Negotiable
Outside
Remote
USA
Summary: The Cyber Command Software Security Assurance Project Manager is a senior-level role requiring extensive experience in application security and secure software development. The position involves conducting security reviews and communicating technical risks to diverse audiences while working in a remote capacity. The candidate must have a strong understanding of secure development practices and experience in cross-functional collaboration within DevOps environments. Familiarity with cloud-native architectures and security governance is also essential.
Key Responsibilities:
- Conduct security reviews (code, design threat modeling, architecture) for modern applications (web, mobile, cloud-native).
- Communicate technical risks and recommendations clearly to technical and non-technical audiences.
- Work cross-functionally with developers, engineers, and product teams.
- Support security governance or policy development.
- Assist in defining security risk tolerances and managing risk exception processes.
- Conduct third-party risk assessments, vendor management, or SaaS reviews.
Key Skills:
- At least 15-20 years of hands-on experience in application security, secure software development, or security consulting.
- Strong knowledge of secure development practices, OWASP Top 10, and relevant standards.
- Familiarity with tools used in code analysis, vulnerability scanning, and security testing.
- Experience working within or alongside DevOps/CI-CD environments.
- Familiarity with container security, API security, and cloud-native application architectures (AWS, Azure, Google Cloud Platform).
- Experience in large, complex organizations and/or government/public sector environments.
Salary (Rate): undetermined
City: undetermined
Country: USA
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: Senior
Industry: IT
- At least 15-20 years of hands-on experience in application security, secure software development, or security consulting.
- Experience conducting security reviews (code, design threat modeling, architecture) for modern applications (web, mobile, cloud-native).
- Strong knowledge of secure development practices, OWASP Top 10, and relevant standards.
- Ability to communicate technical risks and recommendations clearly to technical and non-technical audiences.
- Familiarity with tools used in code analysis, vulnerability scanning, and security testing.
- Experience working cross-functionally with developers, engineers, and product teams.
- Experience working within or alongside DevOps/CI-CD environments.
- Familiarity with container security, API security, and cloud-native application architectures (AWS, Azure, Google Cloud Platform).
- Experience supporting security governance or policy development.
- Experience with risk exception processes or helping define security risk tolerances.
- Experience in large, complex organizations and/or government/public sector environments.
- Experience with third-party risk assessments, vendor management, or SaaS reviews
Please share resumes to