Remote Jobs RockRemote Jobs Rock

Vulnerability Management & Application Security Liaison SPOC

๐Ÿ“… Jul 8
LinuxWindows ServerOpenshift Container PlatformCheckmarx

๐Ÿ“œ Description

  • Analyze infrastructure-adjacent flaws in Linux and Windows operating systems.
  • Oversee containerized security within OpenShift Container Platform (OCP).
  • Collaborate on managing vulnerabilities related to databases and middleware components.
  • Cross-reference application flaws with host-level and container-level vulnerabilities.
  • Partner with Platform Engineering to standardize secure guardrails for development squads.
  • Build dashboards to monitor automation maturity and remediation velocity.

๐Ÿ› ๏ธ Requirements

  • AppSec Tooling: Foundational knowledge 3+ years managing workflows in Checkmarx (SAST) and Black Duck (SCA).
  • Infrastructure Stack: Strong foundational knowledge of Linux, Windows Server, OpenShift Container Platform (OCP), databases, and middleware technologies.
  • Modern Engineering Frameworks: Practical understanding of Internal Developer Platforms (IDPs) and DevSecOps pipelines.
  • Automation & AI: Direct experience tracking or managing test automation frameworks and AI-assisted coding/security tools.
Full job description

Experience: 10+

Contract: Long Term

โ€ผ๏ธOnly GC, USCโ€ผ๏ธ

Expanded Key Responsibilities

Infrastructure & Full-Stack Triage

Analyze infrastructure-adjacent flaws by applying a solid understanding of Linux and Windows operating system vulnerabilities.

Oversee containerized security within OpenShift Container Platform (OCP), ensuring image scanning findings are triaged effectively.

Collaborate on data-layer risk, tracking and managing vulnerabilities related to databases (e.g., Oracle, SQL Server, PostgreSQL) and core middleware components (e.g., Apache, Tomcat, WebSphere).

Cross-reference application flaws (Checkmarx/Black Duck) with host-level and container-level vulnerabilities to determine the true, contextual runtime risk.

Automation & Platform Transformation

Track IDP Adoption: Partner with Platform Engineering to ensure development squads migrate to the Internal Developer Platform, standardizing secure guardrails.

Measure AI Security Adoption: Track and report metrics on how effectively developers utilize AI-driven security companions to triage and fix code flaws.

Govern Test Automation: Collaborate with QA and DevOps to embed automated security gates seamlessly into continuous integration pipelines.

Continuous Monitoring: Build dashboards that display automation maturity, remediation velocity, and the reduction of manual security operations. [1]

Cross-Functional Orchestration & Governance

Act as the primary SPOC aligning App Dev, AppSec, and Production Support teams to prioritize and resolve software flaws.

Enforce remediation SLAs ensuring security patches are delivered according to corporate compliance and risk thresholds.

Govern the Exception Management workflow, reviewing developer risk-acceptance requests and documenting temporary business justifications.

Integrate security fixes with Change Management protocols (e.g., ServiceNow) to ensure production support stability remains intact during deployments.

Local & Hybrid Expectations

Work Structure: 2-3 days on-site, 2-3 days remote (Hybrid).

Location Options: Iselin, NJ (Metropark) or Charlotte, NC (Corporate Hub).

Qualifications & Skills

Technical Requirements

AppSec Tooling: Foundational knowledge 3+ years managing workflows in Checkmarx (SAST) and Black Duck (SCA).

Infrastructure Stack: Strong foundational knowledge of Linux, Windows Server, OpenShift Container Platform (OCP), databases, and middleware technologies.

Modern Engineering Frameworks: Practical understanding of Internal Developer Platforms (IDPs) and DevSecOps pipelines.

Automation & AI: Direct experience tracking or managing test automation frameworks and AI-assisted coding/security tools.

Similar jobs

Positivo Tecnologia

ANALISTA DE SEGURANร‡A DA INFORMAร‡รƒO SR

๐Ÿ•’ 3 days ago
Positivo Tecnologia๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Semiconductors

This role focuses on enhancing information security and privacy practices, ensuring compliance with ISO 27001 and LGPD, while managing risks and collaborating across various business areas.

Governance, Risk And Compliance (grc)Information SecurityPrivacyISO 27001
Afya

Analista de Martech Sรชnior | Afya SP

๐Ÿ•’ 3 days ago
Afya๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Higher Education

As a Senior Martech Analyst, you will enhance and maintain Martech solutions, ensuring alignment with business needs through analysis, testing, and integration management.

MartechCRMDigital ProductsTechnology Platforms
Theconfigteamcareers

SAP Supply Chain Contractors - Register your interest

๐Ÿ•’ 3 days ago
Theconfigteamcareers๐Ÿ‘ฅ 201 - 500 employees๐Ÿข Information Technology And Services

Connect with experienced SAP Supply Chain contractors to explore future opportunities in SAP WM, EWM, and PP implementations and optimizations.

๐Ÿ“ ๐Ÿ‡ช๐Ÿ‡ฌ Egypt - Remote๐Ÿ’ผ Full-Time๐ŸŽธ Senior๐ŸŽฒ Other๐Ÿ“ข ๐Ÿ‡ฆ๐Ÿ‡ช Arabic Required๐Ÿ“ข ๐Ÿ‡ฌ๐Ÿ‡ง English Required
SAP WMSAP EWMSAP PPSAP S/4HANA

The Senior Due Diligence Analyst will execute complex due diligence projects, assess various risks, and provide actionable insights to support risk-based decision-making for a major global technology client.

Due DiligenceInvestigative ResearchRisk ConsultingFinancial Crime

Trusted by Remote Workers