DevSecOps Application Security Specialist

1 week ago


Carrollton, Texas, United States AmerisourceBergen Services Corporation Full time
Job Summary

We are seeking an experienced DevSecOps Application Security Engineer III to join our team at AmerisourceBergen Services Corporation. As a key member of our security team, you will be responsible for identifying, assessing, and remediating application vulnerabilities with strict adherence to predefined SLAs. Your expertise in DevSecOps practices, API Security, and Application Security will enable you to work closely with developers to empower them with secure coding practices and collaborate with DevOps, Operations, Application Development, and Security Architecture teams to foster collaboration and ensure that security is embedded throughout the development lifecycle.

Key Responsibilities
  • Incorporate security measures into every stage of the DevOps pipeline to protect applications and APIs
  • Implement and maintain controls within the Continuous Integration/Continuous Deployment (CI/CD) pipeline to meet necessary security standards
  • Regular usage of automated tools for routine security checks
  • Facilitate collaboration among development, operations, and security teams
  • Develop policies that align with regulations, alongside conducting comprehensive assessments of application/API security
  • Educate teams about secure use of applications/APIs, keeping up-to-date with cybersecurity trends, ensuring adherence to secure design principles across all Software Development Life Cycle (SDLC) phases, managing incident response protocols, and providing training on secure coding best practices
  • Utilize automation tools to identify potential vulnerabilities before they escalate into threats
  • Evaluate third-party services for potential weaknesses in their security posture
  • Ensure that vulnerabilities are remediated before code moves to production and provide guidance on the remediation process for application/API security vulnerabilities
  • Work closely in collaboration with Information Security Officers (ISOs), DevOps teams, Application Development teams, Vendor Partners, and Cyber Engineering teams
  • Conduct proactive research to analyze security weaknesses and recommend appropriate strategies to strengthen controls
  • Assists in security initiatives for areas like Cyber Operations, Incident Response, Threat Intelligence, and Vulnerability Management
  • Guide, coach, and mentor Engineers I/II in executing their tasks, ensuring they follow best security practices
  • Work on multiple projects as a key contributor, contributing to the strategic and tactical direction of cybersecurity initiatives
  • Collaborate with IT teams to improve cloud and application security measures and integrate new and support existing security applications
  • Communicate advanced information security concepts with clients, peers, management, and vendors effectively
  • Familiarity with Static Application Security Testing (SAST), Software Composition Analysis (SCA), Container Security, Infrastructure as Code (IaC) Security, API Security, Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), and Runtime Application Self-Protection (RASP)
Requirements
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field. A strong academic foundation in these disciplines supports advanced skills in security architecture, risk management, and secure development practices
  • Application Security: In-depth knowledge and hands-on experience in securing applications throughout the software development lifecycle. Proficient in threat modeling, secure code review, and utilizing tools to identify security weaknesses
  • API Security: Expertise in securing RESTful and SOAP APIs, ensuring secure authentication, authorization, and data validation mechanisms
  • DevSecOps Integration: Implementing security controls within the CI/CD pipeline to ensure that security is continuously integrated, tested, and monitored across development, deployment, and operational processes
  • Application Vulnerability Management: Extensive experience in vulnerability scanning, penetration testing, and remediating critical security issues such as SQL injection, cross-site scripting (XSS), and buffer overflows. Proven ability to remediate vulnerabilities against predefined SLAs, ensuring that all vulnerabilities are resolved within required timeframes
  • Tracking Aging Vulnerabilities: Strong focus on monitoring and tracking aging vulnerabilities to ensure timely remediation and prevent accumulation of unresolved security issues, using metrics and reporting to manage risk
  • Shift Left Security & Developer Empowerment: Strong advocate for embedding security at the earliest stages of development to reduce vulnerabilities and streamline remediation efforts. Actively empowers developers by promoting secure coding practices and providing them with the necessary tools and training to enhance security awareness and skills
  • Cross-Team Coordination: Proven ability to collaborate and coordinate with DevOps, Operations, Application Development, and Security Architecture teams, ensuring seamless integration of security into every stage of the development and deployment process
  • Platform Expertise: Proficient in using Checkmarx One and Veracode to conduct comprehensive static and dynamic analysis of application code, ensuring that security vulnerabilities are detected and remediated throughout the development lifecycle
  • Familiarity with Static Application Security Testing (SAST), Software Composition Analysis (SCA), Container Security, Infrastructure as Code (IaC) Security, API Security, Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), and Runtime Application Self-Protection (RASP)
Certifications
  • OSCP (Offensive Security Certified Professional) – Demonstrates practical skills in penetration testing and ethical hacking.
  • CEH (Certified Ethical Hacker) – Expertise in identifying vulnerabilities and securing systems against common threats.
  • CISSP (Certified Information Systems Security Professional) – Broad knowledge of cybersecurity concepts, including risk management, asset security, and security operations.
What We Offer

