Cybersecurity Analyst ( AppSec )
DiscoverAbout the role
Discover. A brighter future.
With us, you’ll do meaningful work from Day 1. Our collaborative culture is built on three core behaviors: We Play to Win, We Get Better Every Day & We Succeed Together. And we mean it — we want you to grow and make a difference at one of the world's leading digital banking and payments companies. We value what makes you unique so that you have an opportunity to shine.
Come build your future, while being the reason millions of people find a brighter financial future with Discover.
Job Description:
What You’ll Do
The Application Security teams at DFS provides services and products for securing the software and product footprint used to run the business. As DFS business and engineering workforce has grown, our software footprint has also grown and become more heterogeneous, thus warranting next gen DevSecOps and Application security program implementation with focus on risk and compliance and app dev experience.
Reporting into the Head of Product Security the Cybersecurity Analyst will be a key team member of fast-paced Application security analysis team. This role will be executing threat models, meetings with various cross-functional teams to understand their objectives and limitations, making recommendations on how to build securely, and help drive collaboration from internal application development and product teams to disposition the vulnerabilities, risk and non-compliance to security requirements.
This role requires high levels of application security technical acumen, collaboration and oversight, including the effective challenge of remediation action plans, documentation of control gaps (e.g., Security Exceptions, Issues and Actions), and the ability to work within a team while maintaining independence and ownership of your work. If you are still reading this and intrigued, you could be the right candidate for the role. Please see additional details below and apply today.
How You’ll Do It
Threat model applications, systems, and platforms with a focus on security best practices and data protection requirements
Manages and executes cybersecurity risk assessments using qualitative and quantitative methodologies to support the organization's overall security posture.
Partner with Product Owners to evaluate current security posture and drive future security control implementations based on gaps found during the cybersecurity risk assessment.
Utilizes ServiceNow and Cyber Risk System for risk management and risk remediation, processing potential security exceptions and/or risk acceptances against established security policies and standards.
Identify areas for potential attacks and systemic security issues as they relate to threats and vulnerabilities, including recommendations for enhancements or remediation
Participate in design sessions for proposed system solutions
Engage application teams through an intake process to identify purpose of their system, components that comprise the system, identify threats and recommend security requirements.
Prepare and deliver written and verbal briefings to message threat modeling findings across all levels of the enterprise.
Works independently to scope vulnerable bodies of technologies, identify weaknesses, severity and impact, and recommend paths to remediation
Learns advanced Cybersecurity concepts including new and modern threat exploitation techniques of internal and external bad actors
Achieves team commitments (and influence others to do the same) by using informal leadership & highly developed communication skills
Delivers metrics and performance reporting to enhance real-time risk decisions and initiative prioritization.
Collaborates with cross-functional resources to drive progress toward cyber initiatives or risk remediation deliverables.
Coordinates all exam management requests with program owners.
Collects, reviews, and uploads all artifacts submitted as evidence in advance of requested dates.
Assists in compiling management corrective action plans for risk item closure.
Performs due diligence and validation on identified risk findings.
Minimum Qualifications
At a minimum, here’s what we need from you:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s