Specialist, Application Security
Pru · New Jersey
📍 Newark, NJ, USAvia workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Pru.
Job Classification:
Technology - Information Security
Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career – all while growing your skills and advancing your profession at one of the world’s leading financial services institutions.
Your Team & Role
As an Application Security Specialist on the Attack Surface Management Team, you will partner with other security professionals across the Information Security Office, the Chief Technology Office, and other engineering groups in Prudential to advance Prudential’s application security program and drive Prudential’s risk reduction efforts across the global enterprise.
In this role, you would be responsible for efforts to secure modern applications and ensuring “secure by design” development best practices across all digital assets in alignment with industry standards. You will track and govern risk reduction, work with partner organizations to consult on implementation efforts, mature operational processes and enable automation CI/CD controls for enforcement and monitoring. You will work on significant and unique issues where analysis of situations or data requires an evaluation of intangible variables and may impact future concepts, products or technologies to ensure security of our products and customers!
The ideal candidate will have a deep understanding of modern application architecture, cloud-native security, and DevOps practices. Forward-thinking is required for this role to include focus on how to securely develop systems, enable self-service and incorporate capabilities for Security to scale and defend against evolving threats.
Here is What You Can Expect on a Typical Day
Serve as the escalation point for operational and project work from junior team members, providing technical support for security tools and solutions, and implementing assessment and response processes.
Utilize AppSec tool and process expertise to resolve complex technical and organizational challenges, bridging gaps between AppSec/DevOps and IT/business teams to ensure resource availability for team goals.
Collaborate with leadership to define the future direction of the AppSec program, while maintaining a deep understanding of daily operations to offer informed recommendations.
Enhance vulnerability and configuration monitoring for open source, third-party, and proprietary code and applications, integrating security best practices into development and operations.
Design, develop, and implement security policies and alerting mechanisms based on SOX and NIST standards, and assist in evaluating new software solutions.
Conduct qualitative and quantitative analyses to improve user experience, promoting secure-by-design principles throughout the software development lifecycle.
Validate mitigation controls, ensure reporting metrics convey risk posture to leadership, and adapt them as necessary.
Revise processes, metrics, and documentation to enhance AppSec program capabilities, providing proof-of-concept exploits to demonstrate exploitability and validate remediation actions.
Collaborate with technology peers and business stakeholders to ensure remediation efforts comply with corporate standards, creating technical documentation and SoPs for internal security processes.
Work with engineering teams to address application vulnerabilities, developing remediation and mitigation strategies, and define requirements for automation tools to manage application security posture.
The Skills & Expertise You Bring
Bachelor of Computer Science or Engineering or experience in related fields
Ability to coach others with minimal guidance and effectively leverage diverse ideas, experiences, thoughts and perspectives to the benefit of the organization
Experience with agile development methodologies and Test-Driven Development (TDD)
Knowledge of business concepts tools and processes that are needed for making sound decisions in the context of the company's business
Ability to learn new skills and knowledge on an on-going basis through self-initiative and tackling challenges
Excellent problem solving, communication and collaboration skills
Applied experience with several of the following:
Familiarity with vulnerability and security scanning tools, as well as common vulnerability data sources and frameworks (CVE, CVSS, EPSS, CWE)
Experience improving vulnerability management platforms, processes, and assessments
Engineering mindset – systems thinking, creative problem solving, deductive reasoning
Experience with industry Assessment Frameworks (OWASP WSTG, PTES, Mitre Att@ck Framework)
SAST, SCA, DAST, ASPM tools
Strong understanding of software composition analysis and SBOMs.
Ability to adjust communicate style to the target audience with a proficiency in communicating technical and business risk
Experience with common vulnerability feeds from government, vendor, and open-source communities
Understanding of threat actors with the ability to articulate how they operate and demonstrate how they subvert common security controls
Understanding of the OWASP Top 10. Familiarity with vulnerabilities in 3rd party libraries and remediation
Preferred qualifications:
Scripting background (Python, PowerShell, Bash, etc.)
Understanding of threat actors, with the ability to articulate or demonstrate how they operate and subvert common security controls
Knowledge of industry security standards and frameworks (CIS, NIST, PCI DSS)
Ability to perform exploit validation and web application penetration testing
Agentic AI for Security use cases
Leverage diverse ideas, experiences, thoughts, and perspectives to the benefit of the organization
GIAC Web Application Penetr
More New Jersey jobs
New Jersey jobs · Browse all locations