Application & Web Security Specialist at Dillards

D
Dillards

Application & Web Security Specialist

us flag
United States

On-site

Full Time

#Information Security

#Web

#OOP

#Security

#PCI

#HIPAA

#DAST

#SAST

#Vulnerability Management

#Penetration Testing

Dillards is looking for a Application & Web Security Specialist

Sign up to unlock quick summaries and profile fit assessments

THE OPPORTUNITY

The Application and Web Security Specialist will serve as a security consultant to Web and Application Developers. You will work with developers on identifying security risks within their applications and validating remediation. This role offers the opportunity to build solid relationships throughout the enterprise, with developers and vendors, while learning about the various technologies employed within our organization. There are other opportunities to serve included with this role that relate to other Security disciplines such as Penetration Testing, Vulnerability Management, and Event Correlation.

THE TEAM

The Information Security Team is responsible for the confidentiality of customer and employee information, ensuring the data stored and shared maintains integrity, all while making sure that all of this does not impact the availability of the entire Dillard’s enterprise.

This team is expected to be high-performing. To meet this expectation, the team members are communicative and collaborative, always sharing knowledge and research. Members of this team should be able to understand what is expected of them and adjust on the fly, as priorities may change depending on the company's needs. If you are someone who sets a standard of excellence for yourself and you enjoy working alongside others who set the same standard and who genuinely want each of their peers to succeed, you may be the perfect addition to this team. 

 WHAT YOU WILL DO

  • Inspect and assess current solutions for Web and Application Security risks
  • Architect and implement security controls within the Software Development Lifecycle (SDLC)
  • Hold recurring cadences with development and security leadership to discuss findings and future paths for the company regarding application security posture
  • Participate in vulnerability verification and assist development teams in remediation based on reports from scanners, along with manual penetration testing
  • Conduct penetration tests on code and web environments after every significant modification
  • Ensure security controls comply with applicable laws, regulations, and policies to minimize risk and audit findings
  • Train others in IT on application security concepts and educate developers on risk-based coding, including the OWASP best practices
  • Participate in on-call rotation across the Information Security Team
  • Maintain Software Bill of Materials (SBOM)
  • Secure and monitor all in-house APIs for exploitation

THE SKILLSET

  • Knowledge of web architectures (Apache, WebSphere, CDN, OCP/Docker, Next.JS, React) and ability to read, review, and analyze OOP languages when used in production-ready web applications
  • Understanding of security threats and solutions for applications
  • Experience analyzing risk following regulations, including PCI, HIPAA, Sarbanes-Oxley, and state privacy laws
  • Experience creating processes, procedures, and solutions that reduce technical risk and increase operational efficiency
  • Experience using DAST and SAST tools
  • Ability to work independently and with teams while meeting multiple deadlines
  • Strong interpersonal and communication skills with proven decision-making skills
  • Desire to troubleshoot and lead investigations
  • History of and commitment to ethical behavior and full ethical disclosure

WITHIN 1 MONTH, YOU’LL

  • Be able to handle vulnerability management and remediation
  • Know how to revert a WAF change in the event of a misconfiguration
  • Phishing campaign assistance

WITHIN 2 MONTHS, YOU’LL

  • Handle standard WAF maintenance and speak in recurring meetings with third-party analysts 
  • API vulnerability analysis
  • Configure and create DAST scans/schedules

WITHIN 3 MONTHS, YOU’LL

  • Be able to lead meetings with architects and management 
  • Be available to lead/take on projects
  • Higher-level WAF solutions architecting for complex scenarios
  • Understand software design insecurities outside of standard vulnerabilities

No immigration sponsorship (ex. H-1B, TN, STEM OPT) is available for this position

D

Dillards

3 views

0 applied
Share this job
Copy Permalink
Open roles at Dillards
D
Dillards

Application & Web Security Specialist

us flag
United States

On-site

Full Time

#Information Security

#Web

#OOP

#Security

#PCI

#HIPAA

#DAST

#SAST

#Vulnerability Management

#Penetration Testing

D
Dillards

Digital Production Associate

us flag
United States

On-site

Full Time

#Marketing

#Ecommerce

#Retail

#Data Entry

#Communication

#Microsoft Word

#Microsoft Excel

#Social Media

Discover similar jobs
Tebra logo
Tebra

Security Architect

179k - 204k USD

Remote

Full Time

#Security

#Cloud Security

#Healthcare

#Cloudflare

#GCP

#Kubernetes

#Terraform

#Python

#DevSecOps

#Vertex AI

#BigQuery

#Helm

#Workato

L
Lightdash

Head of Engineering

Remote

Full Time

#Engineering Leadership

#AI

#Developer Experience

#TypeScript

#React

#Node.Js

#SQL

#Docker

#Kubernetes

#GCP

#Architecture

#Security

Doxel logo
Doxel

Director, Product Engineering

Remote

Full Time

#Product Engineering

#Construction

#AI

#Architecture

#Web

#Data Pipelines

#3D Rendering

#Engineering Leadership

#Team Management

Hummingbird logo
Hummingbird

Senior Software Engineer, Infrastructure

Remote

Full Time

#Infrastructure Engineering

#Fintech

#Security

#AWS

#Terraform

#PostgreSQL

#Redis

#Ruby on Rails

#Python

#Docker

#CircleCi

#GraphQL

#TypeScript

Planned Parenthood Federation of America logo
Planned Parenthood Federation of America

