Job description for ITSO Officer at Kyndryl
As an IT Security Officer (ITSO) focusing on Application Security, you will be responsible for securing software development lifecycles, identifying vulnerabilities, and driving security best practices across various tech stacks.
Threat Modeling & Risk Management: Establish comprehensive threat profiles for ongoing application projects; actively identify, quantify, and design remediation strategies for application security risks.
CI/CD & Pipeline Security: Integrate and maintain automated security testing mechanisms within Agile Development processes and DevOps pipelines (utilizing tools like GitLab, GitHub, and Ansible).
Vulnerability Management: Execute static application security testing (SAST) using enterprise tools (e.g., Fortify-on-Demand, SonarQube). Track discovered vulnerabilities and collaborate with engineering teams to ensure timely remediation and patching.
Security Advocacy & Training: Conduct regular security awareness training sessions to foster a security-first culture among development teams.
Stakeholder Collaboration: Interface and collaborate closely with various technical and business stakeholders to communicate security risks and align on deployment goals.
Required Skills and Experience
Experience & Education
Professional Experience: Minimum of 4 years of combined professional experience across software development, application security, and cloud computing environments.
Sector Experience (Preferred): Prior experience working within the Government Commercial Cloud (GCC) environment is highly advantageous.
Technical Skills & Competencies
Architecture & Network: Deep familiarity with mobile and web application programming interface (API) architectures, including REST, SOAP, and SSL/TLS protocols.
Security Frameworks: Strong, practical knowledge of industry-standard security frameworks and best practices, specifically the OWASP Top 10 and the OWASP Application Security Verification Standard (ASVS).
DevOps Ecosystem: Practical understanding of Agile methodologies, DevOps concepts, and version control/automation tooling (e.g., GitLab, GitHub, Ansible).
Soft Skills: Exceptional analytical, troubleshooting, and independent problem-solving skills, paired with strong verbal and written communication abilities.
Preferred Certifications
Valid industry certifications are highly preferred, such as CISSP, OSCP, AWS Certified Security - Specialty, or AWS Certified DevOps Engineer - Professional.
