Unknown Company

Application & Web Security Specialist

little rock, ar • Posted 1 weeks ago
Onsite Full Time General

Application & Web Security SpecialistLittle Rock, ARThe OpportunityThe Application and Web Security Specialist will serve as a security consultant to Web and Application Developers. You will work with developers on identifying security risks within their applications and validating remediation. This role offers the opportunity to build solid relationships throughout the enterprise, with developers and vendors, while learning about the various technologies employed within our organization.

There are other opportunities to serve included with this role that relate to other Security disciplines such as Threat Security, Vulnerability Management, and Event Correlation.The TeamThe Information Security Team is responsible for the confidentiality of customer and employee information, ensuring the data stored and shared maintains integrity, all while making sure that all of this does not impact the availability of the entire Dillard's enterprise.This team is expected to be high-performing. To meet this expectation, the team members are communicative and collaborative, always sharing knowledge and research. Members of this team should be able to understand what is expected of them and adjust on the fly, as priorities may change depending on the company's needs.

If you are someone who sets a standard of excellence for yourself and you enjoy working alongside others who set the same standard and who genuinely want each of their peers to succeed, you may be the perfect addition to this team.What You Will DoInspect and assess current solutions for Web and Application Security risksArchitect and implement security controls within the Software Development Lifecycle (SDLC)Hold recurring cadences with development and security leadership to discuss findings and future paths for the company regarding application security postureParticipate in vulnerability verification and assist development teams in remediation based on reports from scanners, along with manual application security testingConduct application security testing on code and web environments after every significant modificationEnsure security controls comply with applicable laws, regulations, and policies to minimize risk and audit findingsTrain others in IT on application security concepts and educate developers on risk-based coding, including the OWASP best practicesParticipate in on-call rotation across the Information Security TeamEnsure applications maintain a Software Bill of Materials (SBOM) for each applicationSecure and monitor web applications using the web application firewallSecure and monitor all in-house APIs for exploitationImplement security solution(s) for securing AI systems across the environmentCollaborate with AI/ML teams to ensure AI securitySecure and monitor all in-house AI applications for risk and exploitationThe SkillsetKnowledge of web architectures (Apache, WebSphere, CDN, OCP/Docker, Next.JS, React) and ability to read, review, and analyze OOP languages when used in production-ready web applicationsUnderstanding of security threats and solutions for applicationsExperience analyzing risk following regulations, including PCI, HIPAA, Sarbanes-Oxley, and state privacy lawsExperience creating processes, procedures, and solutions that reduce technical risk and increase operational efficiencyExperience using DAST and SAST toolsExperience navigating and monitoring web application traffic through the web application firewallExperience using AI tools for creating and implementing agentic solutionsExperience with LLMs, generative AI systems, or LLM-based applicationsExperience implementing guardrail solutionsHands-on experience with assessing risk and security testing AI systems for OWASP Top 10 for LLMsAbility to work independently and with teams while meeting multiple deadlinesStrong interpersonal and communication skills with proven decision-making skillsDesire to troubleshoot and lead investigationsHistory of and commitment to ethical behavior and full ethical disclosureLocation & Hours: This is a full-time, on-site position located at our Little Rock, Arkansas headquarters. A high level of attendance is required as an essential function of this position.No immigration sponsorship (ex. H-1B, TN, STEM OPT) is available for this position

Back to Job Search