Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Kaiser Permanente

IS Consultant III, Application Security

Career Insights for Vulnerability Analyst / Penetration Tester

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on North Carolina data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.

$118,018 / year median in North Carolina

+8% projected growth

Explore Career

Job Description

Tech Summary:
The IS Consultant III, Application Security position is a hands-on technical role responsible for supporting application security assessments and secure software development practices under the guidance of senior application security consultants. The role performs source code reviews, manual and automated security testing, vulnerability assessments, and security test data analysis for moderately complex technology initiatives. The consultant works with developers, DevOps teams, technology risk teams, and business stakeholders to integrate application security services, validate security findings, provide remediation guidance, and communicate risks to technical and nontechnical audiences. The role also supports continuous application assessment, security tool adoption, standardized security processes, metrics, reporting, and ongoing improvements across assigned business domains.
Job Summary:
In addition to responsibilities listed below, this position is responsible for reviewing application source code for potential security vulnerabilities under the guidance of more senior application security consultants by performing manual and automated security testing on applications in a running state (DAST); working with DevOps teams to integrate application security services; training DevOps personnel and developers to use application security tools; working one-on-one with developers to help them understand security vulnerabilities at hand and to identify/suggest remediation plans; and recommending application security training paths. This also includes responsibility for protecting applications in production by enrolling them for continuous assessment of existing and emerging threats, evaluating web application firewalls; tuning WAF rules; reviewing alerts; and identifying issues as appropriate.
Essential Responsibilities:
Completes work assignments by applying up-to-date knowledge in subject area to meet deadlines; following procedures and policies, and applying data and resources to support projects or initiatives; collaborating with others, often cross-functionally, to solve business problems; supporting the completion of priorities, deadlines, and expectations; communicating progress and information; identifying and recommending ways to address improvement opportunities when possible; and escalating issues or risks as appropriate. Pursues self-development and effective relationships with others by sharing resources, information, and knowledge with coworkers and customers; listening, responding to, and seeking performance feedback; acknowledging strengths and weaknesses; assessing and responding to the needs of others; and adapting to and learning from change, difficulties, and feedback. Effectively communicates investigative findings to non-technical audiences. Works with technology risk teams and business stakeholders to respond to and remediate identified issues, and determine the best approach for improving security posture. Provides recommendations to team or department leadership on how to remediate issues identified through security testing processes. Identifies the impact of security test plans on upstream and downstream solution components. Follows established processes to ensure KPI goals are obtained and performance metrics are tracked on an ongoing basis. Supports continuous process improvement by participating in the development, implementation, and maintenance of standardized security tools, templates, and processes across assigned business domain(s). Performs security test data analysis in support of security vulnerability assessment processes, including root cause analysis. Executes the vulnerability assessment and penetration testing plan, methodologies, and standard processes for moderately complex technology initiatives across multiple IT domains by analyzing business and technology requirements. Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems. Generates scheduled reports (e.g., status updates, risk assessment reports, remediation reports) and provides regular security metrics to IT teams as appropriate.
Qualifications:
Minimum Qualifications:
Minimum two (2) years software or application development experience. Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum three (3) years experience in IT or a related field, including Minimum one (1) year in information security, network engineering, or application development. Additional equivalent work experience may be substituted for the degree requirement.
Additional Requirements:
N/A Preferred Qualifications:
Two (2) years software or application development experience. One (1) year experience integrating third-party source code or libraries. One (1) year experience in data modeling and analytics. One (1) year experience working on cross-functional project teams One (1) year experience in data analytics.