VF CORPORATION

Senior Engineer, Application Security

USCA > USA > North Carolina > Greensboro - VFC Full time

Senior Engineer, Application Security: Become the Newest Member of the VF Family

As a member of the Application Security team, you will be a key member of the team looking across the VF Global enterprise looking for threats and vulnerabilities that would potentially or unnecessarily place the company at risk.

Working with the different teams within VF, you will oversee and report findings to the key stakeholders, evaluate and prioritize vulnerabilities and intersect with the risk functional team within cyber and information security.  Responsibilities will include oversight and management of the Bug Bounty and Vulnerability Disclosure Programs at VF.

How You Will Make a Difference: 

  • Create and implement the strategic vision for the company’s Bug Bounty and Vulnerability Disclosure Program
    • Develop policy for both programs
    • Drive continuous improvement in the programs by strategically aligning with organizational goals
  • Mentor and train Application Security team members
  • Ensure Organizational Level Agreements for remediation, as defined by internal policy and standards, are met
  • Serve as a cybersecurity subject matter expert for application development and infrastructure teams
  • Partner with application development teams for secure development process adoption and continuous security posture improvement
  • Participate in Red Team exercises to simulate real-world attacks, identifying potential gaps in security and effectiveness of existing defenses
  • Analyze organization's cyber defense policies and recommend improvements that align with strategic cybersecurity goals
  • Perform threat assessments on application-level and infrastructure components to identify security risks
  • Assist with the Dynamic Application Security Testing(DAST) program as needed
  • Identify metrics and Key Performance Indicators (KPIs) for application security program
  • Support authorized penetration testing on web applications and enterprise network assets as needed
  • Support purple team exercises and breach and attack simulations as needed
  • Perform end-to-end application security reviews to ensure critical information is appropriately protected
  • Assist with incident response activities as needed, particularly around web applications
  • Participate in the creation of effective and efficient processes to drive successful reduction of risk within the organization
  • Lead in the design and implementation of more secure pipelines and update existing ones
  • Research and advocate for new security solutions and technologies
  • Ensure the highest levels of security practices are maintained by VF through projects and implementations
  • Establish communications with associates related to threats, vulnerabilities, processes and security risks across a global landscape
  • Advocate and evangelize the importance of Threat and Vulnerability management within VF and socialize through internal channels

Years of Related Professional Experience: 10+ years

Position Requirements:

  • Proven experience in offensive security, penetration testing, or application security, with a focus on web application security
  • Expert level understanding of web application security vulnerabilities (OWASP Top 10, etc.) and exploits
  • Experience with Red Team and Purple Team exercises, with knowledge of attack simulation tools and methodologies
  • Extensive experience with agile delivery practices
  • Extensive experience integrating security into DevOps practices
  • Extensive experience conducting source code review
  • Experience using static application security testing tools such as Fortify, Checkmarx, Veracode, etc.
  • Extensive experience with dynamic application security testing tools such as AppScan, Invicti, Qualys WAS, BurpSuite, and OWASP ZAP, etc.
  • Familiarity with common enterprise architectures
  • Excellent organizational and communication skills
  • Demonstrated ability to work independently and with others
  • Follows all defined IT standards and processes (i.e. IT Governance, SM&G, Architecture, etc.), and provides input for improvements to the appropriate process owners as needed
  • Maintains a proper balance between business and operational risk

Educational Preferences:

  • A bachelor’s or master’s degree in computer science, information systems or other related field; or equivalent work experience
  • Relevant certifications (CISSP, CSSLP, OSCP, OSWE, eWPT, PWPP etc.)

Special Physical and/or Mental Requirements: 

  • Travel by air and overnight, as required 10% amount of time.

Hiring Range:

$116,000.00 USD - $145,000.00 USD annually

Incentive Potential: This position is eligible for additional compensation awards that may include an annual incentive plan, sales incentive, or commission potential. Specific details of the additional compensation eligibility for this position will be provided during the recruiting and interview process.

Benefits at VF Corporation: You can review a general overview of each benefit program offered, including this year's medical plan rates on www.MyVFbenefits.com  and by clicking Looking to Join VF? Detailed information on your benefits will be provided during the hiring process.

Please note, our hiring ranges are determined and built from market pay data. In determining the specific compensation for this position, we comply with all local, state, and federal laws.

At VF, we value a diverse, inclusive workforce and we provide equal employment opportunity for all applicants and employees. All qualified applicants for employment will be considered without regard to an individual’s race, color, sex, gender identity, gender expression, religion, age, national origin or ancestry, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, genetic information, military or veteran status, or any other basis protected by federal, state or local laws. If you require accommodations during the application process, please contact us at peopleservices@vfc.com. VF will provide reasonable accommodations for qualified individuals to the extent required by applicable law.

Pursuant to all applicable local Fair Chance Ordinance requirements, including but not limited to the San Francisco Fair Chance Ordinance, VF will consider for employment qualified applicants with arrest and conviction records.