Senior Information Security Administrator

Publicstorage

Frisco (TX)

On-site

USD 140,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Public Storage is seeking a Senior Information Security Administrator to strengthen security across enterprise applications, cloud services, APIs, and development practices.

This role partners closely with software engineering, DevOps, architecture, infrastructure, and business teams to identify and remediate application security risks, perform secure code reviews, guide secure design decisions, and embed security controls into the software development lifecycle.

Qualifications

  • Bachelor's degree or equivalent in a relevant field.
  • 5+ years in cybersecurity, application security, DevSecOps, cloud security, or related roles.
  • Strong development background with ability to read/write code (e.g., Java, C#, JavaScript/TypeScript, Python).
  • Hands-on secure code reviews, risk assessments, vulnerability validation, remediation guidance.
  • Knowledge of web apps, APIs, authentication, authorization, encryption, and secure data handling.
  • Experience with SAST/DAST/SCA, container scanning, IaC scanning, or similar tools.
  • Understanding of cloud security fundamentals across major platforms (Azure, AWS, GCP).
  • Familiarity with CI/CD pipelines, repositories, and DevSecOps automation.
  • Ability to clearly communicate findings to technical and non-technical stakeholders.
  • Strong analytical, troubleshooting, documentation, and prioritization skills.

Responsibilities

  • Lead or support application security assessments for various app types.
  • Perform secure code reviews and provide remediation guidance for common issues.
  • Partner with development teams to implement secure coding throughout the SDLC.
  • Operate and improve SAST/DAST, SCA, container and IaC tooling and CI/CD security controls.
  • Review architecture and data flows to identify security risks before production.
  • Translate findings into prioritized remediation plans and drive closure.
  • Advise on secure configurations, encryption, authentication, and session management.
  • Support cloud security control design across Azure, AWS, or GCP.
  • Advise on DevSecOps practices, including secure CI/CD pipelines and artifact signing.
  • Coordinate with security operations on incidents and remediation validation.
  • Support vulnerability management and documentation of compensating controls.
  • Develop and maintain application security standards and documentation.
  • Support audit and compliance activities with evidence of secure development.

Skills

Secure code reviews
Cloud security
Threat modeling
CI/CD automation
Communication to stakeholders

Education

Bachelor's degree in information security, Computer Science, Software Engineering, Information Technology, or related field

Tools

SAST
DAST
SCA
Container scanning
IaC scanning

Job description

The Senior Information Security Administrator is responsible for strengthening the security of enterprise applications, cloud services, APIs, and development practices. This role partners closely with software engineering, DevOps, architecture, infrastructure, and business teams to identify and remediate application security risks, perform secure code reviews, guide secure design decisions, and embed security controls into the software development lifecycle. The ideal candidate combines hands‑on application security experience, a strong development background, cloud security knowledge, and practical security operations expertise to reduce risk across the enterprise.

Key Responsibilities
  • Lead or support application security assessments for internally developed, third‑party, SaaS, cloud‑hosted, web, mobile, and API‑based applications.
  • Perform secure code reviews and provide actionable remediation guidance for common application security issues, including authentication, authorization, input validation, secrets exposure, insecure dependencies, API abuse, logging gaps, and insecure configuration.
  • Partner with development teams to implement secure coding practices throughout the SDLC, including threat modeling, design reviews, peer review standards, and release readiness checks.
  • Operate and improve application security tooling such as SAST, DAST, SCA, container scanning, IaC scanning, secrets detection, API security tools, and CI/CD security controls.
  • Review application architecture, data flows, cloud deployment patterns, and integration designs to identify security risks before production deployment.
  • Translate vulnerability findings into prioritized, risk‑based remediation plans and work with application owners, developers, DevOps, and product teams to drive closure.
  • Secure application‑side configurations, including encryption, session management, authentication flows, authorization models, logging, error handling, secure headers, CORS, API gateways, and secrets management.
  • Support cloud security control design and validation across platforms such as Azure, AWS, or GCP, including IAM, network segmentation, workload protection, logging, storage security, key management, and policy‑as‑code.
  • Advise on DevSecOps practices, including secure CI/CD pipelines, branch protection, dependency governance, artifact signing, container hardening, and environment separation.
  • Coordinate with security operations teams on application‑related incidents, suspicious activity, exploit attempts, and remediation validation.
  • Support vulnerability management by validating exploitability, reducing false positives, documenting compensating controls, and tracking remediation evidence.
  • Develop and maintain application security standards, secure coding guidelines, design patterns, checklists, procedures, and technical documentation.
  • Support audit and compliance activities by providing evidence for secure development, change management, access controls, logging, vulnerability remediation, and cloud security controls.
  • Mentor developers, security analysts, and IT teams on application security concepts and practical remediation techniques.
Required Qualifications
  • Bachelor's degree in information security, Computer Science, Software Engineering, Information Technology, or related field; or equivalent combination of education and experience.
  • 5-8+ years of experience in cybersecurity, application security, secure software development, DevSecOps, cloud security, or related technology roles.
  • Strong development background with practical experience reading, reviewing, or writing code in languages such as Java, C#, JavaScript/TypeScript, Python, Go, or similar.
  • Hands‑on experience performing secure code reviews, application risk assessments, vulnerability validation, and remediation guidance.
  • Working knowledge of web applications, API, authentication, authorization, encryption, session management, and secure data handling concepts.
  • Experience with application security testing tools such as SAST, DAST, SCA, container scanning, secrets scanning, IaC scanning, or similar platforms.
  • Understanding of cloud security fundamentals across Azure, AWS, or GCP, including IAM, logging, workload security, encryption, networking, and secure configuration.
  • Familiarity with CI/CD pipelines, repositories, build processes, release controls, and DevSecOps automation.
  • Ability to communicate technical findings clearly to developers, engineers, leadership, auditors, and non‑technical stakeholders.
  • Strong analytical, troubleshooting, documentation, and prioritization skills.
Preferred Qualifications
  • Professional certifications such as CSSLP, CISSP, GWAPT, GWEB, CASE, Security+, CISM, Azure Security Engineer, AWS Security Specialty, Google Professional Cloud Security Engineer, or similar.
  • Experience with OWASP risks, secure coding standards, threat modeling, API security, mobile security, cloud‑native security, Kubernetes/container security, or software supply chain security.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security (DevSecOps) Senior Engineer
Application Security (DevSecOps) Senior Engineer

Recru • Spring (TX)

On-site
USD 180,000 - 240,000
Senior Information Security Engineer
Senior Information Security Engineer

Jobtailor • Sandy (UT)

On-site
USD 110,000 - 170,000
Senior Information Security Engineer
Senior Information Security Engineer

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000
Senior DevSecOps Architect
Senior DevSecOps Architect

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Senior Application Security Engineer – Vulnerability Operations
Senior Application Security Engineer – Vulnerability Operations

Veriipro • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Senior Information Protection Advisor – Product Security, DevSecOps
Senior Information Protection Advisor – Product Security, DevSecOps

Jobtailor • Connecticut

On-site
USD 120,000 - 180,000
Application Security (AppSec) Engineer/Architect
Application Security (AppSec) Engineer/Architect

TechDigital Group • Maryland Heights (MO)

On-site
USD 120,000 - 160,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Information Security Advisor
Information Security Advisor

MRO • Norristown

On-site
USD 80,000 - 120,000