Haystack
← Back to Jobs
Remote
Other
RI

Job Role: ASC Champions / Location : (Remote) II Contract

Rivago infotech incCharlotte, NC🇺🇸United StatesPosted Sep 30, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
Charlotte, NC, United States
Posted
1 week ago
AWSOWASPSonarQubeAzureCompliance.NETGitHub ActionsGoogle CloudJavaJenkinsKubernetesPenetration TestingPythonRisk ManagementStakeholder ManagementTriage

Job Description

Role : ASC Champions

Location : Charlotte, NC (Hybrid)

Must have : App Security, App Development, Risk, Vulnerability

•     Minimum 10+ years of relevant experience.

•     Strong security and vulnerability expertise across application and infrastructure layers.

•     Proficiency in Application Development, Application Security, and Security Services.

•     Solid understanding of Risk Management, Vulnerability Assessment, and Remediation.

•     Expertise in SDLC (Software Development Lifecycle) and Product Lifecycle Support.

•     Infrastructure and application security knowledge at a senior/lead level.

•     Go-getter attitude with the ability to manage large, complex platform portfolios.

•     Familiarity with CISO organization structure and enterprise security governance.

 

Position Overview

We are seeking highly experienced ASC Champions to join our Application Security Center within a leading financial institution. In this pivotal role, you will act as a security advocate and subject matter expert, bridging the gap between application development teams and enterprise security governance. You will drive the adoption of secure coding practices, champion application vulnerability management, and ensure compliance with the organization's risk frameworks across Lines of Business (LOBs).

 

Key Responsibilities

•     Champion application security best practices across development teams and Lines of Business (LOBs), driving a security-first culture.

•     Lead application security reviews, threat modeling, and code assessments to identify and mitigate vulnerabilities throughout the SDLC.

•     Partner with development, infrastructure, and risk teams to define and enforce security standards and policies.

•     Manage and track application security vulnerabilities, ensuring timely remediation aligned with risk appetite.

•     Conduct security risk assessments and coordinate with Risk and Compliance teams to ensure regulatory adherence.

•     Provide subject matter expertise on application security tools (SAST, DAST, SCA) and integrate them into CI/CD pipelines.

•     Educate and mentor development teams on secure coding practices, OWASP Top 10, and security frameworks.

•     Interface with CISO and senior leadership to report security posture, risk metrics, and remediation progress.

•     Support penetration testing activities and manage findings through to resolution.

•     Collaborate across multiple LOBs, managing stakeholder relationships and security expectations at scale.

 

Required Qualifications

•     10+ years of experience in application security, application development, or related cybersecurity roles.

•     Deep expertise in application security (SAST, DAST, SCA), vulnerability management, and secure SDLC.

•     Strong knowledge of security risk frameworks (NIST, ISO 27001, OWASP, PCI-DSS, SOX).

•     Hands-on experience with application development (Java, Python, .NET, or similar) enabling effective security partnership with dev teams.

•     Demonstrated experience in vulnerability triage, risk scoring (CVSS), and remediation tracking.

•     Familiarity with cloud platforms (AWS, Azure, Google Cloud Platform) and container/Kubernetes security.

•     Excellent stakeholder management and communication skills; ability to influence without direct authority.

•     Experience in financial services or banking industry strongly preferred.

 

Preferred Qualifications

•     Certified Information Systems Security Professional (CISSP), Certified Application Security Engineer (CASE), or CSSLP.

•     Experience working in a large enterprise banking environment with multiple business units.

•     Familiarity with DevSecOps toolchains (Jenkins, GitHub Actions, SonarQube, Veracode, Checkmarx, Snyk).

Similar jobs