Senior Web Application Security Specialist
VF CorporationAbout the role
Senior Web Application Security Specialist: Become the Newest Member of the VF Family
Now that you’ve found the job description, what’s next?
At VF, we strive to foster a culture of belonging based on respect, connection, openness, and authenticity. As a purpose-led, performance-driven company, we are committed to inclusion, diversity, equity, and action. So, before we get to the job details, take a minute to learn a little more about us – our values and our culture - visit VF Careers or www.vfc.com.
What will you do?
A day in the life of a Senior Web Application Security Specialist at VF looks a little like this.
As a member of the Application Security team, you will be a key member of the team looking across the VF Global enterprise looking for threats and vulnerabilities that would potentially or unnecessarily place the company at risk.
Working with the different teams within VF, you will oversee report findings to the key stakeholders, evaluate and prioritize key vulnerabilities and intersect with the risk functional team within cyber and information security. Responsibilities will include oversight of remediation efforts within VF.
Let’s break down that day in the life a bit more:
- Serve as a subject matter expert for application development and infrastructure teams
- Partner with application development teams for secure development process adoption and continuous security posture improvement
- Assist with the Dynamic Application Security Testing (DAST) program as needed
- Assist with Bug Bounty program as needed
- Determine and define project scope, objectives, and deliverable for large-scale application security project
- Identify metrics and Key Performance Indicators (KPIs) for application security program
- Analyze organization's cyber defense policies/configurations and evaluate weaknesses and vulnerabilities
- Support authorized penetration testing on enterprise network assets as needed
- Support purple team exercises and breach and attack simulations as needed
- Perform end-to-end application security reviews to ensure critical information is appropriately protected
- Participate in the creation of effective and efficient processes to drive successful reduction of risk within VF
- Lead in the design of more secure pipelines and update existing ones
- Research and advocate for new security solutions and technologies
- Ensure the highest levels of security practices are maintained by VF through projects, implementations
- Establish communications with associates related to threats, vulnerabilities, processes and security risks across a global landscape
- Advocate and evangelize the importance of Threat and Vulnerability management within VF and socialize through internal channels
What do you need to succeed?
We all have unique skills that we bring to work and celebrate every day. For this role, there are foundation skills you’ll need to succeed and excel. Additionally, while formal education in a related field is great to have, we are most interested in your 3+ years of experience and professional achievements.
Years of Related Professional Experience: 3-5 years
Position Requirements:
- Have experience with IT Security, Risk Management, or IT Auditing
- Expert knowledge of vulnerabilities as presented on the OWASP top 10
- Extensive experience with agile delivery practices
- Extensive experience integrating security into DevOps practices
- Understanding of networking protocols (IP, DNS, HTTP)
- Extensive experience conducting source code review
- Experience using static application security testing tools such as Fortify, Checkmarx, Veracode, etc.
- Extensive experience dynamic analysis with tools such as AppScan, Invicti, Qualys WAS, BurpSuite, and OWASP ZAP, etc.
- Experience in Web Application and/or Cloud penetration testing.
- Familiarity with common enterprise architectures.
- Experience auditing and configuring Akamai security products (WAF, BMP, etc.).
- Excellent organizational and communication skills.
- Demonstrated ability to work independently and with others
- Follows all defined IT standards and processes (i.e. IT Governance, SM&G, Architecture, etc.), and provides input for improvements to the appropriate process owners as needed
- Maintains a proper balance between business and operational risk
- Follows the defined project management standa
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s