Automatic Data Processing Inc logo

Software Supply Chain- Container Application Security Director

Automatic Data Processing Inc
  • Roseland, NJ
    4 days ago

    Job Description

    ADP is hiring a Director, Container Application Security

    This Hybrid role can sit in Alpharetta, GA or Roseland, NJ

    Unlock Your Career Potential: Global Security Organization at ADP. Do you have a passion for going on the offensive to safeguard critical information? As ADP's Global Security Organization (GSO), we know that our clients rely on us for human capital management solutions, but beyond that, they entrust us with one of their most valuable assets - their employee data. We are honored by this trust and are laser focused on securing data at every step in the information lifecycle, ensuring integrity, confidentiality and compliance with industry and government regulations at all times. From the cloud to the data center and across every emerging device, you'll join a team of experts in the GSO who are always staying one step ahead in this ever-changing world of data by continually evolving our strategies and technologies to protect ADP and our clients.

    The mission of the GSO Enterprise Application Security [EAS] team is to protect ADP's internally developed products from existing and emerging security threats. We improve internal product security posture by integrating and automating security controls early in the product development life cycle and aid in uncovering security risks. This work empowers and supports development teams to recognize and address security risks in a timely manner.

    The EAS team has an opening for Software Supply Chain- Container Application Security Director to drive design, implement, and manage the container application security scanning services partnering with key stakeholders and deliver to assess the security risks and establish a governance framework for the secure use of models before released to the production use.

    Like what you see? Apply now!

    Learn more about ADP at tech.adp.com/careers

    What You'll Do:

    • Drive container application security including supply chain risk initiatives across ADP's different business units.
    • Institutionalize the container security scanning of images in line with shift left strategy in DevSecOps.
    • Manage supply chain, container application security vulnerability remediation flow.
    • Develop and maintain the roadmap for container security & supply chain risk.
    • Customize policies, rules, and alerts to comply with established policies and settings.
    • Drive culture around secure application development through effective training, governance, and metrics
    • Bring thought leadership into the program and drive excellence.
    • Manage the project timelines and delivery.
    • Maintain awareness of Kubernetes cybersecurity threats and best practices to enable securing and hardening Kubernetes clusters at scale
    • Metrics/Reporting
    • Identify meaningful KPIs/KRI's to drive progress, improvement & improvement.
    • Create dashboards to monitor significant events, traffic and data collection.
    • Provide weekly Scanning and Monitoring reports.
    • Create weekly, monthly and in-progress review presentations, as needed.
    • Create and maintain Standard Operating Procedures (SOP)
    • Establish strong partnership with key stakeholders in technology and product organizations.
    • Manage communication upwards, downwards, and horizontally.

    Experience You'll Need:

    • Deep knowledge and understanding of container application security vulnerabilities (SANS, OWASP).
    • Candidate should be very thorough in internet technologies and highly versed with web development secure coding best practices.
    • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, Rally, JIRA, Artifactory, Nexus, SonarQube, git, Snyk).
    • Previous software engineering/architecture experience (Java, C#,.Net, JavaScript, Python) preferred.
    • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
    • Strong experience in training development teams on secure coding
    • Ability to communicate security-related concepts to a broad range of technical and non-technical staff.
    • Some experience with development of RESTful and SOAP web services preferred.
    • Understanding of advanced iterative Agile, Cloud and Container Security
    • Familiarity with micro services architecture and design Patterns.

    To Succeed in This Role:

    • You'll need a bachelor's degree in computer science, Information / Cyber Security, Computer Systems Engineering, Computer Information Systems or equivalent experience.

    Qualifications:

