Job ID TI-14501City Los AngelesState CaliforniaAdditional Location: Exempt/Non Exempt
INFORMATION SECURITY ENGINEER II
WHAT IS THE OPPORTUNITY?
The Application Security Developer is responsible for addressing legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As security issues are uncovered, the Application Security Developer communicates technical solutions to development teams with a focus on risk mitigation – allowing for business continuity, but without negligent risk.
This position is also responsible for assessing the security of internally developed, third party developed, commercial off the shelf (COTS), and open source software applications. This includes performing architecture reviews to steer projects in the right direction early, participating in security code reviews, and performing penetration testing against products prior to shipping.
Technology and Innovation Division As a member of City National's Technology & Innovation group, you will drive, develop, and maintain solutions for clients and colleagues. This is an exciting time of technology advancement and innovation across the bank, particularly within our technology teams.
WHAT WILL YOU DO?
Lead a range of application security assessment activities such as penetration testing and reviewing SAST and DAST reports
Create threat models and leverage them to prioritize resource allocation
Consult, advise or oversee the secure design and configuration requirements of key application projects to ensure compliance with bank and regulatory standards
Participate in strategic initiatives designed to identify and reduce the attack surface across applications and systems
Develop automated testing scripts and tools
Educate and train application teams on security topics and skills to build strong relationships within the development community
Collaborate with security groups such as red teams, threat intelligence and risk management to form a holistic team dedicated to thwarting attackers and reducing attack surface
WHAT DO YOU NEED TO SUCCEED
Minimum of 3 years’ experience in Information/Cyber Security field
Minimum of 3 years’ experience as an engineer or administrator of enterprise security technology platform
Skills and Knowledge
Full-stack web development experience along with proficiency in common development tools such as Git and IDEs
A strong understanding of CI/CD pipelines and practices
A demonstrated interested in application security vulnerabilities, tools, and exploits
BA/BS Degree or equivalent combination of training and experience
Experience with at least one of the following cloud providers: AZURE, AWS, or GCP
Strong written and verbal communication skills, as well as the ability to work well with a diverse mix of stakeholders
*To be considered for this position you must meet at least these basic qualifications The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
INCLUSION AND EQUAL OPPORTUNITY EMPLOYMENT City National Bank is an equal opportunity employer committed to diversity and inclusion. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status or any other basis protected by law.
ABOUT CITY NATIONAL
We start with a basic premise: Business is personal. Since day one we've always gone further than the competition to help our clients, colleagues and community flourish. City National Bank was founded in 1954 by entrepreneurs for entrepreneurs and that legacy of integrity, community and unparalleled client relationships continues to drive phenomenal growth today. City National is a subsidiary of Royal Bank of Canada, one of North America’s leading diversified financial services companies.
City National Bank requires all colleagues to be fully vaccinated against COVID-19 to work on-site at any of our locations.