Jobs and Careers
ZU

Senior Security Testing Engineer

Zurich Insurance
SpainRemotefull_timeVerifiedPosted 29 May 2024

About the role

<p>Our opportunity</p> <p> </p> <p>As Test Manager within BTO Security Testing, you will be part of a Global team providing Application Security services to Zurich Business Units across the world, joining a young and motivated team that is growing fast with focus on a key area for our business. </p> <p>You will be working with both Zurich Security and Application teams to ensure that Application Security Testing requirements are met by coordinating and providing support to the SDLC application scanning and Manual Pen Testing projects across the world.</p> <p>As part of this role, you will not only be using your AppSec skills, but also coordinating both Zurich internal and external teams in different countries, work with the top ranked AppSec toolset and boost your career to the next level.</p> <p> </p> <p> </p> <p>Your role</p> <p>  </p> <p>As a Test Manager your main responsibilities will involve:</p> <p> </p> <ul> <li>Lead and participate in the Information Gathering Sessions to evaluate the requirements from the clients and take the prerequisites required to elaborate the Proposal of Collaboration</li> <li>Evaluate together with the technical lead, the proposal notes and share them with the Test Service Manager</li> <li>Operate with the Security Pipeline to identify next Security Assessment projects in scope and: <ul> <li>Work the stakeholders on confirming scope of projects and access requirements.</li> <li>Elaborate and send the Security Assessment Plan before the projects start.</li> <li>Upload the information gathered and share it with the testers.</li> </ul> </li> </ul> <ul> <li>During the project execution <ul> <li>Be the SPOC of both testers and clients and facilitate the resolution of potential issues that might occur during the MPT projects.</li> <li>Provide support and guidelines to the testers on the project execution when needed.</li> </ul> </li> <li>After project execution: <ul> <li>Ensure that final reports are sent over to the stakeholders.</li> <li>Ensure that Finding Agreements meeting is schedule and assigned to the Tech lead or his/her delegates.</li> <li>Oversee Retest process and ensure that testers take the required actions to run them as per the schedule.</li> </ul> </li> <li>Support and be the SPOC for the Veracode Service supporting the Global Test Service Manager</li> <li>Attend to any required meeting related to Veracode delegated by the Global Test Service Manager</li> <li>Support the team providing services to Veracode and facilitate coordination between the Operations team and the clients.</li> <li>Oversee the Security Test engineering team mailbox and: <ul> <li>Share any relevant proposal received via Forms for Security Assessments with the team contacts.</li> <li>Oversee the request related to Veracode or any Security scan requirements are completed by the Security operations team.</li> </ul> </li> <li>Participate and work together with the Global Security Test Manager on the process and procedures documentation related to the services provided by the unit. </li> <li>Work with external providers and oversee their activities related to Security Assessments and Application Security services.</li> <li>Act as a backup of the Global Security Test Service Manager if required and to cover actions related to the Project execution and designed tasks related to the Run&amp;Maintain services.</li> </ul> <p> </p> <p> </p> <p>Your Skills and Experience </p> <p> </p> <p>As a Test Manager your skills and qualifications will ideally include:</p> <p> </p> <ul> <li>Bachelor’s Degree or equivalent in Computer Science or related subject</li> <li>Understanding of Application Security Testing requirements related to the SDLC. </li> <li>Proven experience managing or executing Manual Pen Testing during the SDLC</li> <li>Hands on experience on AppSec scanning: SAST, DAST IAST, SCA, </li> <li>Experience on DevSecOps/Cloud Security is a plus.</li> <li>Understanding of Information/IT governance and risk management</li> <li>Proven experience with common AppSec Frameworks such as OWASP, PTES, NIST</li> <li>Excellent communication skills, being able to take part in meetings and provide expert advice.</li> </ul> <p> </p> <p><u>Preferred Qualifications</u></p> <p> </p> <ul> <li>Professional Security Qualification - CISSP, CISM, CCSP (or other similar cloud security qualification), CEH, CompTIA Security+</li> <li>Knowledge &amp; Experience of working with AppSec scanning and Manual Pen Testing tools, (Veracode, Checkmarks, Burp suite, among others) </li> <li>Experience as an Application Security Consultant/ Manager/ Developer</li> <li>Familiar with Agile project management methodologies</li> </ul> <p> </p> <p> </p> <p> </p> <p>Additional Information</p> <p> </p> <p>As well as a competitive salary and a yearly bonus we offer benefits package which includes: </p> <p> </p> <ul> <li>Option to work remotely within Spain even up to 100% - you choose; with option to work abroad up to 25 days yearly</li> <li>Ov

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Zurich Insurance

View company profile →