Requirements
The role requires a Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field, with 4-6 years of experience in application security, secure software development, security assessments, or vulnerability management. Professional certifications in Application Security or Secure Software Development are considered an advantage.
Description
OverviewJob Description Job TitleConsultantJob Code680865GradeI3GroupDivisionLegal, Risk & GovernanceDepartmentCybersecurityUnitApplication SecurityROLE PURPOSEThe aim is to state the overall significance of the job from the organization's perspective.The role exists to perform application security assessments and support the integration of security throughout the software development lifecycle by identifying application vulnerabilities, conducting code and design reviews, assessing APIs and integrations, and providing security guidance to development teams to strengthen the security of Elm's applications and digital solutions.Key Accountabilities & ActivitiesThis section describes the principal outputs required from the job.Key AccountabilitiesKey ActivitiesApplication Security AssessmentPerform security assessments for applications and digital solutions.Evaluate applications against approved security requirements and standards.Document identified vulnerabilities, risks, and recommended remediation actions.Secure Code ReviewConduct security-focused source code reviews to identify vulnerabilities and insecure coding practices.Assess code against secure coding standards and common application security risks.Provide remediation guidance to development teams.Threat ModelingConduct threat modeling for new and existing applications and services.Identify potential attack scenarios, threats, and security control gaps.Recommend security controls based on identified risks.Application Vulnerability ManagementIdentify, analyze, and assess application-layer vulnerabilities.Coordinate with development teams on vulnerability remediation activities.Validate remediation and monitor outstanding application security findings.API & Integration SecurityAssess APIs, microservices, and third-party integrations for cybersecurity risks.Evaluate authentication, authorization, data protection, and integration controls.Recommend appropriate security improvements.Secure Design & Development AdvisoryProvide security guidance to development and engineering teams throughout the development lifecycle.Support the application of secure design and development practices.Recommend security controls appropriate to solution risks and requirements.Application Security Standards & FrameworksDevelop and maintain application security standards, guidelines, and technical requirements.Support alignment with secure software development practices and applicable cybersecurity standards.Evaluate emerging application security practices and recommend enhancements.Developer Security AwarenessSupport secure coding awareness and technical security training for developers.Develop security guidance and knowledge materials addressing common application vulnerabilities.Promote secure development practices across engineering teams.Policies, Processes & ProceduresFollow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.Information SecurityComply with all relevant information security practices and standards to ensure data integrity and confidentiality.JOB SPECIFICATIONSAcademic And Professional QualificationsBachelor's degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field.Professional certifications in Application Security, Secure Software Development, or related cybersecurity disciplines are considered an advantage.Years And Nature Of Experience4–6 years of experience in application security, secure software development, security assessments, vulnerability management, or related cybersecurity domains.