Talent.com
Specialist, Application Security
Specialist, Application SecurityPrudential Financial • Newark, NJ, USA
Specialist, Application Security

Specialist, Application Security

Prudential Financial • Newark, NJ, USA
30+ days ago
Job type
  • Full-time
Job description

Job Classification :

Technology - Information Security

Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career – all while growing your skills and advancing your profession at one of the world’s leading financial services institutions.

Your Team & Role

As an Application Security Specialist on the Attack Surface Management Team, you will partner with other security professionals across the Information Security Office, the Chief Technology Office, and other engineering groups in Prudential to advance Prudential’s application security program and drive Prudential’s risk reduction efforts across the global enterprise.

In this role, you would be responsible for efforts to secure modern applications and ensuring “secure by design” development best practices across all digital assets in alignment with industry standards. You will track and govern risk reduction, work with partner organizations to consult on implementation efforts, mature operational processes and enable automation CI / CD controls for enforcement and monitoring. You will work on significant and unique issues where analysis of situations or data requires an evaluation of intangible variables and may impact future concepts, products or technologies to ensure security of our products and customers!

The ideal candidate will have a deep understanding of modern application architecture, cloud-native security, and DevOps practices. Forward-thinking is required for this role to include focus on how to securely develop systems, enable self-service and incorporate capabilities for Security to scale and defend against evolving threats.

Here is What You Can Expect on a Typical Day

  • Serve as the escalation point for operational and project work from junior team members, providing technical support for security tools and solutions, and implementing assessment and response processes.
  • Utilize AppSec tool and process expertise to resolve complex technical and organizational challenges, bridging gaps between AppSec / DevOps and IT / business teams to ensure resource availability for team goals.
  • Collaborate with leadership to define the future direction of the AppSec program, while maintaining a deep understanding of daily operations to offer informed recommendations.
  • Enhance vulnerability and configuration monitoring for open source, third-party, and proprietary code and applications, integrating security best practices into development and operations.
  • Design, develop, and implement security policies and alerting mechanisms based on SOX and NIST standards, and assist in evaluating new software solutions.
  • Conduct qualitative and quantitative analyses to improve user experience, promoting secure-by-design principles throughout the software development lifecycle.
  • Validate mitigation controls, ensure reporting metrics convey risk posture to leadership, and adapt them as necessary.
  • Revise processes, metrics, and documentation to enhance AppSec program capabilities, providing proof-of-concept exploits to demonstrate exploitability and validate remediation actions.
  • Collaborate with technology peers and business stakeholders to ensure remediation efforts comply with corporate standards, creating technical documentation and SoPs for internal security processes.
  • Work with engineering teams to address application vulnerabilities, developing remediation and mitigation strategies, and define requirements for automation tools to manage application security posture.

The Skills & Expertise You Bring

  • Bachelor of Computer Science or Engineering or experience in related fields
  • Ability to coach others with minimal guidance and effectively leverage diverse ideas, experiences, thoughts and perspectives to the benefit of the organization
  • Experience with agile development methodologies and Test-Driven Development (TDD)
  • Knowledge of business concepts tools and processes that are needed for making sound decisions in the context of the company's business
  • Ability to learn new skills and knowledge on an on-going basis through self-initiative and tackling challenges
  • Excellent problem solving, communication and collaboration skills
  • Applied experience with several of the following :

  • Familiarity with vulnerability and security scanning tools, as well as common vulnerability data sources and frameworks (CVE, CVSS, EPSS, CWE)
  • Experience improving vulnerability management platforms, processes, and assessments
  • Engineering mindset – systems thinking, creative problem solving, deductive reasoning
  • SAST, SCA, DAST, ASPM tools
  • Strong understanding of software composition analysis and SBOMs.
  • Ability to adjust communicate style to the target audience with a proficiency in communicating technical and business risk
  • Experience with common vulnerability feeds from government, vendor, and open-source communities
  • Understanding of threat actors with the ability to articulate how they operate and demonstrate how they subvert common security controls
  • Understanding of the OWASP Top 10. Familiarity with vulnerabilities in 3rd party libraries and remediation
  • Preferred qualifications :