    • Ten years or more experience in various IT or cybersecurity roles with 3+ years leadership experience and management in multi-cloud computing and containerized environments, specifically secure operation in Kubernetes
    • Experience leading efforts in Container Application Security programs
    • Deep knowledge and understanding of application security vulnerabilities (OWASP SANS,)
    • Candidate should be very thorough in internet technologies and highly versed with web development best practices.
    • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, Rally, JIRA, Artifactory, Nexus, SonarQube, git)
    • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
    • Understanding of Container Security Scanning, Application Security Test Automation tools and frameworks such as SAST, DAST, IAST, Container Application Security testing, and Burp Suite
    • Ability to communicate security-related concepts to a broad range of technical and non-technical stakeholders.
    • Knowledge in securing cloud deployment and containers (familiarity with Ansible, Chef, DeMisto, Docker, Helm, and/or Kubernetes)
    • Understanding of advanced iterative Agile and container & cloud security
    • Familiarity with micro services architecture and design Patterns
    • Excellent analytic skills, including qualitative and quantitative data analysis to support and defend data-driven decision-making regarding system threats, vulnerabilities, and risk
    • Experience in an enterprise environment orchestrating multiple pods and containers.
    • Hands-on experience with container security tools such as Snyk, Chainguard, Grype, Prisma (Twistlock), or StackRox
    • Experience with other cloud container solutions, such as Docker, Containered, or Rancher
    • Experience configuring disaster recovery (DR) environments.
    • Previous software engineering/architecture experience (Java, C#,.Net, JavaScript) preferred
    • Some experience with development of RESTful and SOAP web services preferred
    • Any of the following are a plus but not necessary: CEH, CISSP, CSSLP, GCIA, GPEN, GWAPT,

    What are you waiting for? Apply today!

    Find out why people come to ADP and why they stay: https://youtu.be/ODb8lxBrxrY

    (ADA version: https://youtu.be/IQjUCA8SOoA )

    Numbers & Facts

    LocationRoseland, NJ
    IndustryManagement Consulting Services
    Company Size10,000 employees or more
    Websitehttps://jobs.adp.com/life-at-adp/

    About Company

    ADP powers the working world with comprehensive solutions that drive business success. Consistently named one of the "Most Admired Companies" by FORTUNE® Magazine, and recognized by Forbes® as one of "The World's Most Innovative Companies," ADP has over a half-million clients around the globe and 65 years of experience as one of the largest providers of human capital management solutions world-wide. At ADP, we believe that diversity fuels innovation. ADP is committed to equal employment opportunities regardless of race, color, genetic information, creed, religion, sex, sexual orientation, gender identity, lawful alien status, national origin, age, marital status, non-job related physical or mental disability, or protected veteran status. We support an inclusive workplace where associates excel based on personal merit, qualifications, experience, ability, and job performance.

    Skills

    • ADPunmatched
    • Agile Programming Methodologiesunmatched
    • Alliance/Partner Managementunmatched
    • Analysis Skillsunmatched
    • Ansibleunmatched
    • Applications Securityunmatched
    • Atlassian JIRAunmatched
    • Best Practicesunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Chef (Configuration Management)unmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Computer Systemsunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Cross-Functionalunmatched
    • Data Analysisunmatched
    • Data Collectionunmatched
    • Design Patterns Programming Methodologiesunmatched
    • Disaster Recoveryunmatched
    • Dockerunmatched
    • Enterprise Protectionunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GPEN - GIAC Penetration Testerunmatched
    • Gitunmatched
    • Government Regulationsunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Internet Technologyunmatched
    • Javaunmatched
    • JavaScriptunmatched
    • Jenkinsunmatched
    • Leadershipunmatched
    • Metricsunmatched
    • Microservicesunmatched
    • Microsoft .NETunmatched
    • Microsoft C# (C Sharp)unmatched
    • Network Operations Centerunmatched
    • Operations Security (OPSEC)unmatched
    • Performance Metricsunmatched
    • Policy Developmentunmatched
    • Problem Solving Skillsunmatched
    • Process Improvementunmatched
    • Product Developmentunmatched
    • Product Lifecycleunmatched
    • Project/Program Managementunmatched
    • Python Programming/Scripting Languageunmatched
    • Quantitative Analysisunmatched
    • REST (Representational State Transfer)unmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • SOAP (Simple Object Access Protocol)unmatched
    • Secure Codingunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Scanning Servicesunmatched
    • Software Developmentunmatched
    • Software Engineeringunmatched
    • Software Testingunmatched
    • Source Code/Configuration Management (SCM)unmatched
    • Standard Operating Procedures (SOP)unmatched
    • Standards Developmentunmatched
    • Supply Chainunmatched
    • Supply Chain Managementunmatched
    • Supply Chain Management Softwareunmatched
    • Systems Engineeringunmatched
    • Talent Managementunmatched
    • Technical Strategyunmatched
    • Test Automationunmatched
    • Test Suiteunmatched
    • Test Toolsunmatched
    • Thought Leadershipunmatched
    • Time Managementunmatched
    • Web Programmingunmatched
    • Web Servicesunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder