
  • Identify and demonstrate vulnerabilities that may be used by an adversary to exploit components of the target systems.
  • Analyze security findings, including risk analysis and root cause analysis.
  • Risk rate the vulnerabilities based on actual impact to the business.
  • Ability to document security weaknesses, including steps to reproduce and explain technical details in a concise, understandable manner.
  • Develop comprehensive and accurate security penetration reports.
  • Research and formulate practical short and long term remediations for vulnerabilities.
  • Effectively communicate findings and strategy to business stakeholders, including technical and executive leadership.
  • Work closely with development teams to ensure closing of remediated vulnerabilities until deployed to production.
  • Ability to maintain and develop dashboards to track the status of security vulnerabilities.
  • Follow up on the overdue vulnerabilities to meet the compliance requirements.
  • Good to have security certifications: GIAC Web Application Penetration Tester (GWAPT), GIAC Penetration Tester (GPEN), Licensed Penetration Tester (LPT), Certified Ethical Hacker (CEH), OSCP or OCWE, etc.
  • Active team player with interpersonal, collaborative, and consultative skills.
  • Strong, clear, and concise verbal and written communication skills.
  • Ability to adapt, reprioritize project work, and help drive the team's focus as priorities shift or requirements change.


  • Monterrey, Nuevo León, México CHUBB A tiempo completo

    Job Title: Application Security SpecialistChubb is seeking an experienced Application Security Specialist to join our Information Security team. The successful candidate will be responsible for identifying and mitigating security vulnerabilities in our global application portfolio.Key Responsibilities:Manage the overall vulnerability remediation status of...


  • Monterrey, Nuevo León, México Azka IT Consulting A tiempo completo

    Azka IT Consulting is a Mexican company that connects IT talent with Latin American and United States companies.We are seeking an Endpoint Security Specialist to join our team.Responsibilities:As an Endpoint Security Specialist, you will be responsible for:Managing Endpoint Security Products: Agents, Endpoint Security Platform, Firewall, Threat Prevention,...


  • Monterrey, Nuevo León, México Epicor A tiempo completo

    Job SummaryAs an Application Support Specialist at Epicor, you will play a vital role in providing exceptional customer support and technical expertise to clients through remote testing, troubleshooting, and training.


  • Monterrey, Nuevo León, México Azka IT Consulting A tiempo completo

    Azka IT Consulting is seeking a skilled Endpoint Security Specialist to join our team.The ideal candidate will have experience managing endpoint security products, including agents, firewalls, and threat prevention systems.Responsibilities will include:Managing endpoint security products in production and pre-production environmentsHandling security...


  • Monterrey, Nuevo León, México Trane Technologies A tiempo completo

    At Trane Technologies, we strive to create innovative climate solutions for a sustainable world. Our team is dedicated to challenging the status quo and uplifting others to thrive at work and at home. We're looking for a Security Operations Specialist to join our team and help us safeguard the well-being of our employees.**Job Summary:**The Security...


  • Monterrey, Nuevo León, México Azka It Consulting A tiempo completo

    Azka It Consulting is a Mexican company that connects top IT talent with Latin American and United States companies.We are seeking a skilled Cyber Security Specialist to join our team.Key Responsibilities:Identify and mitigate IT security threats, enforce security standards, and provide support in incident management.Requirements:University degree in...


  • Monterrey, Nuevo León, México CHUBB A tiempo completo

    About ChubbChubb is a global company that operates in various regions, including Asia Pacific, North America, Latin America, Japan, and Europe. Our Information Security team protects our information systems against unauthorized access, detects attempts to gain access, and responds to security incidents.


  • Monterrey, Nuevo León, México Redwood Logistics LLC A tiempo completo

    Job Title: Cash Application SpecialistAt Redwood Logistics LLC, we are seeking a highly skilled Cash Application Specialist to join our team. As a key member of our Accounts Receivable team, you will be responsible for maintaining accurate data related to deposits and active accounts receivable.Key Responsibilities:Import and process customer payments across...


  • Monterrey, Nuevo León, México Nemak A tiempo completo

    About the RoleWe are seeking a highly skilled Information Security Specialist to join our team at Nemak. In this role, you will play a pivotal part in safeguarding sensitive information, managing access controls, and implementing measures to adhere to regulatory requirements.