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit

Salary Range$86,860

This Salary Range reflects a National Average for this job. The actual range may vary based on your locale. Ranges in Colorado/California/Washington/New York/Hawaii/Vermont/Minnesota/Massachusetts/Illinois State-specific locations may be up to 10% lower than the minimum salary range, and 12% higher than the maximum salary range.

Equal Employment Opportunity

AmerisourceBergen Services Corporation is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.

The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.

AmerisourceBergen Services Corporation is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call or email. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned

.

Affiliated CompaniesAffiliated Companies: AmerisourceBergen Services Corporation

  • Carrollton, Texas, United States Paranet Full time

    Job DescriptionWe are seeking a highly skilled Cyber Security Specialist to join our team at Paranet. As a key member of our security team, you will be responsible for providing technical assistance to our customers in the Dallas area.Key ResponsibilitiesMonitor and analyze network logs to identify potential security breachesInvestigate and respond to...


  • Carrollton, Texas, United States NSC Technologies Full time

    About the RoleWe are seeking a highly skilled Security Systems Specialist to join our team at NSC Technologies. As a key member of our security solutions business, you will be responsible for installing and servicing access control, CCTV, and surveillance systems.Key ResponsibilitiesInstallation and Service: Perform service and installation of various...


  • Carrollton, Texas, United States Anistar Full time

    Job SummaryWe are seeking a highly skilled Lead Security Specialist to join our team at Anistar Technologies. As a key member of our security solutions business, you will be responsible for installing and servicing access control, CCTV, and surveillance systems.Key ResponsibilitiesInstall and configure various security management solutions, including access...

  • Security Officer

    3 weeks ago


    Carrollton, Texas, United States BankInfoSecurity Full time

    About the Role:As a Security Officer - Data Center Specialist at BankInfoSecurity, you will be responsible for ensuring the security and safety of our clients' property and personnel. This is a critical role that requires a high level of professionalism, attention to detail, and effective communication skills.Key Responsibilities:Implement site-specific...


  • Carrollton, Texas, United States Paranet Solutions, Inc. Full time

    Job Title: L1 Security AnalystWe are seeking a highly skilled L1 Security Analyst to join our team at Paranet Solutions, Inc. in the Dallas area.Job Summary:The L1 Security Analyst will provide technical assistance to our customers, focusing on network security analysis, monitoring, and incident response. This role requires a strong understanding of security...


  • Carrollton, Texas, United States NSC Technologies Full time

    Job Title: Security TechnicianLocation: Dallas-Ft. Worth, TexasJob Summary:We are seeking a skilled Security Technician to join our team at NSC Technologies. As a Security Technician, you will be responsible for installing and servicing access control, CCTV, and surveillance systems.Key Responsibilities:Install and configure security management solutions,...


  • Carrollton, Texas, United States NSC Technologies Full time

    Job Title: Lead Security TechnicianLocation: Dallas-Ft. Worth, TexasPay Rate: Up to $35/hourJob Summary:Anistar Technologies is seeking a skilled Security Technician to install, program, and service access control, CCTV, and surveillance systems. The successful candidate will support the security solutions business by installing and troubleshooting newly...


  • Carrollton, Texas, United States Community Choice Financial Family of Brands Full time

    Job Title: Lead Cybersecurity SpecialistJoin our team as a Lead Cybersecurity Specialist and take on a critical role in protecting our digital assets from the ever-evolving threat landscape.Job SummaryWe are seeking a highly skilled and experienced cybersecurity professional to lead our security operations detection and response functions. As a Lead...


