Product/Platform Security Lead

1 week ago


Washington, Washington, D.C., United States IMF - International Monetary Fund Full time
Work for the IMF. Work for the World.


The Information Technology Department (ITD) at the IMF is more than just a support function; it is a critical catalyst for change.

We champion the seamless integration of cutting-edge technology solutions, ensuring the IMF's mission is propelled by innovation and efficiency.


Within the IT department, the Information Security and Governance (ISG) division and other first-line cybersecurity teams stand as the guardians of integrity and a beacon of trust.

We are not just about managing risks; we are about envisioning, enabling, and implementing a secure future for global economic stability.


Our teams are dedicated to:

  • Crafting and executing a forwardthinking and resilient Cybersecurity Strategy.
  • Enacting inclusive governance that balances security needs with operational fluidity.
  • Developing policies and standards that stay ahead of the threat landscape.
  • Ensuring compliance, resilience, and agility in our cybersecurity posture.
  • Engaging in relentless evaluation, management, and tracking of cybersecurity and digital risks linked to the utilization of the Fund's information assets, ensuring a secure operational framework.
  • Continuously enriching our annual information security culture, awareness, and education initiative, fostering a securityconscious environment across the organization.
  • Administering a compliance management program dedicated to maintaining firm adherence to the Fund's information security policies and standards.
  • Preserving a solid enterprise security reference architecture that acts as a safeguard for the Fund's information assets against pertinent threats.
  • Engineering, implementing, and sustaining secure and resilient technological solutions, spanning both onpremises and cloud infrastructures, to support the Fund's mission.
  • Overseeing cyber threat intelligence, and incident management, digital forensics, and investigations, alongside championing innovation in cybersecurity practices to achieve operational excellence and deliver value promptly.


As we expand our efforts to serve the Fund's staff and its members more effectively, we invite seasoned cybersecurity professionals to our elite cybersecurity teams.

We are looking for individuals with the requisite skills and expertise to address the current and forthcoming cybersecurity and business challenges faced by the Fund.


Job Summary


The Information Technology Department (ITD)'s Information Security and Governance (ISG) division of the International Monetary Fund (IMF) is seeking to fill a Product/Platform Security Lead (App Security) position.


Under the general supervision of the Chief Information Security Officer, this role will develop, mature, and drive application security initiatives at IMF including the design, implementation, and management of a comprehensive program to embed security into the software development lifecycle.


The role will serve as a lead subject matter expert on application security, providing pragmatic guidance to stakeholders across the organization.


Major Duties and Responsibilities
1\. Enhances, executes, and manages a formal application security program. Establish and execute forward looking application security strategies that enable proactive secure application development.

2\. Works closely with the broader information security team to align application security efforts with overall security objectives and initiatives.

3\.

Partners with application development and operation teams (and business stakeholders) to set the path for secure development practices for existing and future applications.

4\.

Provides advice, in collaboration with the Security Assurance and Security Policy functions, on the development and maintenance of security standards, policies, and guidelines for application development.

This includes enhancing software security design standards - building in security best practices at the beginning of the software development life cycle.

5\. Collaborates with the Security Architecture function to analyze and make recommendations to improve application security architectures.

6\. Provides guidance and training to developers on secure coding practices and common vulnerabilities.

7\. Collaborates with development teams in conducting application security tests, threat modeling, and code analysis to identify and mitigate security vulnerabilities

8\.

Stays updated on emerging threats, vulnerabilities, and industry trends in application security, and ensure that security measures are continuously improved and updated.

9\. Regularly monitors the Application Security program's operational health and maturity through key metrics and risk reporting.

Minimum Qualifications


Advanced degree in information security, computer science, engineering, mathematics, or related field of study plus a minimum of 8 years of progressive information security work experience; or a bachelor's degree in information security, computer science, engineering, mathematics, or related field of study and minimum of 14 years of progressive information security work experience.


  • Candidates should possess one or more of the following certifications— CISSP, CISM, CCSP, CEH, GIAC
  • Experience leading IAM related programs in regulated industries.

Relationship Management Skills

  • Ability to establish and maintain effective partnerships and working relations in a multicultural, multiethnic environment with sensibility and respect for diversity.
  • Demonstrates ability to represent the department fully and successfully to internal and external audiences.

