Enable job alerts via email!

IT Enterprise Application Security Lead

BRG

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

BRG is seeking an experienced IT Enterprise Application Security Lead to enhance security posture for SaaS applications, especially Workday. The role involves defining security strategies and policies, leading audits, and collaborating with various teams to ensure compliance and secure operations. A successful candidate will have extensive IT experience, security acumen, and strong communication skills, facing high-pressure environments while demonstrating leadership and initiative.

Benefits

Medical insurance
Vision insurance
401(k)
Paid maternity leave
Paid paternity leave

Qualifications

  • 5+ years of experience in major IT functions.
  • Strong familiarity with compliance frameworks like SOC2 and ISO 27002.
  • Excellent written and verbal communication skills.

Responsibilities

  • Lead application security strategy for enterprise SaaS applications.
  • Conduct security audits focused on ERP systems.
  • Collaborate with multiple departments to ensure security compliance.

Skills

Application Security Principles
Role-Based Access Control (RBAC)
Data Privacy
Compliance Frameworks (NIST, ISO, SOC2)
Security Audits
Cloud Security

Education

Bachelor’s degree in Computer Science, Information Security, or related field
Relevant certifications (e.g., CISSP, CISM, GIAC)

Job description

This range is provided by BRG. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Base pay range

$120,000.00/yr - $170,000.00/yr

BRG is seeking an experienced and strategic IT Enterprise Application Security Lead to oversee and enhance the security posture of our enterprise SaaS applications, with a strong emphasis on Workday. This role is responsible for defining and implementing application security strategies, policies, and best practices across multiple cloud-based platforms, ensuring compliance, data integrity, and secure operations in alignment with business and regulatory requirements.

Key Responsibilities:

  • Understand and document security models, controls, and options for all BRG Enterprise Apps, with a specific focus on Workday.
  • Lead recurring internal security audits, specifically focused on changes made to our ERP system.
  • Maintain strong knowledge of overarching BRG IT Security Policies, Standards, and Procedures.
  • Create policies, standards or procedures specific to the operations of these apps that meet or enhance overarching BRG IT Security Policies.
  • Partner with Workday administrators, HR, Finance, and IT stakeholders to ensure secure configuration, access controls, and role-based permissions.
  • Determine framework for mapping compliance frameworks (NIST, ISO, SOC 2, SOC2, etc) to specific controls within the operations of enterprise applications.
  • Documenting and ensuring enforcement of controls unique to the enterprise application suite.
  • Organize and lead security remediation efforts identified by audits or other assessments.
  • Lead responses to security questionnaires or provide input to questionnaires if the item is related to the security of our Enterprise applications.
  • Work with internal and external auditors to demonstrate and provide evidence for controls that are in place.
  • Collaborate with identity and access management (IAM) teams to integrate with SSO/MFA and ensure secure user provisioning/deprovisioning.
  • Respond to security incidents involving enterprise applications and participate in root cause analysis and incident reporting.
  • Stay current with emerging security threats, trends, and best practices in SaaS and enterprise application security.
  • Provide leadership and mentoring to junior security staff and cross-functional teams.
  • Participate in Change Management.

Job Requirements:

  • Bachelor’s degree in Computer Science, Information Security, related field, or equivalent work experience. Advanced degree or relevant certifications (e.g., CISSP, CISM, GIAC) a plus.
  • 5+ years of experience in major information technology functions.
  • Strong familiarity with industry frameworks such as SOC2, ISO 27002, HIPAA, HITRUST.
  • Familiarity with GDPR and CCPA.
  • Experience with enterprise systems or ERP’s. Workday a plus.
  • Strong knowledge of application security principles, role-based access control (RBAC), segregation of duties (SoD), and data privacy.
  • A self-starter with high levels of drive, energy, resilience, a can-do attitude, and willingness to take the initiative. Ability to operate independently.
  • Ability to adjust to changing priorities. Ability to effectively prioritize and execute tasks in a high-pressure environment.
  • Excellent written and verbal communication skills. Must have a positive, professional attitude. Experience working with executive level clients. Must be able to communicate complex topics to non-technical audiences. Excellent customer-facing/customer service skills. Excellent organizational skills.
  • Position may require infrequent traveling for short periods. Trips will sometimes extend to 5 working days and could on rare occasions extend beyond 5 business days. All travel expenses will be reimbursed.

