Technical Consultant-Application Security
Introduction
A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys. With support from our strategic partners, robust IBM technology, and Red Hat, you’ll have the tools to drive meaningful change and accelerate client impact. At IBM Consulting, curiosity fuels success. You’ll be encouraged to challenge the norm, explore new ideas, and create innovative solutions that deliver real results. Our culture of growth and empathy focuses on your long-term career development while valuing your unique skills and experiences.
Your role and responsibilities
As a Technical Consultant in Application Security, you will guide clients in understanding security challenges, risks, and vulnerabilities in their application landscape. You will apply deep technical expertise to incorporate security measures throughout the Software/Application Development lifecycle.
Your primary responsibilities will include:
• Develop Security Measures: Design and implement security measures throughout the Software/Application Development lifecycle, including Design, Build, and deployment phases, to mitigate security risks and vulnerabilities.
• Analyze Vulnerabilities: Drive Application Security Vulnerability management by analyzing high-risk vulnerabilities, formulating mitigation plans, and minimizing false positives to ensure the security of applications.
• Implement Security Guardrails: Apply expertise in implementing security guardrails during Application Modernization programs on multicloud environments to ensure secure application development and deployment.
• Provide Security Expertise: Offer in-depth knowledge of various Application Security domains, such as Threat Modelling, Secure SDLC, DevSecOps, and Application Security testing, to guide clients in securing their applications.
• Manage Security Risks: Identify and manage security risks and vulnerabilities in clients' application landscapes, providing recommendations for mitigation and remediation.
Required technical and professional expertise
• Application Security Expertise: Experience with incorporating security measures throughout the Software/Application Development lifecycle, including Design, Build, and deployment phases.
• Vulnerability Management: Experience in analyzing high-risk vulnerabilities, formulating mitigation plans, and minimizing false positives to ensure the security of applications.
• Multicloud Security: Experience implementing security guardrails during Application Modernization programs on multicloud environments.
• Application Security Domains: In-depth knowledge of various Application Security domains, such as Threat Modelling, Secure SDLC, DevSecOps, and Application Security testing.
• Security Risk Management: Experience identifying and managing security risks and vulnerabilities in application landscapes, with expertise in providing recommendations for mitigation and remediation.
Preferred technical and professional experience
• Deep Understanding of DevSecOps: Experience with implementing DevSecOps practices to ensure the security of applications throughout the Software/Application Development lifecycle. Knowledge of DevSecOps tools and methodologies is beneficial.
• Familiarity with Multicloud Environments: Experience working with multiple cloud providers, such as AWS, Azure, or Google Cloud, is advantageous. Understanding of cloud security controls and compliance requirements is desirable.
• Threat Modelling Expertise: In-depth knowledge of threat modelling methodologies and tools, such as STRIDE or PASTA, is beneficial. Experience with threat modelling in Agile development environments is advantageous.
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.