IT Security Officer (Application Security & Cloud Computing)
location_onCentral Regionschedule10 hours ago
apartmentWork style:On-site
badgeEmployment:Full-time
historyMinimum experience:5+ years
schoolEducation:Bachelor’s degree
Job description
Role Overview
We are seeking an experienced Application Security Officer to support cybersecurity risk management, application security reviews, security operations, and incident response activities across enterprise applications, infrastructure, and cloud environments.
The successful candidate will work closely with stakeholders, project teams, and technology teams to identify, assess, and remediate cybersecurity risks while promoting secure development practices and cybersecurity awareness.
Responsibilities
- Review system architecture, data flows, interfaces, APIs, internet-facing entry points, and existing security controls to identify potential security risks.
- Conduct cybersecurity risk assessments for new and existing IT systems, applications, infrastructure, and cloud services.
- Develop threat models and threat profiles for application projects to identify, quantify, and remediate application security risks.
- Review remediation plans and supporting evidence to verify that identified security risks have been adequately addressed.
- Track security vulnerabilities and ensure timely remediation, patching, and closure in accordance with established requirements.
- Monitor and investigate cybersecurity alerts and incidents, including malware, phishing, account compromise, data breaches, unauthorized access, and cloud security incidents.
- Perform cybersecurity incident response and management activities, including incident triage, investigation, containment, remediation, recovery, and post-incident review.
- Conduct security awareness training sessions to promote cybersecurity awareness and security best practices.
Requirements
Experience & Technical Skills
- At least 5 years of combined work experience in software development, application security, and cloud computing environments (e.g., AWS).
- Good understanding of mobile and web application architectures, including APIs and related technologies and protocols such as REST, SOAP, and SSL/TLS.
- Strong knowledge of application security principles and industry best practices, including OWASP Top 10 and OWASP Application Security Verification Standard (ASVS).
- Familiarity with Agile development methodologies, CI/CD, and DevSecOps practices, including tools such as GitLab, GitHub, and Ansible, as well as the integration of automated security testing into CI/CD pipelines.
- Experience using SAST code scanning tools such as Fortify-on-Demand, SonarQube, or equivalent solutions.
- Experience in threat modelling and developing threat profiles for application projects is preferred.
Soft Skills
- Good verbal and written communication skills.
- Strong collaboration skills and experience engaging with various stakeholders.
- Strong analytical, problem-solving, and troubleshooting abilities.
- Ability to work independently and effectively manage assigned responsibilities.
Education
- Degree in a relevant discipline or an equivalent qualification.
Preferred Qualifications
- Relevant professional certifications such as CISSP, OSCP, CCSP, CRISC, AWS Security Certification, or equivalent.
- Experience working with Government Commercial Cloud (GCC) environments is preferred.
Skills mentioned
Apply for this job
Use the application link supplied with this listing to apply to CMC Global. Check the destination before entering personal information.

