Sr. Manager, Information Security

2 months ago


Boston, United States Globalization Partners. Full time

What you will do:

Manage a team of engineers/analysts and build resiliency into the team. Evangelize application security fundamentals and act as a consultative partner to development teams. Implement and leverage SAST/DAST/SCA security tools like Veracode and Snyk. Make recommendations on application security tools. Guide and perform security activities including threat modeling and vulnerability analysis, code review, and security testing, ensuring teams are validating for OWASP Top 10 and CWE/SANS Top 25. Triage application risks daily as identified by AppSec scanning tools to eliminate false positives and provide a well-vetted set of vulnerabilities to engineering. Collaborate with engineering to drive the timely remediation of vetted risk and to implement creative solutions that increase operational effectiveness. Generate, collect, and report on AppSec metrics on a regular basis. Make recommendations on development processes and provide production application security support as needed. Create and maintain technical documentation for the AppSec program. Contribute to the development and delivery of security awareness and secure development training programs.

What we are looking for:

10+ years of related work experience in the Application Security field. Strong communication and relationship building skills with a high degree of comfort speaking with developers, IT executives, and business partners. Strong experience managing & developing a high-performance team. Strong experience performing security focused application design reviews, threat modeling, manual code reviews, container security, and ethical hacking. Strong experience implementing and working with SAST/DAST/SCA security tools. Deep knowledge of security vulnerabilities, being able to identify issues, assess risk, and provide remediation guidance. Deep knowledge of authentication and authorization options and standards. Strong experience using common security testing tools and techniques to perform security assessments with significant expertise in either web or mobile penetration testing. Strong experience working with developers and knowledgeable about modern web, mobile, and API development practices. Ability to read and write code in at least one programming language. Knowledge of CI/CD practices and experience incorporating security requirements into a SDLC.

The annual gross base salary range for this position is $,-$, plus an annual bonus opportunity.

G-P values its employees and offers excellent benefits and perks including generous paid parental leave, flexible time off, flexible spending accounts, medical Insurance, dental Insurance, vision Insurance, k, and sabbatical after 5 years of service.

We will consider for employment all qualified applicants, including those with arrest records, conviction records, or other criminal histories, in a manner consistent with the requirements of any applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.

Are you ready to work for a company that has continuously being recognized as a Top Place to work. People are the heartbeat of the company and the key to making G- P an inclusive and fun place to work – a collaborative environment where you can make a real impact and love the work you’re doing



  • Boston, United States BOSTON TRUST WALDEN COMPANY Full time

    Job DescriptionJob DescriptionBoston Trust Walden Company Overview Boston Trust Walden Company is an independent, employee-owned firm that provides investment management services to institutional investors and private wealth clients. The firm manages approximately $16 billion in client assets.Boston Trust Walden distinguishes itself in several key ways,...


  • Boston, United States Whitridge Associates Full time

    As an Information Security Specialist, you will be responsible for managing and improving our information security programs, focusing on vulnerability management, remediation, and security program analysis. Your expertise in email security, Proofpoint, and E5 licensing security features will be crucial in maintaining a robust security framework. You will...


  • Boston, United States The Computer Merchant, LTD. Full time

    JOB TITLE: Information Security Engineer JOB LOCATION: Boston, MA WAGE RANGE*: 60 - 67/ hour JOB NUMBER: 33818687 REQUIRED EXPERIENCE: BA or BS degree in Computer Science, Information Technology or related field preferred. Strong technical knowledge in at least one of the technical domains of information security such as access control systems, firewalls,...


  • Boston, United States InfiCare Technologies Full time

    Job DescriptionJob DescriptionHi There,Hope you are doing great.InfiCare has been providing Contingent Staffing and Direct Hire staffing services to its clients across the US and in four continents Since XX01. Starting from a modest beginning in X001, today we service clients ranging from Fortune X0X companies to medium sized businesses as well as small...


  • Boston, United States Metasys Technologies, Inc. Full time

    Information Security Engineer Boston, MA (hybrid, 3 days onsite) 6+Month Contract This hybrid role requires initial in-office training in the Northeast (several weeks minimum), with subsequent flexibility to work remotely. Typically, the schedule involves three days onsite and two days offsite, based on the manager's discretion. Normal office hours are...


  • Boston, United States Metasys Technologies, Inc. Full time

    Information Security Engineer Boston, MA (hybrid, 3 days onsite) 6+Month Contract This hybrid role requires initial in-office training in the Northeast (several weeks minimum), with subsequent flexibility to work remotely. Typically, the schedule involves three days onsite and two days offsite, based on the manager's discretion. Normal office hours are...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DOThe right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DOThe right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DOThe right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, Massachusetts, United States The Computer Merchant, LTD. Full time

    Job SummaryThe Computer Merchant, LTD. is seeking a highly skilled Cyber Security Operations Specialist to join our team. As a key member of our security operations team, you will be responsible for monitoring and responding to security alerts, reviewing and improving our Splunk SIEM logs, and conducting threat hunting and incident response activities.Key...


  • Boston, United States eTek IT Services, Inc. Full time

    Job DescriptionJob DescriptionRole : Information Security AnalystLocation: Boston, MAExperience : 8+ yearsW2 Contract& Required Skills• Professional certifications such as CISSP, CISM, CRISC, or similar are highly desirable. • Minimum of 3-5 years of experience in information security, risk management, or a related field. • Strong knowledge of security...


  • Boston, United States Rose International Full time

    Date Posted: 08/27/2024Hiring Organization: Rose InternationalPosition Number: 469992Job Title: Information Security GRC AnalystJob Location: Boston, MA, USA, 02116Work Model: HybridEmployment Type: TemporaryEstimated Duration (In months): 10Min Hourly Rate($): 50.00Max Hourly Rate($): 55.00Must Have Skills/Attributes: Compliance, Data Security, Governance,...


  • Boston, United States InvoiceCloud Full time

    Job DescriptionJob DescriptionAbout InvoiceCloud: InvoiceCloud is a leading provider of online bill payment services. Founded in 2009, the company has grown to be one of the leading disruptors in the cloud-based electronic bill presentment and payment (EBPP) space, helping institutions put customer experience first. By switching to InvoiceCloud, clients can...


  • Boston, United States QuEra Computing Inc. Full time

    Summary:This position is responsible for the QuEra cybersecurity posture from an engineering analysis and auditing perspective. In this role its not only critical to support design and implementation of policy and controls but also enforcement and auditing of the organization and staff.Responsibilities:Implementation management and monitoring of IT security...


  • Boston, Massachusetts, United States Northeast Security Full time

    Security Operations Supervisor - All ShiftsNortheast Security is on the lookout for experienced Security Operations Supervisors to oversee our prestigious high-rise class A properties.Compensation: $22.00-$23.50 per hour**Based on Location and Experience**Available Security Supervisor Schedules:Wednesday-Sunday 10:00pm-6:00amMonday-Friday...


  • Boston, Massachusetts, United States Finance Full time

    Exciting Opportunity for Information Security Risk Specialist - Technology Risk ManagementAbout the Company:We are a prominent Financial Institution in search of a skilled Information Security Risk Specialist to become a part of our Technology Risk Management team. Our commitment lies in prioritizing the interests of our clients, employees, communities, and...


  • Boston, MA, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States Overture Partners Full time

    Security Engineer (Hybrid)We are seeking a Security Engineer with a mix of technical and functional skills, who has a strong understanding of both technical security and governance. The ideal candidate will focus on the technical aspects of security while also getting involved with policy where necessary.Key Responsibilities:Manage a variety of day-to-day...