  • Carrollton, Texas, United States Axiom Path Full time

    Cyber Security Engineer III - Data Protection SpecialistAxiom Path is seeking a highly skilled Cyber Security Engineer III to join our dynamic team. As a key member of our cybersecurity operations team, you will play a critical role in protecting critical data in the global healthcare supply chain.Key Responsibilities:Lead the review and management of Data...


  • Carrollton, Texas, United States Motion Recruitment Full time

    {"title": "Cybersecurity Systems Specialist", "content": "Cybersecurity Systems SpecialistMotion Recruitment is seeking a highly skilled Cybersecurity Systems Specialist to join our team in Carrollton, Texas. As a key member of our team, you will be responsible for designing and implementing secure systems and networks to protect our clients' critical...


  • Carrollton, Texas, United States Community Choice Financial Family of Brands Full time

    About the RoleWe are seeking a highly skilled Sr. Information Security Engineer to join our team at Community Choice Financial Family of Brands. As a key member of our security team, you will be responsible for providing oversight of our enterprise security technologies and advancing our security program.Key ResponsibilitiesOwns Information Security...


  • Carrollton, Texas, United States NSC Technologies Full time

    Lead Security Technician Job DescriptionWe are seeking a skilled Lead Security Technician to join our team at NSC Technologies. As a key member of our team, you will be responsible for installing and servicing access control, CCTV, and surveillance systems.Key Responsibilities:Install, configure, and test security management solutions, including access...

  • IT Support Specialist

    2 weeks ago


    Carrollton, Texas, United States edgecomputingassociation Full time

    Job Title: IT Support SpecialistAt edgecomputingassociation, we are seeking a highly skilled IT Support Specialist to join our team. As an IT Support Specialist, you will be responsible for providing technical support to our end-users, troubleshooting and resolving hardware and software issues, and maintaining our computer systems and networks.Key...


  • Carrollton, Texas, United States edgecomputingassociation Full time

    Job Title: IT Support SpecialistAt edgecomputingassociation, we are seeking a highly skilled IT Support Specialist to join our team. As an IT Support Specialist, you will be responsible for providing technical support to our end-users, troubleshooting and resolving hardware and software issues, and maintaining our computer systems and networks.Key...


  • Carrollton, Texas, United States Amazon Inc Full time

    Job Title: Loss Prevention SpecialistThe Loss Prevention Specialist plays a critical role in Amazon Operations, leading the effort to safeguard assets and ensure a secure work environment. Key responsibilities include:Overseeing security services to prevent losses and protect company assetsDeveloping and implementing effective security protocols to mitigate...


  • Carrollton, Texas, United States Community Choice Financial Family of Brands Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Specialist to join our team at Community Choice Financial Family of Brands. As a key member of our Information Security team, you will play a critical role in safeguarding our company against cyber threats and ensuring the confidentiality, integrity, and availability of our systems and data.Key...


  • Carrollton, Texas, United States Community Choice Financial Family of Brands Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Specialist to join our team at Community Choice Financial Family of Brands. As a key member of our Information Security team, you will play a critical role in safeguarding our organization against cyber threats and ensuring the confidentiality, integrity, and availability of our systems and data.Key...


  • Carrollton, Texas, United States Insight Global Full time

    Technical Support SpecialistInsight Global is seeking a skilled Technical Support Specialist to join our team. As a Technical Support Specialist, you will be responsible for troubleshooting, configuring, installing, and managing hardware, software, and access issues in our clients' environments.You will work closely with our clients to identify and resolve...


  • Carrollton, Texas, United States Crescent Bank Full time

    About the RoleCrescent Bank is seeking a highly skilled professional to fill the position of Enterprise Risk Management Specialist. This individual will play a crucial role in safeguarding the bank's assets and ensuring compliance with industry and regulatory standards.Key ResponsibilitiesRisk Assessment and Testing: Design and conduct risk assessments and...


  • Carrollton, Texas, United States McLane Company Full time

    Job SummaryWe are seeking a highly skilled Loss Prevention Specialist to join our team at McLane Company. As a Loss Prevention Specialist, you will be responsible for ensuring the safety and security of our facility and its occupants.Key ResponsibilitiesAccess Control: Monitor and control access to the facility, ensuring that only authorized personnel are...