POSITION SUMMARY:
IPG is seeking a Software Security Architect to join the CISO group. The individual will be responsible for program management of the application security program including setting strategy and leading adoption of secure software development lifecycle (S-SDLC) program across IPG and its agencies. Preference is given to candidates with a background in software development and a strong understanding of software development lifecycle. The ideal candidate is a good communicator, persuasive, analytical, understands risk and is knowledgeable in application development. This is a position where the right candidate can build a world class software security organization.
ESSENTIAL FUNCTIONS:
Lead software security program strategy based on business needs
Evangelize the adoption of secure software development lifecycle methodology across enterprise
Manage implementation and adoption of centralized application security services.
Lead the assessment, metrics, and reporting of software security risk across IPG’s application portfolio
Chair the global software security working group
Act as primary point of contact for software security questions and mentoring for security champions
Engage with third party venders to deliver software security tools and services
Strong knowledge of or the ability & interest to learn common software risks (such as OWASP top 10)
Familiarity with threat modeling, software composition analysis, and vulnerability disclosure programs
EDUCATION, SKILLS AND EXPERIENCE REQUIREMENTS:
Bachelor of Science in Computer Information Systems, Computer Science, Information Systems Management, related field or equivalent work experience
6+ years of combined hands-on experience in software development, application engineering, and hosted applications.
Information Security certification or equivalent desired
Knowledge of NIST-800 and Cloud Information Security (CIS).Strong understanding of development methodologies, particularly Agile and DevOps.
Familiarity with static and dynamic application security, penetration testing and vulnerability assessment tools, such as Veracode, Checkmarx, Burp Suite and WPscan
Familiarity with API standards and implementation (OAuth, JWT, JWYKey, Public key encryption, OpenId).
Experience working with development technologies such as Microsoft .NET (C#), ASP.NET/MVC, WCF/Web API/REST, JavaScript frameworks, HTML+CSS3+Javascript.
Able to explain impact of vulnerabilities and mitigating strategies to application development teams.
Good oral and written communication skills
BENEFITS OF JOINING IPG:
One of our primary goals is to support the health and well-being of you and your family. Our compensation plan includes the following benefits, in addition to many others:
Healthcare Options
Medical
Dental
Vision
Prescription
Dependent and Health Care Flexible Spending Accounts
401(k) savings plan with company match
Flexible based Paid Time Off
Employee Assistance Program
Legal Assistance Plan
Tuition Reimbursement
Employee Stock Purchase Plan
Exclusive discounts on cell phones, gyms, and everyday purchases
New York, New York
Interpublic group is a global provider of marketing solutions. Through our 54,000 employees in all major world markets, our companies specialize in consumer advertising, digital marketing, communications planning and media buying, public relations and specialty marketing.
IPG agencies create customized marketing programs for many of the world's largest companies through our comprehensive global services. The work our agencies produce helps clients build brands, increase sales of their products and services and gain market share.
The work we provide clients is specific to their unique needs. Our solutions vary from project-based activity involving one agency to long-term, fully integrated campaigns created by multiple IPG agencies working together. With offices in over 100 countries, we can operate in a single region, or deliver globally integrated programs.
The role of our holding company is to provide resources and support to ensure that our agencies can best meet clients’ needs. Based in New York City, our holding company sets company-wide financial objectives and corporate strategy, establishes financial management and operational controls, guides personnel policy, directs collaborative inter-agency programs, conducts investor relations, provides enterprise risk management and oversees mergers and acquisitions. In addition, we provide limited centralized functional services that offer our companies operational efficiencies, including accounting and finance, executive compensation management and recruitment assistance, employee benefits, marketing information retrieval and analysis, internal audit, legal services, real estate expertise and travel services.