GRC Application Security Specialist (Contract)
Core
Develop and maintain technology and cybersecurity risk governance while identifying, assessing, and mitigating security vulnerabilities in software applications.
Role type
Senior GRC Application Security Specialist (Contract)
Builds
Robust security posture across the organization's technology landscape, including secure SDLC integration and compliance frameworks.
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC), Application Security
Deliverable
Production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ICT cybersecurity, data security, audit management, governance, risk compliance management, application security, secure coding practices, vulnerability assessment, penetration testing, static/dynamic/manual source code review, OWASP Top 10 remediation, Web Application Scanning Tools, risk treatment strategies, compliance checks, incident reporting, DevOps pipeline security integration, data visualization and analytics
Preferred skills
CISSP, CISM, CISA, Instruction Manual 8, CSA Cybersecurity Code of Practice, JIRA reporting and dashboarding, AI assistant tools in development processes
Technologies
Web Application Scanning Tools, JIRA, DevOps pipelines
Responsibilities
Develop and promote a culture of technology risk governance; Provide subject matter expertise on cybersecurity requirements and compliance; Review and establish ICT policies and process controls; Integrate security tools and processes into DevOps pipelines; Collaborate with developers to remediate application security vulnerabilities; Present management reporting with data analysis and strategic recommendations
Seniority
Senior, hands-on IC