Chief Information Security Officer (83285)

CyberJobs.Com

Reston (VA)

Hybrid

USD 164,000 - 222,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Discretionary bonus
Stock awards

Job summary

Verisign is seeking an experienced application security leader to act as SME across development teams, guiding threat modeling, vulnerability assessments, and remediation. You will own the vulnerability management lifecycle with a focus on SCA, SAST/DAST, and secrets scanning, while coordinating remediation with engineering and leadership.

The role requires 10+ years in IT and 6+ years in application security assessments, with strong OWASP knowledge and experience securing modern architectures.

Qualifications

  • 10+ years’ experience in Information Technology with hands-on development
  • 6+ years conducting application security assessments using COTS/open-source tools
  • Hands-on with software composition analysis, SAST/DAST and secrets scanning
  • Experience leading vulnerability management programs with SLAs and executive reporting
  • Strong knowledge of OWASP Testing Framework and OWASP Top 10
  • Experience with modern software architectures (SPA, microservices, containers)
  • Familiar with AI/LLM security risks and guidance
  • Ability to manage multiple opportunities and teams independently
  • Excellent communication and leadership for senior audiences

Responsibilities

  • Serve as the application security SME for development teams through requirements, design, and architecture phases
  • Lead vulnerability assessments and provide remediation guidance to engineering teams
  • Own vulnerability management lifecycle across toolchain—SCA, SAST/DAST, secrets scanning
  • Review Bug Bounty submissions and provide remediation guidance
  • Track issues against SLAs and elevate overdue items to leadership
  • Guide security testing integration into CI/CD pipelines
  • Review third-party apps against internal security requirements
  • Mentor junior engineers and analysts, provide feedback
  • Contribute to security standards and best practices in the organization
  • Assess AI-integrated apps for risks like prompt injection and data exposure

Skills

Application security
Software development
OWASP Top 10
Security testing tools
Vulnerability management
API security testing
Linux
CI/CD security
Communication leadership
Bug bounty programs

Tools

Burp Suite
Fortify
SCA platforms

Job description

Verisign helps enable the security, stability, and resiliency of the internet. We are a trusted provider of internet infrastructure services for the networked world and deliver unmatched performance in domain name system (DNS) services.

We are a mission focused, values driven company where each individual can contribute to building a stronger, more secure internet. We offer a dynamic and flexible work environment with competitive benefits and the ability to grow your career.

Responsibilities
  • Serve as the application security subject matter expert for development teams during requirement, design, and architecture phases, including application threat modeling for new and significantly changed applications
  • Perform and lead deep dive manual and automated application vulnerability assessments, documenting findings, and provide clear remediation guidance to the responsible engineering teams
  • Own the application security vulnerability management lifecycle across the security toolchain, including software composition analysis, static and dynamic testing, interactive testing, secrets scanning
  • Review and provide remediation guidance for submissions from Verisign’s public Bug Bounty program
  • Track open issues against defined SLAs, follow up with development teams, and elevate overdue items to engineering and InfoSec leadership
  • Provide guidance to support integration of security testing into CI/CD pipelines
  • Review third party and vendor supplied applications against internal security requirements
  • Mentor junior engineers and analysts, review peer work, and provide constructive feedback
  • Contribute to Information Security standards, secure coding guidance, and be an active participant in the broader Verisign technical community
AI And Application Security
  • Assess applications that embed large language models or other AI services for risks such as prompt injection, sensitive data exposure, insecure output handling, and over permissioned agents and integrations
  • Develop and maintain internal guidance for developers using AI coding assistants, including expectations for review, testing, and scanning of AI generated code
  • Evaluate and pilot AI assisted capabilities within the application security workflow such as finding triage, false positive reduction, and remediation guidance
  • Track developments in AI security guidance and standards and translate them into practical internal requirements and guidance
Key Skills And Experience
  • 10+ years’ experience in Information Technology, including hands on application development experience
  • 6+ years’ experience conducting application security assessments using COTS and open-source tooling (Burp Suite, Fortify, or equivalent)
  • Hands-on experience with software composition analysis, dynamic application security testing, and secrets scanning platforms
  • Experience running a vulnerability management program through ticketing and workflow systems, including SLA definition and executive level reporting
  • Strong working knowledge of the OWASP Testing Framework and OWASP Top 10
  • Proficiency in currently accepted software development life cycles and associated standards and procedures
  • Knowledge of current application architectures (Single Page Application, 3 tier, microservices, containerized workloads)
  • Practical familiarity with AI and LLM application security risks and current industry guidance in that area
  • Methodical and organized, able to manage multiple opportunities, projects, and partners concurrently
  • Able to multitask and work independently with minimum supervision to meet firm deadlines
  • Excellent communication, presentation, and leadership skills, including the ability to present to senior technical and non-technical audiences
Preferred Skills And Experience
  • 6+ years software development using Java, C++, Rust, Go and/or scripting languages such as Python or Perl
  • Experience implementing security assessments within a Continuous Integration pipeline
  • Advanced experience with Linux operating systems, high comfort level with working at the command line
  • Understanding of Agile methodologies (Kanban, Scrum, pair programming, etc.)
  • Understanding of DevOps and security integration
  • Experience with API security testing
  • Experience running or supporting a public or private bug bounty program

This position is based in our Reston, VA office and offers a hybrid work schedule.

The pay range is $164,300 - $222,300.

The anticipated annual base salary range for this position is noted above, however, base pay offered may vary depending on job-related knowledge, skills, experience. Verisign offers a discretionary bonus which is based on individual and company performance, and certain roles may be eligible for discretionary stock awards.

Verisign is an equal opportunity employer. That means we recruit, hire, compensate, train, promote, transfer, and administer all terms and conditions of employment without regard to their race, color, religion, national origin, sex, sexual orientation, gender identity, age, protected veteran status, disability, or other protected categories under applicable law.

Additional Information

Our Careers Page

Our Benefits Summary

Verisign in the Community

Staffing agency policy: No fees will be paid for unsolicited resumes submitted to Verisign or our employees by third parties.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Verisign Inc. • Reston (VA)

Hybrid
USD 164,000 - 222,000
Senior Application Security Engineer
Senior Application Security Engineer

Verisign • Reston (VA)

On-site
USD 164,000 - 222,000
Hybrid work schedule
Discretionary bonus
Stock awards
Senior Application Security Engineer
Senior Application Security Engineer

VeriSign, Inc. • Reston (VA), Northern (KY)

Hybrid
USD 164,000 - 222,000
Software Engineer - C++
Software Engineer - C++

Verisign Inc. • Reston (VA)

On-site
USD 136,000 - 184,000
Senior InfoSec Tools Engineer
Senior InfoSec Tools Engineer

VeriSign, Inc. • Reston (VA)

On-site
USD 135,800 - 183,800
Discretionary bonus
Discretionary stock awards
Manager - Information Security Compliance
Manager - Information Security Compliance

Verisign Inc. • Reston (VA)

Hybrid
USD 136,000 - 184,000
Discretionary bonus
Stock awards
Sr Research Engineer
Sr Research Engineer

Verisign • Reston (VA)

On-site
USD 164,300 - 222,300
Manager - Information Security Compliance
Manager - Information Security Compliance

Koitecc Solutions • Reston (VA), Northern (KY)

On-site
USD 136,000 - 184,000
Discretionary bonus
Stock awards
Junior Software Engineer
Junior Software Engineer

Verisign Inc. • Reston (VA)

On-site
USD 89,900 - 121,700
Software Engineer - C++
Software Engineer - C++

Verisign • Reston (VA)

Hybrid
USD 136,000 - 184,000