Application Security and Compliance Programs Manager
Listed on 2025-12-27
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Reporting to the VP, Info Tech & Security, the Application Security and Compliance Programs Manager is responsible for our Compliance Programs & Application Security that ensures Cofense Engineering designs, builds, ships, and operates software securely whilst being responsible for our information security standards.
Essential Duties/Responsibilities- Primarily responsible for being single point of contact on all project management activities for FEDRAMP/SOC2/ISO
27001 program - Own the relationships with the 3
PAO, sponsoring agency, and FedRAMP PMO - Lead the FedRAMP continuous monitoring (Con Mon) activities including the Plans of Actions and Milestones (POA&Ms)
- Lead the planning, scheduling, and preliminary analysis for all internal and external audits
- Integrating security tools, standards, and processes into the software development lifecycle (SDLC)
- Ensuring that software engineers are trained with the appropriate level of security knowledge to perform their daily tasks
- Improving and supporting application security tool deployments including static analysis, dependency/component analysis, and dynamic analysis tools
- Improving and maintaining secure development
- Supporting incident response and architecture review processes whenever application security expertise is required
- Managing annual penetration testing services and application security assessments
- Providing manual penetration testing, threat modeling, and gap analysis for Cofense developed applications
- Supporting Vendor Security activities to ensure 3rd-party software and development meets Cofense security requirements
- Support application security activities related to compliance efforts including FedRAMP/SOC 2/ISO
27001 - Execute strategic vision for the Application Security program
- Other duties as assigned
Skills and Abilities
Required
- FedRAMP industry relationships and knowledge
- Superb soft skills including the ability to gain the trust of stakeholders and senior management and negotiate priorities with outside teams
- Working knowledge of public cloud providers (e.g., AWS)
- Ability to translate security concepts into language that is meaningful to many audiences, including business leaders, technical leaders, and individuals
- Ability to approach application security from the perspective of risk management
- Strong leadership and technical skills to effectively manage Application Security engineers
- Understanding of deployment methodologies in use for assigned products and projects
- Ability to multitask and context-switch across diverse teams and projects
- Familiarity with common security libraries, security controls, and common security flaws
- Familiarity with cloud security controls and best practices
- Excellent verbal and written communication skills
- 5+ years application security experience
- Experience must demonstrate working knowledge in all phases of preparing and reviewing complete ATO packages for information technology systems and/or applications as defined by the Federal Information Security Modernization Act and implemented by the guidance of the GSA Federal Risk and Authorization Management Program (FedRAMP)
- Must possess a strong background with
- NIST Risk Management Framework (SP 800-53)
- Federal Information Processing Standards (FIPS) 199 and 140
- DoD Cloud Computing Security Requirements Guide (SRG)
- Experience load-balancing multiple competing projects at the enterprise level
- Bachelor's degree preferred. Strong preference given for bachelor and advanced degrees in software technology related fields
The above statements are neither intended to be an all-inclusive list of the duties and responsibilities of the job described, nor are they intended to be a listing of all of the skills and abilities required to do the job. Rather, they are intended only to describe the general nature of the job. This job description is not a contract of employment, either express or implied.
Employment with Cofense will be voluntarily entered into and your employment is considered ense reserves the right to alter the job description at any time without notice.
Cofense is committed to equal employment opportunity. We will not discriminate against employees or applicants for employment on any legally recognized basis [protected class] including, but not limited to: veteran status, uniform service member status, race, color, religion, sex (including pregnancy), gender identity, sexual orientation, national origin, age, physical or mental disability, marital status, genetic information or any other status or characteristic protected by applicable national, federal, state or local laws and ordinances.
We adhere to these commitments in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, and discipline.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).