Senior Engineer, Application Security
VF CorporationAbout the role
Senior Engineer, Application Security: Become the Newest Member of the VF Family
As a member of the Application Security team, you will be a key member of the team looking across the VF Global enterprise looking for threats and vulnerabilities that would potentially or unnecessarily place the company at risk.
Working with the different teams within VF, you will oversee and report findings to the key stakeholders, evaluate and prioritize vulnerabilities and intersect with the risk functional team within cyber and information security. Responsibilities will include oversight and management of the Bug Bounty and Vulnerability Disclosure Programs at VF.
How You Will Make a Difference:
- Create and implement the strategic vision for the company’s Bug Bounty and Vulnerability Disclosure Program
- Develop policy for both programs
- Drive continuous improvement in the programs by strategically aligning with organizational goals
- Mentor and train Application Security team members
- Ensure Organizational Level Agreements for remediation, as defined by internal policy and standards, are met
- Serve as a cybersecurity subject matter expert for application development and infrastructure teams
- Partner with application development teams for secure development process adoption and continuous security posture improvement
- Participate in Red Team exercises to simulate real-world attacks, identifying potential gaps in security and effectiveness of existing defenses
- Analyze organization's cyber defense policies and recommend improvements that align with strategic cybersecurity goals
- Perform threat assessments on application-level and infrastructure components to identify security risks
- Assist with the Dynamic Application Security Testing(DAST) program as needed
- Identify metrics and Key Performance Indicators (KPIs) for application security program
- Support authorized penetration testing on web applications and enterprise network assets as needed
- Support purple team exercises and breach and attack simulations as needed
- Perform end-to-end application security reviews to ensure critical information is appropriately protected
- Assist with incident response activities as needed, particularly around web applications
- Participate in the creation of effective and efficient processes to drive successful reduction of risk within the organization
- Lead in the design and implementation of more secure pipelines and update existing ones
- Research and advocate for new security solutions and technologies
- Ensure the highest levels of security practices are maintained by VF through projects and implementations
- Establish communications with associates related to threats, vulnerabilities, processes and security risks across a global landscape
- Advocate and evangelize the importance of Threat and Vulnerability management within VF and socialize through internal channels
Years of Related Professional Experience: 10+ years
Position Requirements:
- Proven experience in offensive security, penetration testing, or application security, with a focus on web application security
- Expert level understanding of web application security vulnerabilities (OWASP Top 10, etc.) and exploits
- Experience with Red Team and Purple Team exercises, with knowledge of attack simulation tools and methodologies
- Extensive experience with agile delivery practices
- Extensive experience integrating security into DevOps practices
- Extensive experience conducting source code review
- Experience using static application security testing tools such as Fortify, Checkmarx, Veracode, etc.
- Extensive experience with dynamic application security testing tools such as AppScan, Invicti, Qualys WAS, BurpSuite, and OWASP ZAP, etc.
- Familiarity with common enterprise architectures
- Excellent organizational and communication skills
- Demonstrated ability to work independently and with others
- Follows all defined IT standards and processes (i.e. IT Governance, SM&G, Architecture, etc.), and provides input for improvements to the appropriate process owners as needed
- Maintains a proper balance between business and operational risk
Educational Preferences:
- A bachelor’s or master’s degree in computer science, information systems or other related field; or equivalent work experience
- Relevant certifications (CISSP, CSSLP, OSCP, OSWE, eWPT, PWPP etc.)
Special Physical and/or Mental Requirements:
- Travel by air and overnight, as required 10% amount of time.
Hiring Range:
$116,000.00 UApply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s