Dear Associates,
Position: Cyber Command Software Security Assurance Project Manager – Lev.3
Client Location: New York, NY
Work Location: Remote (Must work on EST time zone)
Duration: 24 months (35 hours/week)
Rate: Quote Your Best
Resource Must provide Three (3) Professional References ; Work Authorization & Valid Photo ID
Work Authorization MUST BE valid Till December 2027 (no exceptions on this)
Scope of Services:
- Perform application security services including risk assessments, architecture reviews, and code review for internal and third-party applications.
- Coordinate with developers, project teams, and third-party vendors to assess and guide secure software development and integration.
- Provide consultative guidance during design, development, and deployment phase of new solutions.
- Review threat models, validate security controls, and ensure alignment with security policies.
- Review and interpret security testing reports and vulnerability findings, and assist with risk remediation strategies.
- Contribute improvements in existing AppSec process, workflows, and documentation.
- Participate in defining and expanding secure software development lifecycle practices across the organization.
- Support the development and refinement of policy and governance documents related to software security.
- Track and report on security metrics, status of findings, and overall risk trends.
- Support management of tools, resources, and schedules for security testing
Must have Skills:
- At least 12-15 years of hands-on experience in application security, secure software development, or security consulting.
- Experience conducting security reviews (code, design threat modeling, architecture) for modern applications (web, mobile, cloud-native).
- Strong knowledge of secure development practices, OWASP Top 10, and relevant standards.
- Ability to communicate technical risks and recommendations clearly to technical and non-technical audiences.
- Familiarity with tools used in code analysis, vulnerability scanning, and security testing.
- Experience working cross-functionally with developers, engineers, and product teams.
- Experience working within or alongside DevOps/CI-CD environments.
- Familiarity with container security, API security, and cloud-native application architectures (AWS, Azure, GCP).
- Experience supporting security governance or policy development.
- Experience with risk exception processes or helping define security risk tolerances.
- Experience in large, complex organizations and government/public sector environments.
- Experience with third-party risk assessments, vendor management, or SaaS reviews
Thanks,
Ram M.
Global IT Solutions USI Inc.
Phone: (718) 676-9625 Ext. 205
Mobile: (847) 769-0850
Fax : (718) 377-2527
E-mail: r...@gitsus.com
http://www.gitsus.com
An E-Verify Company
Certified Minority-owned Business Enterprise (MBE) – New York City (NYC), New York State (NYS) and The Port Authority of New York & New Jersey (PANYNJ)
Note: We respect your online privacy. This is not an unsolicited e-mail. If you are not interested in receiving our e-mails then please reply with a "REMOVE" in the subject line. All removal requests will be honored ASAP. We sincerely apologize for any inconvenience caused to you.