  • Scripting background (Python, PowerShell, Bash, etc.)
  • Understanding of threat actors, with the ability to articulate or demonstrate how they operate and subvert common security controls
  • Knowledge of industry security standards and frameworks (CIS, NIST, PCI DSS)
  • Ability to perform exploit validation and web application penetration testing
  • Agentic AI for Security use cases
  • Leverage diverse ideas, experiences, thoughts, and perspectives to the benefit of the organization
  • GIAC Web Application Penetration Tester (GWAPT)
  • CompTIA Advanced Security Practitioner (CASP+)
  • GIAC Cloud Security Automation (GCSA)
  • IT Security certification beyond intro level certifications, (e.g., GCFA, GCIA, GNFA, GCTI, GREM, GCIH, GCFA, GPEN, OSCP, etc.).
  • Cloud (AWS, Azure, GCP, etc.) Certs
  • Other Security Certifications beyond intro level
  • What we offer you :

    Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $99,700.00 to $148,500.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills.

    Market competitive base salaries, with a yearly bonus potential at every level .

    Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave .

    401(k) plan with company match (up to 4%).

    Company-funded pension plan.

    Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.

    Work / Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.

    Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.

    Employee Stock Purchase Plan : Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period), after one year of service.

    Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance.

    Create a job alert for this search

    Security Application Security • Newark, NJ, USA

    Related jobs
    Security Operations Center Analyst

    Security Operations Center Analyst

    TechBiz Global GmbH • Newark, NJ, US
    Full-time
    At TechBiz Global, we are providing recruitment service to our TOP clients from our portfolio.Security Operations Center Analyst. If you're looking for an exciting opportunity to grow in a innovativ...Show more
    Last updated: 3 days ago
    Operational Excellence Specialist

    Operational Excellence Specialist

    Novartis Group Companies • Millburn, NJ, United States
    Full-time
    This role is based in Millburn, NJ.Novartis is unable to offer relocation support : please only apply if this location is accessible for you. Help reimagine cancer care by shaping how our Radioligand...Show more
    Last updated: 1 day ago • Promoted
    Business Information Security Support

    Business Information Security Support

    VDart Inc • New Brunswick, New Jersey, USA
    Full-time
    Business Information Security Support for Technology Services.Onsite in New Brunswick NJ (5 days / week).Support new implementations by assessing security controls using standard security user storie...Show more
    Last updated: 26 days ago • Promoted
    Director, Platform and Data Security

    Director, Platform and Data Security

    Zelis Healthcare, LLC • Morristown, NJ, United States
    Full-time
    Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers.We serve more than 750 payers, including the top five national health plans, regional hea...Show more
    Last updated: 30+ days ago • Promoted
    Immunology Specialist

    Immunology Specialist

    Syneos Health / inVentiv Health Commercial LLC • New Brunswick, NJ, United States
    Full-time
    You have what it takes : a competitive drive coupled with exceptional sales ability.In this role, you will be responsible for implementing the sales plan by delivering proficient sales presentations...Show more
    Last updated: 21 days ago • Promoted
    Pre-Authorization Specialist - Temporary to hire

    Pre-Authorization Specialist - Temporary to hire

    Jobot • East Brunswick, NJ, US
    Full-time
    Temporary to hire / Full health benefits / $$$.This Jobot Consulting Job is hosted by : Billy Mewton.Are you a fit? Easy Apply now by clicking the "Apply Now" button and sending us your resume.Jobot i...Show more
    Last updated: 30+ days ago • Promoted
    Vice President, Application Cyber Security Specialist

    Vice President, Application Cyber Security Specialist

    CLS Group • Iselin, NJ, United States
    Full-time
    Functional title – Application Security Specialist.Corporate level – Vice President.Report to – Director, Application Security. Location – New Jersey / New York.Expected full-time salary range betwe...Show more
    Last updated: 11 hours ago • Promoted • New!
    Ingredient Compliance Specialist

    Ingredient Compliance Specialist

    Joulé • 07054, NJ, US
    Permanent
    Job Title : Ingredient Compliance Specialist Type : Direct Hire Location : Morris County, NJ (Whippany / Parsippany, NJ) Schedule : Hybrid | 9 : 00 a. Salary : $70,000–$85,000 + performance bonus About the O...Show more
    Last updated: 13 days ago • Promoted
    TECHNICAL APPLICATIONS TRAINING SPECIALIST

    TECHNICAL APPLICATIONS TRAINING SPECIALIST

    Larry Radzely • East Hanover, NJ, US
    Full-time
    Quick Apply
    Technical Applications Training Specialist.Internal and External customers for the company's line of products (instruments, reagents and digital products), providing the customer the highest level ...Show more
    Last updated: 6 days ago • Promoted
    Applications Specialist

    Applications Specialist

    Mirion • Somerset, NJ, United States
    Full-time
    This position provides support for our software products utilized in the Nuclear Medicine industry.They will be involved in extensive customer telephone support, some travel for installations, trai...Show more
    Last updated: 24 days ago • Promoted
    Claim Specialist - Property Field Inspection

    Claim Specialist - Property Field Inspection

    State Farm • West Freehold, NJ, United States
    Full-time
    Being good neighbors - helping people, investing in our communities, and making the world a better place - is who we are at State Farm. It is at the core of how we operate and the reason for our suc...Show more
    Last updated: 23 days ago • Promoted
    Principal Application Security Engineer

    Principal Application Security Engineer

    Selective Insurance • Millburn, NJ, United States
    Full-time
    At Selective, we don't just insure uniquely, we employ uniqueness.Selective's unique position as both a leading insurance group and an employer of choice is recognized in a wide variety of awards a...Show more
    Last updated: 21 days ago • Promoted
    Lead Security Engineer - Application Runtime Protection

    Lead Security Engineer - Application Runtime Protection

    ADP • Roseland, NJ, United States
    Full-time
    Lead Security Engineer - Application Runtime Protection.Unlock Your Career Potential : Global Security Organization at ADP. Do you have a passion for going on the offensive to safeguard critical info...Show more
    Last updated: 24 days ago • Promoted
    Emergency Response Specialist (Hiring Immediately)

    Emergency Response Specialist (Hiring Immediately)

    RWJBH Mobile Health (EMS) • East Brunswick, NJ, US
    Full-time +1
    Location : RWJ Health Network Inc.Department : MH Central BLS Emergency.The above reflects the anticipated hourly wage range for this position if hired to work in New Jersey.The compensation offered ...Show more
    Last updated: 30+ days ago • Promoted
    Immunology Specialist

    Immunology Specialist

    Syneos Health Careers • New Brunswick, NJ, United States
    Full-time
    You have what it takes : a competitive drive coupled with exceptional sales ability.In this role, you will be responsible for implementing the sales plan by delivering proficient sales presentations...Show more
    Last updated: 4 days ago • Promoted
    Analyst - Security Analytics - Consider strong remote candidates

    Analyst - Security Analytics - Consider strong remote candidates

    MILLENNIUMSOFT • Franklin Lakes, NJ, United States
    Remote
    Full-time
    Position : Analyst - Security Analytics.Client : Medical Devices Company.Level of Experience : Senior Level.Employment Type : Contract on W2 (Need US Citizens or GC Holders or GC EAD or OPT or EAD ...Show more
    Last updated: 4 days ago • Promoted
    OT Security Specialist

    OT Security Specialist

    Telescope Recruitment • Somerset, NJ, United States
    Full-time
    Citizenship is required for this position due to the confidential nature of the work.Our employer is a publicly traded industry leader manufacturing premium metal payment cards for the world's top ...Show more
    Last updated: 11 hours ago • Promoted • New!
    Technical Applications Training Specialist

    Technical Applications Training Specialist

    Diagnostica Stago, Inc. • Parsippany, NJ, US
    Full-time
    DSI) is an industry leader in the science of hemostasis and thrombosis.Stago provides the total commitment of global resources and responsiveness, coupled with cutting edge technology and reliabili...Show more
    Last updated: 8 days ago • Promoted