Work Management Skills

  • Navigates through obstacles and challenges effectively and demonstrates commitment to deliver successful results.
  • Ability to lead, guide and mentor a diversified team of information security experts.
  • Ability to collaborate with IT and business colleagues to prioritize work, develop roadmaps, enhance services, and contribute meaningfully to the department's service delivery.
  • Ability to manage a broad portfolio of services; ability to balance multiple priorities and demands.
  • Analytical skills that enable synthesis of inputs from many sources and allow for strategic thinking and tactical implementation.
  • Interpersonal skills that create openness and trust among colleagues.
  • Facilitation and conflict management skills that enable effective working relationships.
  • Spoken and written communications that are compelling, convincing, and reassuring, and skills to articulate complex technical ideas to nontechnical stakeholders.
  • Pragmatic security expert with an inherent ability to balance security demands with business reality.

Technical Skills

  • Experience with assessment of a comprehensive and broad set of security technologies and processes, secure software development (Application Security), data protection, cryptography, key management, identity and access management, cloud API integration, network security, logging and monitoring within SaaS, IaaS, PaaS, and other cloud environments.
  • Experience working with cybersecurity capabilities within cloud infrastructure and services specifically for Microsoft Azure (amongst others e.g., Amazon Web Services-AWS and/or Google Cloud Platform-GCP).
  • An understanding of web service frameworks, mobile application architectures, and service architectures (such as eventdriven, serviceoriented, or serverless architectures).
  • Experience with Docker and microservices architecture.
  • Strong understanding of application security leading practices including OWASP and CWE.
  • Extensive experience in secure code reviews, business logic assessment, application security testing and
- automation of application security processes.

  • Experience managing secure coding and software deployment in a variety of current languages (e.g., Python, , C#, .NET, JavaScript, Go, Ruby, PowerShell, Bash, Scala). Experience with a variety of SDKs and RESTful API design/development.
  • Familiar with application security tools like BurpSuite Pro, SAST, DAST, Nmap, Metasploit, and Kali Linux, etc. Experience in 3rdparty testing tools such as Fortify, AppScan, Veracode, WhiteHat, etc.
  • Experience working with Agile development/Scrum methodologies, and incorporation of security requirements into SDLC (CI/CD) with product owners/managers.
  • Familiarity with HTML/CSS, JavaScript and UI/UX design and software quality assurance principles.
*This vacancy shall be filled by a 3-year Term appointment in accordance with the Fund's new employment rules that took effect on May 1, 2015.

Department:
ITDSG Information Technology Department Information Security & Governance

Hiring For:


A13, A14*The IMF is committed to achieving a diverse staff, including age, creed, culture, disability, educational background, ethnicity, gender, gender expression, nationality, race, religion and beliefs, and sexual orientation.

We welcome requests for reasonable accommodations for disabilities during the selection process.*

  • Washington, Washington, D.C., United States IMF - International Monetary Fund Full time

    Work for the IMF. Work for the World.The Information Technology Department (ITD) at the IMF is more than just a support function; it is a critical catalyst for change. We champion the seamless integration of cutting-edge technology solutions, ensuring the IMF's mission is propelled by innovation and efficiency.Our commitment is to: Maintain and elevate the...


  • Washington, Washington, D.C., United States IMF - International Monetary Fund Full time

    Work for the IMF. Work for the World.The Information Technology Department (ITD) at the IMF is more than just a support function; it is a critical catalyst for change. We champion the seamless integration of cutting-edge technology solutions, ensuring the IMF's mission is propelled by innovation and efficiency.Our commitment is to: Maintain and elevate the...


  • Washington, Washington, D.C., United States Teksouth Corporation Full time

    Teksouth is seeking a motivated and knowledgeable Power Platform Developer to join our team in a remote capacity. The developer will actively advise and participate in the architecture and hands-on development of applications primarily using the Microsoft Power Platform. The candidate should have extensive hands-on Power Apps and Power BI development...

  • Security Tools Lead

    4 weeks ago


    Washington, Washington, D.C., United States SAIC Career Site Full time

    Description SAIC is seeking a technical Security Tools Team Lead to join our dynamic team in supporting a critical US government agency in the National Capital Region. This role presents an exciting opportunity to lead the operation, maintenance, and modernization efforts of various security tools within a collaborative environment, reporting directly to...

  • Security Tools Lead

    2 months ago


    Washington, Washington, D.C., United States SAIC Career Site Full time

    Description SAIC is seeking a technical Security Tools Team Lead to join our dynamic team in supporting a critical US government agency in the National Capital Region. This role presents an exciting opportunity to lead the operation, maintenance, and modernization efforts of various security tools within a collaborative environment, reporting directly to...


  • Washington, Washington, D.C., United States Expression Full time

    Expression is seeking an experienced Cloud Platform Architect who has a growth mindset, insatiably curious, always learning and welcoming of challenges for the opportunity to grow. In this role you will help design cloud architecture, hybrid solutions, and application support for customer requirements, make recommendations based on both business analysis and...


