Senior Technology Manager - Application Security
Bank of AmericaAbout the role
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. Weβre devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Job Description:
This job is responsible for building and leading a team to deliver technology products and services that meet business outcomes. Key responsibilities include developing a technology strategy, ensuring technology solutions comply with applicable standards, promoting design, engineering, and organizational practices, and advocating and advancing modern, Agile solution delivery practices. Job expectations may include coaching, mentoring, providing feedback and hands on career development, identifying emerging talent, fostering leadership skills, and managing stakeholders.
Position Summary
We are seeking a highly skilled and hands-on Senior Technology Manager specializing in Application Security. This role requires deep technical expertise in secure coding practices, vulnerability scanning, and cloud application security. The Senior Technology Manager will lead technical initiatives focused on security code scanning, application vulnerability scanning using tools such as Invicti, Checkmarx and validating secure coding practices in cloud environments. The Manager will collaborate closely with developers, DevOps, and cloud architects to embed security within the software development lifecycle and cloud infrastructure.
As the Sr. Manager over our Application Security program, you will lead multiple teams in the design, development, test, and delivery of innovative products to identify and reduce security vulnerabilities during the CI/CD process. The Manger will contribute to our mission of safeguarding our valuable assets and data from evolving cyber threats. The leader of this dynamic team and make a significant impact on our organization's security posture and lead us through our Application Security program. This role is highly visible to senior leadership, auditors, and regulators.
The successful candidate will have demonstrated success in building software products, managing engineering teams, coordinating large-scale projects, effectively communicating with executive and technical audiences, and moving quickly to achieve outcomes. This is a technology leadership role requiring software engineering experience to excel but not focused on personal delivery of code.
Key Responsibilities:
Hands-On Technical Leadership:
- Provide hands-on leadership in the deployment, configuration, and management of application security scanning tools such as Invicti and Checkmarx.
- Design and implement application security strategies for cloud-based and on-premises applications, focusing on secure code development and vulnerability management.
- Serve as a technical subject matter expert on secure coding practices, secure architecture, and vulnerability scanning methods.
Security Code and Vulnerability Scanning:
- Manage the configuration, customization, and automation of application security scanning tools, enabling comprehensive scanning in CI/CD pipelines.
- Analyze scan results, triage security findings, and provide detailed remediation guidance to developers.
- Conduct regular assessments of the scanning tools to optimize their efficiency and accuracy in detecting security vulnerabilities.
Cloud Application Security Validation:
- Validate that cloud applications adhere to secure coding practices by leveraging static and dynamic analysis tools.
- Collaborate with cloud architects to design secure application architecture and enforce security policies within cloud environments (AWS, Azure, GCP).
- Implement and review cloud security configurations, ensuring alignment with security frameworks such as CIS Benchmarks and NIST.
Sec
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights β in under 60 seconds.
Apply Now βGenerate Application KitFree account required β sign up in 30s