At least 8 years of hands-on experience in application security or secure software development., Strong knowledge of secure development practices and relevant standards like OWASP Top 10., Ability to communicate technical risks clearly to both technical and non-technical audiences., Experience working in large organizations or government/public sector environments..
Key responsibilities:
Perform application security services including risk assessments and code reviews.
Coordinate with developers and project teams to guide secure software development.
Track and report on security metrics and overall risk trends.
Support the development of policy and governance documents related to software security.
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
Navitas Partners LLC is a diversity led business, headquartered in NJ, as a dynamic IT professional services and workforce solutions company. We believe creating the best solutions in human resource services means always going above and beyond - and people are our most important asset. Our “DNA”
invokes core values of knowing, trusting and serving our relationships. The better we know our clients and candidates, the better our relationship, and the better we match the needs and exceed expectations. We want our client’s experience with us to reflect a transparent, professional and driven relationship.
At Navitas Partners we strive for Excellence in People, and grow with you to become a true extension of your HR specific business requirements, while remaining sensitive to your price & business needs.
Certified Diversity Employer: SBE • WOSB • WBE • MBE • NMSDC
NAICS: 541511, 541512, 541513, 541519, 54164, 518210, 811212, 561320
https://form.jotform.com/223145471243247
Title: Cyber Command Software Security Assurance Project Manager 3 - PM3
Location: Remote, NY
Duration: 2 Years
Job Description:
Client seeks a Software Security Assurance Project Manager to support the adoption of secure-by-design practices into gencies' software development lifecycle through our Software Security Assurance Program (SSAP).
TASKS:
Perform application security services including risk assessments, architecture reviews, and code review for internal and third-party applications
Coordinate with developers, project teams, and third-party vendors to assess and guide secure software development and integration
Provide consultative guidance during design, development, and deployment phase of new solutions
Review threat models, validate security controls, and ensure alignment with security policies
Review and interpret security testing reports and vulnerability findings, and assist with risk remediation strategies
Contribute improvements in existing AppSec process, workflows, and documentation
Participate in defining and expanding secure software development lifecycle practices across the organization
Support the development and refinement of policy and governance documents related to software security
Track and report on security metrics, status of findings, and overall risk trends
Support management of tools, resources, and schedules for security testing
MANDATORY SKILLS/EXPERIENCE Note: Candidates who do not have the mandatory skills will not be considered:
At least 8 years of hands-on experience in application security, secure software development, or security consulting
Experience conducting security reviews (code, design threat modeling, architecture) for modern applications (web, mobile, cloud-native)
Strong knowledge of secure development practices, OWASP Top 10, and relevant standards
Ability to communicate technical risks and recommendations clearly to technical and non-technical audiences
Familiarity with tools used in code analysis, vulnerability scanning, and security testing
Experience working cross-functionally with developers, engineers, and product teams.
Experience working within or alongside DevOps/CI-CD environments
Familiarity with container security, API security, and cloud-native application architectures (AWS, Azure, GCP)
Experience supporting security governance or policy development
Experience with risk exception processes or helping define security risk tolerances
Experience in large, complex organizations or government/public sector environments
Experience with third-party risk assessments, vendor management, or SaaS reviews
Required profile
Experience
Spoken language(s):
English
Check out the description to know which languages are mandatory.