IT Enterprise Applications Security Lead
United States; Washington, District Of Columbia, United States; Emeryville, California, United States; Chicago, Illinois, United States
Full Time Senior-level / Expert USD 120K - 170K
Berkeley Research Group
BRG is a global consulting firm that helps leading organizations advance in three key areas: economics, disputes, and investigations; corporate finance; and performance improvement and advisory. BRG has offices across the United States and in...
BRG is seeking an experienced and strategic IT Enterprise Application Security Lead to oversee and enhance the security posture of our enterprise SaaS applications, with a strong emphasis on Workday. This role is responsible for defining and implementing application security strategies, policies, and best practices across multiple cloud-based platforms, ensuring compliance, data integrity, and secure operations in alignment with business and regulatory requirements. Key Responsibilities:
- Understand and document security models, controls, and options for all BRG Enterprise Apps, with a specific focus on Workday.
- Lead recurring internal security audits, specifically focused on changes made to our ERP system.
- Maintain strong knowledge of overarching BRG IT Security Policies, Standards, and Procedures.
- Create policies, standards or procedures specific to the operations of these apps that meet or enhance overarching BRG IT Security Policies.
- Partner with Workday administrators, HR, Finance, and IT stakeholders to ensure secure configuration, access controls, and role-based permissions.
- Determine framework for mapping compliance frameworks (NIST, ISO, SOC 2, SOC2, etc) to specific controls within the operations of enterprise applications.
- Documenting and ensuring enforcement of controls unique to the enterprise application suite.
- Organize and lead security remediation efforts identified by audits or other assessments.
- Lead responses to security questionnaires or provide input to questionnaires if the item is related to the security of our Enterprise applications.
- Work with internal and external auditors to demonstrate and provide evidence for controls that are in place.
- Collaborate with identity and access management (IAM) teams to integrate with SSO/MFA and ensure secure user provisioning/deprovisioning.
- Respond to security incidents involving enterprise applications and participate in root cause analysis and incident reporting.
- Stay current with emerging security threats, trends, and best practices in SaaS and enterprise application security.
- Provide leadership and mentoring to junior security staff and cross-functional teams.
- Participate in Change Management.
- Bachelor’s degree in Computer Science, Information Security, related field, or equivalent work experience. Advanced degree or relevant certifications (e.g., CISSP, CISM, GIAC) a plus.
- 5+ years of experience in major information technology functions.
- Strong familiarity with industry frameworks such as SOC2, ISO 27002, HIPAA, HITRUST.
- Familiarity with GDPR and CCPA.
- Experience with enterprise systems or ERP’s. Workday a plus.
- Strong knowledge of application security principles, role-based access control (RBAC), segregation of duties (SoD), and data privacy.
- A self-starter with high levels of drive, energy, resilience, a can-do attitude, and willingness to take the initiative. Ability to operate independently.
- Ability to adjust to changing priorities. Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Excellent written and verbal communication skills. Must have a positive, professional attitude. Experience working with executive level clients. Must be able to communicate complex topics to non-technical audiences. Excellent customer-facing/customer service skills. Excellent organizational skills.
- Position may require infrequent traveling for short periods. Trips will sometimes extend to 5 working days and could on rare occasions extend beyond 5 business days. All travel expenses will be reimbursed.
Job stats:
1
0
0
Category:
Leadership Jobs
Tags: Application security Audits CCPA CISM CISSP Cloud Compliance Computer Science ERP Finance GDPR GIAC HIPAA HITRUST IAM ISO 27002 NIST Privacy SaaS SOC SOC 2 SSO
Regions:
Remote/Anywhere
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsInformation System Security Officer jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSystems Engineer jobsSenior Information Security Analyst jobsCyber Security Specialist jobsSenior Network Security Engineer jobsInformation Security Manager jobsIT Security Analyst jobsChief Information Security Officer jobsIT Security Engineer jobsSecurity Consultant jobsSenior Information Security Engineer jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsInformation Systems Security Engineer jobsSenior Cyber Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsSenior Software Engineer jobsCybersecurity Specialist jobs
EDR jobsSaaS jobsEncryption jobsJava jobsBash jobsTop Secret jobsThreat detection jobsTerraform jobsSplunk jobsRMF jobsIDS jobsSDLC jobsSOC 2 jobsIPS jobsMalware jobsSQL jobsActive Directory jobsCompTIA jobsDocker jobsFinance jobsForensics jobsGIAC jobsIntrusion detection jobsDoDD 8570 jobsITIL jobs
OWASP jobsVPN jobsHIPAA jobsIT infrastructure jobsCRISC jobsAnsible jobsClearance Required jobsTCP/IP jobsCCSP jobsOSCP jobsMITRE ATT&CK jobsData Analytics jobsBanking jobsZero Trust jobsNIST 800-53 jobsJira jobsCISO jobsUNIX jobsEndpoint security jobsSOAR jobsDNS jobsIndustrial jobsPolygraph jobsSOX jobsGCIH jobs