Candidate must be able to submit verification of his/her legal right to work in the U.S., without company sponsorship.

Salary Range: $120,000-$170,000

BRG is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, religion, color, sex, gender, national origin, age, United States military veteran status, ancestry, sexual orientation, marital status, family structure, medical condition including genetic characteristics or information, veteran status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Industries
    Business Consulting and Services

Referrals increase your chances of interviewing at BRG by 2x

Inferred from the description for this job

Medical insurance

Vision insurance

401(k)

Paid maternity leave

Paid paternity leave

Get notified when a new job is posted.

Sign in to set job alerts for “Information Technology Security Specialist” roles.

United States $106,700.00-$125,400.00 4 days ago

United States $128,000.00-$176,000.00 1 day ago

Information Security and Compliance Analyst

United States $100,000.00-$120,000.00 1 week ago

United States $70,000.00-$80,000.00 2 weeks ago

Seattle, WA $117,900.00-$222,000.00 4 days ago

Reston, VA $70,000.00-$85,000.00 1 hour ago

United States $121,000.00-$140,000.00 5 days ago

Information Security Analyst I (Remote, 2+ Years Exp, 1st Shift)

Home, KS $105,000.00-$125,000.00 4 months ago

Information Security Analyst I (Remote, 2+ Years Exp, 1st Shift)

Austin, TX $70,000.00-$96,000.00 1 week ago

Information Security Analyst I (Remote, 2+ Years Exp, 1st Shift)

Seattle, WA $70,000.00-$96,000.00 1 week ago

Information Security Analyst I (Remote, 2+ Years Exp, 1st Shift)

New York City Metropolitan Area $150,000.00-$170,000.00 3 months ago

Information Security Analyst I (Remote, 2+ Years Exp, 2nd Shift)

Concord, MA $90,000.00-$110,000.00 1 day ago

United States $55,000.00-$85,000.00 6 days ago

Information Security Analyst I (Remote, 2+ Years Exp, 2nd Shift)

North Carolina, United States 3 weeks ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Director of Growth and Strategy, Security and Intelligence Services

Concentric Advisors, Inc

Washington null

Remote

Remote

USD 140,000 - 160,000

Full time

12 days ago

Information Security Lead

DecisionPoint Corporation

null null

Remote

Remote

USD 120,000 - 160,000

Full time

Today
Be an early applicant

Head of Product @ Keeper Security, Inc.

Cyber Crime

Cameron Park null

Remote

Remote

USD 150,000 - 220,000

Full time

7 days ago
Be an early applicant

Associate Director, GCP Security Specialist

KPMG Careers

Stamford null

Remote

Remote

USD 139,000 - 297,000

Full time

15 days ago

Chief Information Security Officer (CISO)

Lensa

null null

Remote

Remote

USD 150,000 - 200,000

Full time

Today
Be an early applicant

Senior Lead Information Security Engineer - Information Assurance

Lumen Argentina

Virginia null

Remote

Remote

USD 136,000 - 182,000

Full time

Yesterday
Be an early applicant

Vice President of Global Facilities Security and Chief Security Officer

BlueHalo

Arlington null

On-site

On-site

USD 150,000 - 220,000

Full time

Yesterday
Be an early applicant

Cloud Lead Security Engineer

Lumen Argentina

null null

Remote

Remote

USD 103,000 - 139,000

Full time

Today
Be an early applicant

Cloud Lead Security Engineer

Lumen Argentina

null null

Remote

Remote

USD 103,000 - 139,000

Full time

Today
Be an early applicant