November 23, 2024
Electric Energy Jobs

Cybersecurity Advisor – Application Security Engineering [HYBRID]

Organization:
Southern California Edison
Region:
Canada, California, Rosemead
End of contest:
December 22, 2024
Type:
Full time
Category:
Information technology (it)
Description
Job Description

Join the Clean Energy Revolution

Become a Cybersecurity Advisor -  Application Security Engineering at Southern California Edison (SCE) and build a better tomorrow. In this job, you will serve as a member of our Cybersecurity Technology & Engineering Team.

You will be responsible for ensuring the security of our organization's software applications. You will work closely with development teams to identify and remediate security vulnerabilities throughout the software development lifecycle. Your role will involve conducting security assessments, implementing security controls, and providing guidance on secure coding practices. Additionally, you will collaborate with multi-functional teams to enhance the overall security posture of our applications and mitigate potential risks.

As a Cybersecurity Advisor - Application Security Engineering, your work will help power our planet, reduce carbon emissions and create cleaner air for everyone. Are you ready to take on the challenge to help us build the future?

A day in the life - Get ready to think big, work smart and shine bright!

  • Perform security assessments of software applications to identify vulnerabilities and weaknesses.
  • Develop and implement security controls to mitigate risks and protect sensitive data.
  • Conduct code reviews to identify security flaws and recommend remediation strategies.
  • Work closely with development teams to integrate security best practices into the software development lifecycle.
  • Design and implement secure authentication, authorization, and encryption mechanisms.
  • Collaborate with multi-functional teams to define security requirements and ensure compliance with industry standards and regulations.
  • Provide security guidance and training to development teams on secure coding practices and techniques.
  • Investigate and respond to security incidents, including conducting forensic analysis and implementing corrective actions.
  • Stay informed about the latest cybersecurity threats, trends, and technologies to continuously improve security measures.
  • Participate in security architecture reviews and provide recommendations for enhancing the security of applications and infrastructure.
  • A material job duty of all positions within the Company is ensuring the protection of all its physical, financial and cybersecurity assets, and properly accessing and managing private customer data, proprietary information, confidential medical records, and other types of highly sensitive information and data with the highest standards of conduct and integrity.

The essentials

  • Seven (7) or more years of experience in Information Technology, Information Security, Software Development, or Cybersecurity. 
  • Four (4) or more years of experience in Cybersecurity. 
  • Experience in application security, including conducting security assessments, code reviews, and implementing security controls.
  • Experience and solid understanding of secure software development practices, including knowledge of common vulnerabilities such as OWASP Top 10, Verification frameworks such as OWASP ASVS, and Software maturity models such as OWASP SAMM
  • Experience with web application firewalls, penetration testing tools, vulnerability scanning tools, application analysis tools (SCA, SAST, DAST), and threat assessment tools.
  • Experience and proficiency in programming/scripting languages such as JavaScript, Java, Python, PowerShell, Bash and C#, with the ability to analyze and debug code for security issues.
  • Superb communication and collaboration skills, with the ability to work effectively with multi-functional teams.
  • Strong analytical and problem-solving abilities, with a keen attention to detail.

The preferred 

  • Bachelor's degree or higher in Computer Science, Information Technology, or related field.
  • Professional certifications such as\: Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Information Security Manager (CISM), Certified Secure Software Lifecycle Professional (CSSLP), Certified Application Security Engineer (CASE), Certified Application Security Professional (CASP+), Offensive Security Certified Professional (OSCP), Certified Web Application Defender (GWEB) and/or any other relevant certifications.
  • Experience with secure coding standards such as CWE/SANS Top 25.
  • Experience and working knowledge of cloud security principles and cloud platforms such as AWS, Azure, and GCP.
  • Strong understanding of basic communications protocols and networking
  • Experience and working knowledge of containers and container platforms

You should know 

  • This position's work mode is hybrid. The employee will report to an SCE facility for a set number of days with the option to work remotely on the remaining days. Unless otherwise noted, employees are required to reside in the state of California. Further details of this work mode will be discussed at the interview stage. The work mode can be changed based on business needs.
  • Visit our Candidate Resource page to get meaningful information related to benefits, perks, resources, testing information, hiring process, and more!
  • Relocation does not apply to this position.
  • The primary work location for this position is Rosemead, CA however, the successful candidate may also be asked to work for a period out in the field throughout the SCE service territory.
  • Position may require up to 5 - 10% traveling between alternate SCE work location sites.
  • This position has been identified as a NERC/CIP impacted position - Prior to being hired, the successful candidate must pass a Personnel Risk Assessment (PRA) or Background Investigation. Once hired, the candidate must complete specified training prior to gaining un-escorted access to assigned work location and performing necessary job duties.
  • Candidates for this position must be legally authorized to work directly as employees for any employer in the United States without visa sponsorship.
  • US Citizenship required as part of Critical Infrastructure security protocols.
  • Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

Read the full posting.

Contact

Southern California Edison

P.O. Box 800

Rosemead

California États-Unis

www.sce.com