  • Monterrey, Nuevo León, México Scranton, PA A tiempo completo

    Job Title: Information Security SpecialistThis role is responsible for ensuring the security and integrity of University systems and networks. The ideal candidate will have a strong background in information security technologies, including auditing tools, antivirus software, and firewalls.Key Responsibilities:Research and implement information security...


  • Monterrey, Nuevo León, México Danfoss A tiempo completo

    About DanfossAt Danfoss, we are dedicated to engineering solutions that allow the world to use resources in smarter ways. Our mission is to drive the sustainable transformation of tomorrow by developing innovative technologies that enable efficient energy use and reduce emissions.We believe that innovation and great results are driven by a diverse team of...


  • Monterrey, Nuevo León, México Jabil Circuit A tiempo completo

    At Jabil, we strive to push the boundaries of what's possible and deliver exceptional results. Our commitment to excellence has earned us a reputation as a trusted partner for top brands worldwide.About this RoleWe are seeking a skilled Security Systems Specialist to join our team. As a CCTV Monitoring Expert, you will be responsible for ensuring the...

  • IT Security Specialist

    hace 4 días


    Monterrey, Nuevo León, México Sydsa A tiempo completo

    At Sydsa, we are looking for a bilingual IT Security Specialist to work with our team.We offer a competitive salary plus benefits:A competitive monthly salary ranging from $50,000.00 to $56,000.00.DIRECT HIRING (not Outsourcings, agencies or per projects).Salary Basis (no mixed schemes, or honorariums).Predictable payments every two weeks.Law Benefits (6...


  • Monterrey, Nuevo León, México Nearshore Cyber A tiempo completo

    **Job Summary:**Nearshore Cyber seeks a skilled Security Threat Detection Specialist to join our team. The ideal candidate will have 2-5 years of experience in information security, with expertise in threat detection and response, incident management, and security analytics.**Key Responsibilities:**• Monitor and respond to security threats on a 24x7 basis,...


  • Monterrey, Nuevo León, México Nearshore Cyber A tiempo completo

    Job Summary:Nearshore Cyber is seeking a skilled Cyber Security Awareness Specialist to join our team. In this role, you will be responsible for developing and implementing effective security awareness initiatives to protect our enterprise.About the Role:The ideal candidate will have 2-3 years of experience in information security, IT, marketing,...

  • SAP Security Specialist

    hace 3 semanas


    Monterrey, Nuevo León, México Norsk Hydro A tiempo completo

    About the RoleThe SAP Security Specialist will be responsible for the authorization support of SAP business applications.Key ResponsibilitiesDesign, implementation, and administration of roles in our SAP environmentAnalysis and resolving problems related to access and user administration in SAPAlignment with all relevant project stakeholdersParticipation in...


  • Monterrey, Nuevo León, México Essentra A tiempo completo

    Essentra is seeking a skilled Cash Application Specialist to process cash and credit card transactions accurately and efficiently.Key Responsibilities:• Process charges and refunds in a timely and accurate manner• Post cash in accordance with internal controls and accounting policies• Create credit card files in Excel using functions such as VLOOKUP•...


  • Monterrey, Nuevo León, México Azka It Consulting A tiempo completo

    **About Azka It Consulting**We are a Mexican company that connects the best IT talent with Latin American and United States companies.We are seeking a highly skilled Network Security Operations Specialist to join our team.Key Responsibilities:Provide top-level support for our internal clientsStay up-to-date with changes in user and system software and...


  • Monterrey, Nuevo León, México Jabil Circuit A tiempo completo

    At Jabil, we strive to make anything possible and everything better. Our comprehensive engineering, manufacturing, and supply chain solutions empower us to deliver scalable and customized solutions globally. As a trusted partner for top brands, we foster sustainable processes that minimize environmental impact and create vibrant communities worldwide.**ROLE...


  • Monterrey, Nuevo León, México Jabil Circuit A tiempo completo

    At Jabil, we strive to push the boundaries of innovation and excellence. With over 50 years of experience across various industries and a vast network of over 100 sites worldwide, our commitment extends beyond business success as we aim to build sustainable processes that minimize environmental impact and foster vibrant and diverse communities globally.Job...