IT Enterprise Applications Security Lead
United States; Washington, District Of Columbia, United States; Emeryville, California, United States; Chicago, Illinois, United States
Full Time Senior-level / Expert USD 120K - 170K
Berkeley Research Group
BRG is a global consulting firm that helps leading organizations advance in three key areas: economics, disputes, and investigations; corporate finance; and performance improvement and advisory. BRG has offices across the United States and in...
BRG is seeking an experienced and strategic IT Enterprise Application Security Lead to oversee and enhance the security posture of our enterprise SaaS applications, with a strong emphasis on Workday. This role is responsible for defining and implementing application security strategies, policies, and best practices across multiple cloud-based platforms, ensuring compliance, data integrity, and secure operations in alignment with business and regulatory requirements. Key Responsibilities:
- Understand and document security models, controls, and options for all BRG Enterprise Apps, with a specific focus on Workday.
- Lead recurring internal security audits, specifically focused on changes made to our ERP system.
- Maintain strong knowledge of overarching BRG IT Security Policies, Standards, and Procedures.
- Create policies, standards or procedures specific to the operations of these apps that meet or enhance overarching BRG IT Security Policies.
- Partner with Workday administrators, HR, Finance, and IT stakeholders to ensure secure configuration, access controls, and role-based permissions.
- Determine framework for mapping compliance frameworks (NIST, ISO, SOC 2, SOC2, etc) to specific controls within the operations of enterprise applications.
- Documenting and ensuring enforcement of controls unique to the enterprise application suite.
- Organize and lead security remediation efforts identified by audits or other assessments.
- Lead responses to security questionnaires or provide input to questionnaires if the item is related to the security of our Enterprise applications.
- Work with internal and external auditors to demonstrate and provide evidence for controls that are in place.
- Collaborate with identity and access management (IAM) teams to integrate with SSO/MFA and ensure secure user provisioning/deprovisioning.
- Respond to security incidents involving enterprise applications and participate in root cause analysis and incident reporting.
- Stay current with emerging security threats, trends, and best practices in SaaS and enterprise application security.
- Provide leadership and mentoring to junior security staff and cross-functional teams.
- Participate in Change Management.
- Bachelor’s degree in Computer Science, Information Security, related field, or equivalent work experience. Advanced degree or relevant certifications (e.g., CISSP, CISM, GIAC) a plus.
- 5+ years of experience in major information technology functions.
- Strong familiarity with industry frameworks such as SOC2, ISO 27002, HIPAA, HITRUST.
- Familiarity with GDPR and CCPA.
- Experience with enterprise systems or ERP’s. Workday a plus.
- Strong knowledge of application security principles, role-based access control (RBAC), segregation of duties (SoD), and data privacy.
- A self-starter with high levels of drive, energy, resilience, a can-do attitude, and willingness to take the initiative. Ability to operate independently.
- Ability to adjust to changing priorities. Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Excellent written and verbal communication skills. Must have a positive, professional attitude. Experience working with executive level clients. Must be able to communicate complex topics to non-technical audiences. Excellent customer-facing/customer service skills. Excellent organizational skills.
- Position may require infrequent traveling for short periods. Trips will sometimes extend to 5 working days and could on rare occasions extend beyond 5 business days. All travel expenses will be reimbursed.
Job stats:
3
0
0
Category:
Leadership Jobs
Tags: Application security Audits CCPA CISM CISSP Cloud Compliance Computer Science ERP Finance GDPR GIAC HIPAA HITRUST IAM ISO 27002 NIST Privacy SaaS SOC SOC 2 SSO
Regions:
Remote/Anywhere
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Systems Engineer jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSystems Administrator jobsSenior Cybersecurity Engineer jobsCybersecurity Editor jobsCybersecurity Content Editor jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsIT Security Analyst jobsSenior Network Security Engineer jobsChief Information Security Officer jobsSenior Information Security Engineer jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsIT Security Engineer jobsSecurity Specialist jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Cyber Security Engineer jobsCybersecurity Specialist jobsSenior IT Auditor jobsSenior Software Engineer jobs
SaaS jobsEncryption jobsTS/SCI jobsJava jobsCEH jobsSplunk jobsTop Secret jobsThreat detection jobsTerraform jobsIDS jobsSDLC jobsMalware jobsIPS jobsRMF jobsFinance jobsSQL jobsForensics jobsDocker jobsIntrusion detection jobsActive Directory jobsSOC 2 jobsCompTIA jobsOWASP jobsVPN jobsAnsible jobs
ITIL jobsClearance Required jobsTCP/IP jobsCRISC jobsGIAC jobsHIPAA jobsDoDD 8570 jobsIT infrastructure jobsMITRE ATT&CK jobsJira jobsOSCP jobsBanking jobsSOAR jobsData Analytics jobsSOX jobsIndustrial jobsDNS jobsZero Trust jobsCCSP jobsJavaScript jobsUNIX jobsGCIH jobsCISO jobsArtificial Intelligence jobsPolygraph jobs