Project Manager with Threat Modelling & OWASP

Project Manager with Threat Modelling & OWASP

Posted 3 days ago by 1753864878

Negotiable
Outside
Remote
USA

Summary: The role is for a Project Manager specializing in Threat Modelling and OWASP, focusing on application security and secure software development. This position is remote and is expected to last for over 12 months. The candidate should possess extensive experience in security reviews and be able to communicate technical risks effectively. Familiarity with modern application architectures and security practices is essential for success in this role.

Key Responsibilities:

  • Conduct security reviews including code, design threat modeling, and architecture for modern applications.
  • Communicate technical risks and recommendations to both technical and non-technical audiences.
  • Work cross-functionally with developers, engineers, and product teams.
  • Utilize tools for code analysis, vulnerability scanning, and security testing.

Key Skills:

  • At least 8 years of hands-on experience in application security, secure software development, or security consulting.
  • Strong knowledge of secure development practices, OWASP Top 10, and relevant standards.
  • Familiarity with DevOps/CI-CD environments and container security.
  • Experience with risk exception processes and security governance.

Salary (Rate): undetermined

City: undetermined

Country: USA

Working Arrangements: remote

IR35 Status: outside IR35

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

Not a Regular Project Manager role!!!

Project Manager with Threat Modelling an OWASP Remote 12+ Months Long Term

Mandatory Skills:
At least 8 years of hands-on experience in application security, secure software development, or security consulting
Experience conducting security reviews (code, design threat modeling, architecture) for modern applications (web, mobile, cloud-native)
Strong knowledge of secure development practices, OWASP Top 10, and relevant standards
Ability to communicate technical risks and recommendations clearly to technical and non-technical audiences
Familiarity with tools used in code analysis, vulnerability scanning, and security testing
Experience working cross-functionally with developers, engineers, and product teams

Desirable Skills:
Experience working within or alongside DevOps/CI-CD environments
Familiarity with container security, API security, and cloud-native application architectures (AWS, Azure, Google Cloud Platform)
Experience supporting security governance or policy development
Experience with risk exception processes or helping define security risk tolerances
Experience in large, complex organizations or government/public sector environments
Experience with third-party risk assessments, vendor management, or SaaS reviews