ROLES & RESPONSIBILITIES
Inspect and assess current solutions on Application Security risks.
Identify security flaws in application code and web configurations, suggest and oversee remediation.
Collaborate to create effective SIEM rules and other tools’ alerts to notify staff of application and web threats and correlate across environments.
Lead the vulnerability practice of scanning code across technology stacks and languages.
Validate risks and vulnerabilities while rating criticality and urgency.
Conduct penetration tests on code and web environments after every significant modification.
Ensure security controls are in compliance with applicable laws, regulations and policies to minimize risk and audit findings.
Train others in IT on application security concepts and educate developers on risk based coding including the OWASP best practices.
Identify areas where IT processes need to be established or improved.
Participate in on-call rotation across the Information Security group.
REQUIRED SKILLS
Authorization to work in the United States without sponsorship.
Knowledge of web architectures (WebSphere, Apache, IIS/IHS, CDN, NFS mounts, ESB, Jenkins, OCP) and application languages (.NET, Groovy, Java, PHP, BASH, Python, AJAX, Ruby on Rails, REST, XML, SOA, HTML, XML, COBOL), and code repositories (GIT, CVS, etc.).
Understanding of security threats and solutions for applications.
Experience analyzing risk in accordance with regulations including PCI, HIPAA, and Sarbanes-Oxley.
Experience creating processes, procedures and solutions that reduce technical risk and increase operational efficiency.
Ability to work independently and in teams, while meeting multiple deadlines.
Strong interpersonal and communication skills with proven decision making skills.
Desire to troubleshoot and lead investigations.
History of and commitment to ethical behavior and ethical full disclosure.
Background in the following areas: cyber security, intrusion detection/prevention, OS architecture, malicious network traffic identification, malicious code detection/prevention, security auditing, security architecture, security awareness education, databases, identity management, PKI, encryption methods/standards, event correlation, authentication services, advanced incident handling and forensics.
Little Rock, AR
Dillard's, Inc. ranks among the nation's largest fashion apparel, cosmetics and home furnishings retailers with annual sales exceeding $6.3 billion. The Company focuses on delivering maximum fashion and value to its shoppers by offering compelling selections complemented by exceptional customer care.
The Company focuses on delivering style, service and value to its shoppers by offering compelling apparel, cosmetics and home selections complemented by exceptional customer care. Dillard’s stores offer a broad selection of merchandise and feature products from both national and exclusive brand sources. The Company operates almost 300 Dillard’s locations and several clearance centers, plus an Internet store at Dillards.com.