  • Washington, Washington, D.C., United States Master Security Full time

    Master Security is a leading provider of security services to government and private sector clients in the North Capitol Region. With a history of reliability spanning more than 50 years, Master Security continues to provide focused, experienced, and professional security personnel and security solutions.Master Security is currently seeking FPS / GSA...


  • Washington, Washington, D.C., United States Mozilla Full time

    To learn the Hiring Ranges for this position, please select your location from theApply Nowdropdown menu.To learn more about our Hiring Range System, please click thislink. Why Mozilla?Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the...


  • Washington, Washington, D.C., United States ELS Inc Full time

    Founded in 1976 and headquartered in Arlington, VA, ELS, Inc. is an employee-owned small business that has been successfully providing Program Management, Acquisition, Business and Financial, Engineering, Field Engineering, Training and Logistics Support Services to the U.S. Navy for over 40 years. We are a Prime contractor on both SeaPort-e and the Navy's...


  • Washington, Washington, D.C., United States True Tandem Full time

    Company DescriptionTrueTandem's mission is to be a trusted information technology solutions provider, committed to the success of our customers, communities and employees. To enable this mission, we listen to our customers' needs, empower our dedicated and talented employees, envision success together, and deliver innovative cost-effective solutions. For our...


  • Washington, Washington, D.C., United States CDW Full time

    DescriptionBring your IT career and talents to CDW, where you can have a greater impact, be inspired by our mission and excited about your career and future. A Fortune 200 leader, we're the driven professionals and technology experts companies turn to most to solve their IT challenges.Fueled by our shared passion and expertise, CDW delivers innovative...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    Power Platform Apps DeveloperThe Opportunity: As a Power Platform Apps Developer, you know how to harness the latest technologies by developing low-code platforms and creating user-friendly solutions for your clients. We're looking for an experienced solution engineer like you to support the management of low-code development platforms from vision to...


  • Washington, Washington, D.C., United States Graham Technologies Full time

    Job Overview:Graham Technologies (GTECH) is seeking a Lead Security Control Assessor whose primary duties will be to ensure that all requirements for assessment in compliance with NIST are being met. You will be happy to know that this is a hybrid position. The work location is Washington, DC. Responsibilities:Validate all work provided by the team.Ensure...


  • Washington, Washington, D.C., United States IMF - International Monetary Fund Full time

    Work for the IMF. Work for the World.The Information Technology Department (ITD) at the IMF is more than just a support function; it is a critical catalyst for change. We champion the seamless integration of cutting-edge technology solutions, ensuring the IMF's mission is propelled by innovation and efficiency.Within the IT department, the Information...


  • Washington, Washington, D.C., United States QData Full time

    HiHope you are doing good...We have an urgent requirement below please go through Job description and send your updated profile and expected rate ASAP.Please reach me at .comJob Title DevOps Leads/ArchitectLocation Anywhere in NJ and Anywhere near DCONLY GC and CitizenJob Description Six or more years of total experience as a system administrator on Linux...


  • Washington, Washington, D.C., United States QData Full time

    HiHope you are doing good...We have an urgent requirement below please go through Job description and send your updated profile and expected rate ASAP.Please reach me at .comJob Title DevOps Leads/ArchitectLocation Anywhere in NJ and Anywhere near DCONLY GC and CitizenJob Description Six or more years of total experience as a system administrator on Linux...


  • Washington, Washington, D.C., United States TEKSOUTH CORPORATION Full time

    This is a hybrid position - one day onsite per week at Washington Navy Yard.Responsibilities Utilize strong troubleshooting skills to identify and resolve issues with Power BI dashboards, Power Apps, and SharePoint lists. Collaborate with the customer in translating user stories and requirements into functional code. Participate in meetings, task groups,...


  • Washington, Washington, D.C., United States True Tandem Full time

    Company DescriptionTrueTandem's mission is to be a trusted information technology solutions provider, committed to the success of our customers, communities and employees. To enable this mission, we listen to our customers' needs, empower our dedicated and talented employees, envision success together, and deliver innovative cost-effective solutions. For our...


  • Washington, Washington, D.C., United States Halvik Full time

    Job DescriptionHalvik is a thriving company focused on prioritizing its employees, and we are searching for a candidate like yourself to join our team. Our dedication lies in delivering intelligent IT solutions driven by quality and innovation to support the prosperity of our clients. You have the opportunity to contribute to something truly remarkable.What...


  • Washington, Washington, D.C., United States Source Moon Consulting, LLC Full time

    Introduction The Sponsor provides data-driven, business analysis to support senior organizational leaders and requires support specializing in cloud development of relevant processes, tools, and integrated systems to format, load, analyze, and display large-volume data streams, arriving in a variety of formats. Work Requirements Cloud Development-HRR: No The...