AbbVie Inc

Senior Application Security Specialist


PayCompetitivo
LocationLake County/Illinois
Employment typeOther

This job is now closed

  • Job Description

      Req#: 62029390784

      AbbVie Information Security is looking for a highly motivated, diligent, and skillful analyst to join the Attack Surface Management (ASM) team. AbbVie’s Application Security team protects AbbVie’s patients, data, and brand by identifying vulnerabilities and threats to our organization and working to drive remediation of identified security risks. Application Security is a capability of ASM within the larger Cyber Security Operations (CSO) function. Join us as Senior Security Specialist, Application Security to support and improve our efforts to identify and reduce AbbVie’s attack surface and help our business continue to have remarkable impacts on people’s lives.

      The Senior Security Specialist is a key member of the Application Security team and works with internal and external groups to identify and drive remediation of information security risks across all AbbVie application environments.

      The ideal candidate must have prior experience conducting manual web and mobile application security penetration tests within an enterprise environment and working with application stakeholders to discuss vulnerabilities and remediation options.

      In this role, you’ll be responsible for:

      • Maintaining awareness of the latest critical information security vulnerabilities, threats, and exploits
      • Providing guidance on existing and emerging threats in the web and mobile application space, as they apply within the AbbVie environment
      • Performing application security reviews throughout the application development lifecycle, including tasks such as:
        • Performing security assessments for AbbVie web and mobile applications across the enterprise
        • Dynamic (DAST) application security testing and/or penetration testing of applications and source code
        • Auditing results of security assessments with development and/or security teams and offering plans for remediation of vulnerabilities
        • Retesting remediation to confirm the efficacy of fixes
      • Reviewing deliverables from third-party service providers and other Application Security Analysts to ensure completeness and accuracy
      • Communicating technical application security concepts to customers, including developers, architects, and managers
      • Participating in the management of AbbVie’s bug bounty program, working to validate and triage reported vulnerabilities, and working with application owners to ensure valid findings are remediated
      • Training customer staff on application security and remediation of application security code defects
      • Identifying and developing secure software development best practices
      • Identifying enhancements to tools, standards, and processes; providing input into policies and procedures, and contributing to the implementation and refinement of the strategy for the Application Risk program on a global basis

      Tools and skills you will use in this role:

      • Web and mobile application penetration testing tools
      • Security information and event management (SIEM) tools (Chronicle, Splunk, ELK, etc.)
      • Attack surface management solutions (Falcon, Tenable, Shodan, Censys, etc.)

      Experiences that make you a strong candidate for this role:

      Required:

      • Minimum of 8 year's Information Security experience or equivalent experience in Information Risk Management.
      • Advanced knowledge of web application vulnerabilities and web application business logic flaws and threats
      • Advanced understanding of application architectures and technologies, including web applications, mobile technology, data encryption, and identity and access management
      • Advanced, hands-on experience with manual vulnerability testing and static code analysis
      • Advanced experience with tools including, but not limited to, Kali Linux platform and built-in tools, Burp Suite, and OWASP ZAP. Burp or Zap expertise must focus on manual testing rather than automated scanning.
      • Advanced understanding of security controls such as Authentication, Authorization, Access Control, Cryptography, and Network Protocols along with security standards: OWASP Top 10, SANS 25, NIST, and CVE
      • Written and verbal communication skills are critical
      • Communicating concepts to diverse audiences with varying skill sets is vital

      Beneficial:

      • Certifications such as OSCP, OSWE, or ECSA

      If you believe you’re a great fit for this job but don’t have all of the experiences listed above, we encourage you to apply anyway!


      AbbVie is committed to operating with integrity, driving innovation, transforming lives, serving our community, and embracing diversity and inclusion. It is AbbVie’s policy to employ qualified persons of the greatest ability without discrimination against any employee or applicant for employment because of race, color, religion, national origin, age, sex (including pregnancy), physical or mental disability, medical condition, genetic information, gender identity or expression, sexual orientation, marital status, status as a protected veteran, or any other legally protected group status.


  • About the company

      AbbVie is an American publicly traded biopharmaceutical company founded in 2013.

Notice

Talentify is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Talentify provides reasonable accommodations to qualified applicants with disabilities, including disabled veterans. Request assistance at accessibility@talentify.io or 407-000-0000.

Federal law requires every new hire to complete Form I-9 and present proof of identity and U.S. work eligibility.

An Automated Employment Decision Tool (AEDT) will score your job-related skills and responses. Bias-audit & data-use details: www.talentify.io/bias-audit-report. NYC applicants may request an alternative process or accommodation at aedt@talentify.io or 407-000-0000.