Himalayas logo
CofenseCO

Application Security and Compliance Programs Manager

Cofense, formerly PhishMe, is the leading provider of human-driven phishing defense solutions worldwide.

Cofense

Employee count: 201-500

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Reporting to the VP, Info Tech & Security, the Application Security and Compliance Programs Manager is responsible our Compliance Programs & Application Security that ensures Cofense Engineering designs, builds, ships, and operates software securely whilst being responsible for our information security standards.

Essential Duties/Responsibilities

  • Primarily responsible for being single point of contact on all project management activities for FEDRAMP/SOC2/ISO27001 program
  • Own the relationships with the 3PAO, sponsoring agency, and FedRAMP PMO
  • Lead the FedRAMP continuous monitoring (ConMon) activities including the Plans of Actions and Milestones (POA&Ms)
  • Lead the planning, scheduling, and preliminary analysis for all internal and external audits
  • Integrating
security
tools,
standards,
and
processes
into
the
software development
life
cycle
(SDLC).
  • Ensuring
that
software engineers
are
trained
with
the
appropriate
level
of security
knowledge to perform
their daily

  • Improving
and
supporting
application
security
tool deployments
including
static
analysis, dependency/component analysis, and dynamic analysis tools.
  • Improving
and
maintaining
secure
development

  • Supporting
the
incident
response
and
architecture
review
processes
whenever
application
security
expertise
is

  • Managing
annual
penetration
testing
services and application security assessments.
  • Providing
manual
penetration
testing, threat modeling, and gap analysis for Cofense developed applications.
  • Supporting
Vendor
Security
activities
to
ensure
3rd‐party software
and
development
meets Cofense
security

  • Support application security activities related to compliance efforts including FedRAMP/SOC 2/ISO27001.
  • Execute strategic vision for the Application Security program.
  • Other duties as assigned

Knowledge, Skills and Abilities Required

  • FedRAMP industry relationships and knowledge
  • Superb soft skills including the ability to gain the trust of stakeholders and senior management and negotiate priorities with outside teams
  • Working knowledge of public cloud providers (e.g., AWS)
  • Ability to translate
 security
concepts
into
language
that
is
meaningful
to
many
 audiences,
including
business leaders, technical
leaders,
and
individual


  • Ability to approach application
 security
from
the
perspective
of
risk
management
  • Strong
leadership
and technical skills
to effectively
 managers
Application Security engineers.
  • Understanding of deployment methodologies in use for assigned products and projects.
  • Ability to multitask and context-switch across diverse teams and projects.
  • Familiarity with common security libraries, security controls, and common security flaws.
  • Familiarity with cloud security controls and best practices.
  • Excellent verbal and written communication skills.

Education and/or Experience:

  • 5+ years application security experience
  • Experience must demonstrate working knowledge in all phases of preparing and reviewing complete ATO packages for information technology systems and/or applications as defined by the Federal Information Security Modernization Act and implemented by the guidance of the GSA Federal Risk and Authorization Management Program (FedRAMP).
  • Must possess a strong background with
    • NIST Risk Management Framework (SP 800-53)
    • Federal Information Processing Standards (FIPS) 199 and 140
    • DoD Cloud Computing Security Requirements Guide (SRG)
  • Experience load-balancing multiple competing projects at the enterprise level.
  • Bachelor’s degree preferred. Strong preference given for bachelor and advanced degrees in software technology related fields.

- Disclaimer-

The above statements are neither intended to be an all-inclusive list of the duties and responsibilities of the job described, nor are they intended to be a listing of all of the skills and abilities required to do the job. Rather, they are intended only to describe the general nature of the job. This job description is not a contract of employment, either express or implied. Employment with Cofense will be voluntarily entered into and your employment is considered at will. Cofense reserves the right to alter the job description at any time without notice.

Cofense is committed to equal employment opportunity. We will not discriminate against employees or applicants for employment on any legally recognized basis [protected class] including, but not limited to: veteran status, uniform service member status, race, color, religion, sex (including pregnancy), gender identity, sexual orientation, national origin, age, physical or mental disability, marital status, genetic information or any other status or characteristic protected by applicable national, federal, state or local laws and ordinances. We adhere to these commitments in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, and discipline.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Manager

Location requirements

Hiring timezones

United States +/- 0 hours

About Cofense

Learn more about Cofense and their company culture.

View company profile
Cofense, formerly PhishMe, is the leading provider of human-driven phishing defense solutions worldwide. We deliver a collaborative approach to cybersecurity by enabling organization-wide engagement to active email threats. Our collective defense suite combines best-in-class incident response technologies with timely attack intelligence sourced from employees to stop attacks in progress faster and stay ahead of breaches.

From driving awareness to security automation and orchestration, our solutions are designed to anticipate and disrupt the attack kill chain at delivery to quickly mitigate the impacts from spear phishing, ransomware, malware, and business email compromise.

Today this is all made real for thousands of global organizations in the defense, energy, financial services, healthcare, and manufacturing sectors that understand how changing user behavior will improve security, aid incident response, and reduce the risk of compromise.

Employee benefits

Learn about the employee benefits and perks provided at Cofense.

View benefits

Company events

Company-sponsored events and teambuilding events.

Paid parental leave

Paid family leave for all parents to support you and your family.

Flexible working hours

We accommodate all kinds of lifestyles and life stages. Come work on your terms.

Disability insurance

Cofense provides Short Term and Long Term Disability to US employees at no cost.

View Cofense's employee benefits
Claim this profileCofense logoCO

Cofense

Company size

201-500 employees

Founded in

2011

Chief executive officer

Rohyt Belani

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

Remote companies like Cofense

Find your next opportunity by exploring profiles of companies that are similar to Cofense. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan