|
KEY ACCOUNTABILITIES & ACTIVITIES
This section describes the principal outputs required from the job.
|
|
Key Accountabilities
|
Key Activities
|
- Application Security Assessment
|
- Perform security assessments for applications and digital solutions.
- Evaluate applications against approved security requirements and standards.
- Document identified vulnerabilities, risks, and recommended remediation actions.
|
- Secure Code Review
|
- Conduct security-focused source code reviews to identify vulnerabilities and insecure coding practices.
- Assess code against secure coding standards and common application security risks.
- Provide remediation guidance to development teams.
|
- Threat Modeling
|
- Conduct threat modeling for new and existing applications and services.
- Identify potential attack scenarios, threats, and security control gaps.
- Recommend security controls based on identified risks.
|
- Application Vulnerability Management
|
- Identify, analyze, and assess application-layer vulnerabilities.
- Coordinate with development teams on vulnerability remediation activities.
- Validate remediation and monitor outstanding application security findings.
|
- API & Integration Security
|
- Assess APIs, microservices, and third-party integrations for cybersecurity risks.
- Evaluate authentication, authorization, data protection, and integration controls.
- Recommend appropriate security improvements.
|
- Secure Design & Development Advisory
|
- Provide security guidance to development and engineering teams throughout the development lifecycle.
- Support the application of secure design and development practices.
- Recommend security controls appropriate to solution risks and requirements.
|
- Application Security Standards & Frameworks
|
- Develop and maintain application security standards, guidelines, and technical requirements.
- Support alignment with secure software development practices and applicable cybersecurity standards.
- Evaluate emerging application security practices and recommend enhancements.
|
- Developer Security Awareness
|
- Support secure coding awareness and technical security training for developers.
- Develop security guidance and knowledge materials addressing common application vulnerabilities.
- Promote secure development practices across engineering teams.
|
- Policies, Processes & Procedures
|
- Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.
- Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.
|
- Information Security
|
- Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.
|