Associate Director, Information Security Engineer

Remote

Full Time

#Information Security

#Security Operations

#SIEM

#Splunk

#Security Monitoring

#Vulnerability Assessment

#Incident Response

#SIEM Administration

#Windows Server

#Firewalls

#Networking

Mission Lane logo
Mission Lane

Head of Information Security

216k - 240k USD

Remote

Full Time

#Information Security

#Fintech

#Cybersecurity

#Risk Management

#Cloud Security

#AWS

#GCP

#SIEM

#DevSecOps

#Incident Response

#PCI DSS

#ISO 27001

The Browser Company logo
The Browser Company

Staff Security Engineer

225k - 300k USD

Remote

Full Time

#Security

#Browser Development

#Security Engineering

#Golang

#Swift

#TypeScript

#Python

#Threat Modeling

#Security Architecture

E
Exodus Movement Inc.

Security Engineer

130k - 160k USD

Remote

Full Time

#Security Engineering

#Security

#AI

#Detection Engineering

#Incident Response

#SIEM

#AWS Security

#Scripting Languages

#MITRE

#Threat Modeling

S
ShortStory

Senior Software Engineer, Full Stack

Remote

Full Time

#Full Stack

#Software Engineering

#Retail

#Python

#Web

#Pytest

#AWS

#Kubernetes

#Postgres

#SQL

D
Darkroom

Associate Director, Design

Remote

Full Time

#Growth Marketing

#Design

#Figma

#Brand Design

#Web

#Adobe Photoshop

#Adobe Illustrator

#Project Management

#Team Leadership

#Presentation

#Design Systems

Sword Health logo
Sword Health

Governance, Risk & Compliance Analyst

pt flag
Portugal

Remote

Full Time

#Information Security

#Healthcare Technology

#Compliance

#ISO 27001

#SOC 2

#GDPR

#HIPAA

#Risk Management

#Leadership

#AI

Lumina logo
Lumina

Software Engineer

Remote

Full Time

#Technology

#Web

#Scripting

#AI

#Infrastructure

Unqork logo
Unqork

Senior Application Security Engineer

117k - 160k USD

Remote

Full Time

#Application Security

#Penetration Testing

#Security Engineering

#OWASP Top 10

#Node.Js

#Python

#Burp suite

#OWASP

#SAST

#DAST

#SCA

#Vulnerability Management

E
Equilibrium Labs

Blockchain Engineer

Remote

Contractor

#Blockchain

#Web

#Infrastructure

#Rust

#Go

#TypeScript

#Solidity

#Move

#Cairo

#Cryptography

#Polkadot

#Ethereum

Zushealth logo
Zushealth

Director, Solutions & Forward Deployed Engineering

Remote

Full Time

#Solutions Engineering

#Healthcare

#Engineering

#FHIR

#HL7

#Integrations

#APIs

#Data Pipelines

#ETL

#Snowflake

#HIPAA

#AI Tools

#Automation

Xebia logo
Xebia

Senior DevOps Platform Engineer

Remote

Full Time

#DevOps

#Platform Engineering

#Harness

#Kubernetes

#Terraform

#AWS

#Azure

#GCP

#GitOps

#Observability

#Security

#Ansible

Chainguard logo
Chainguard

Enterprise Business Development Representative

100k - 100k USD

Remote

Full Time

#Business Development

#Enterprise Sales

#Security

#Outbound Sales

#Salesforce

#Outreach

#SalesLoft

#Pipeline Generation

#Stakeholder Engagement

Beghouconsulting logo
Beghouconsulting

IT Analyst

in flag
India

Hybrid

Full Time

#IT

#Life Sciences

#Active Directory

#Security

#Microsoft Office

#VMWare

#Storage

#Backup

#Ticketing

#Windows

#Support

#Networking

P
Paymenttools

Information Security Manager

de flag
Germany

Hybrid

Full Time

#Security

#Payments

#Cloud

#Audit Management

#ISO 27001

#PCI DSS

#Project Management

#Risk Assessment

#Compliance Reporting

#Cloud Native

S
Southern Poverty Law Center

Protective Services Officer

us flag
United States

45k - 45k USD

On-site

Full Time

#Security

#Security Systems

#Executive

#Threat Detection

Your dream job awaits.

Explore exciting opportunities, connect with top employers, and ignite your career.