2

Aumni - Manager of Security Engineering

260312-South Florida Region Admin
Full-time
On-site
Salt Lake, Utah, United States
Description

It is your time to step up as a leader of talented security teams at one of the world's largest and most influential companies.




As a Manager of Security Engineering at JPMorgan Chase within the Aumni line of business, you are an integral part of team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. As a core technical contributor, you are responsible for carrying out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions. 




The Aumni Information Technology & Security department is responsible for maintaining the IT operations and security of Aumni’s systems and data. We collaborate with all other departments in various capacities with an emphasis on reducing friction where possible while maintaining security.  




Our mission statement is:  




To deliver stronger, smarter security solutions, provide peace of mind for the venture  




capital ecosystem, and enable the success of our customers, employees, and investors.  




If you do not have experience in each area listed below, do not let that discourage you  




from applying. We are looking for an individual with a solid foundation, an aptitude to  




learn, and the ability to ask good questions.  



Job responsibilities




  • Build an application security program that encompasses secure development throughout the SDLC

  • Partner with engineering management to ensure products are developed securely   

  • Educate our software engineers on secure coding practices and even build out a robust security champions program  

  • Assist our customers with their SSO configurations, identify product roadmap  

  • features that require a security eye, review API security configuration  

  • Co-manage our vulnerability scanning tools with our Cloud Security Engineer  

  • Inform the strategy for future headcount and budget in the application security engineering domain  




Required qualifications, capabilities, and skills


 





  • 2+ years of people management experience.  

  • 4+ years of application security experience.   

  • Strong understanding of security principles, protocols, and best practices.   

  • Capable of devising long-term security strategies and roadmaps for the Aumni application.   

  • Must be a team player who is eager to share domain knowledge with the team and eager to learn from others as well. 

  • Knowledge of Secure Software Development Lifecycle Frameworks.  

  • SCA & OSS License Scanning  

  • High Risk Code Review/Testing  

  • Helping Developers Follow Security Best Practices  







  • Vulnerability Remediation Support 

  • Experience with various threat modeling tools and methodologies (STRIDE, OWASP Top 10, Threat Dragon) 





Preferred qualifications, capabilities, and skills


 


  • Knowledgeable of Security Frameworks (ASVS, NIST CSF)  

  • Hands on experience implementing & managing various SAST, SCA & Secret scanning tools 

  • Hands on experience investigating & prioritizing vulnerabilities discovered by third party security tools. (Identifying false positives, out of scope items, adjusting CVSS severity of vulnerability to business context, etc.)  

  • Hands on experience with DAST tools 

  • Knowledge of CI/CD tools and how to integrate security into the pipeline

  • Experience with scripting languages (Bash, Python, etc.) 

  • Knowledge of SDET tools and writing security test cases

  • Experience securing various layers of the OSI model

  • Experience configuring and maintaining a Content Security Policy & other HTTP Security Headers

  • Experience with cloud platforms and securing them

  • Configuring Secret Scanning