Software Supply Chain- Container Application Security Director

ADP, Inc.

Roseland (NJ)

Hybrid

USD 123,000 - 304,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Coverage
Retirement Savings
Wellness Program
Paid Time Off

Job summary

ADP, Inc. is seeking a Director of Container Application Security to lead design, implementation, and governance of container security across ADP’s product ecosystems in a hybrid role based in Alpharetta, GA or Roseland, NJ.

The role emphasizes shift-left security in DevSecOps, vulnerability remediation, KPI reporting, and collaboration with technology teams to secure cloud deployments and Kubernetes environments.

Qualifications

  • Ten years or more experience in various IT or cybersecurity roles with 3+ years leadership experience in multi-cloud computing and containerized environments, specifically secure operation in Kubernetes
  • Experience leading efforts in Container Application Security programs
  • Deep knowledge and understanding of application security vulnerabilities (OWASP SANS,)
  • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, Rally, JIRA, Artifactory, Nexus, SonarQube, git)
  • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
  • Understanding of Container Security Scanning, Application Security Test Automation tools and frameworks such as SAST, DAST, IAST, Container Application Security testing, and Burp Suite
  • Knowledge in securing cloud deployment and containers (familiarity with Ansible, Chef, DeMisto, Docker, Helm, and/or Kubernetes)
  • Understanding of advanced iterative Agile and container & cloud security
  • Familiarity with micro services architecture and design Patterns
  • Excellent analytic skills, including qualitative and quantitative data analysis to support and defend data-driven decision-making regarding system threats, vulnerabilities, and risk
  • Experience in an enterprise environment orchestrating multiple pods and containers.
  • Hands-on experience with container security tools such as Snyk, Chainguard, Grype, Prisma (Twistlock), or StackRox
  • Experience with other cloud container solutions, such as Docker, Containered, or Rancher
  • Experience configuring disaster recovery (DR) environments.
  • Previous software engineering/architecture experience (Java, C#,.Net, JavaScript) preferred
  • Some experience with development of RESTful and SOAP web services preferred
  • Any of the following are a plus but not necessary: CEH, CISSP, CSSLP, GCIA, GPEN, GWAPT,

Responsibilities

  • Drive container application security including supply chain risk initiatives across ADP’s different business units.
  • Institutionalize the container security scanning of images in line with shift left strategy in DevSecOps.
  • Manage supply chain, container application security vulnerability remediation flow.
  • Develop and maintain the roadmap for container security & supply chain risk.
  • Customize policies, rules, and alerts to comply with established policies and settings.
  • Drive culture around secure application development through effective training, governance, and metrics
  • Bring thought leadership into the program and drive excellence.
  • Manage the project timelines and delivery.
  • Maintain awareness of Kubernetes cybersecurity threats and best practices to enable securing and hardening Kubernetes clusters at scale
  • Metrics/Reporting
  • Identify meaningful KPIs/KRI’s to drive progress, improvement & improvement.
  • Create dashboards to monitor significant events, traffic and data collection.
  • Provide weekly Scanning and Monitoring reports.
  • Create weekly, monthly and in-progress review presentations, as needed.
  • Create and maintain Standard Operating Procedures (SOP)
  • Establish strong partnership with key stakeholders in technology and product organizations.
  • Manage communication upwards, downwards, and horizontally.

Skills

Container security
DevSecOps
CI/CD pipelines
Java
C#
JavaScript
Python
Cloud security
Security architectures
Vulnerability remediation

Education

Bachelor's degree in Computer Science or equivalent

Tools

Snyk
Chainguard
Grype
Prisma (Twistlock)
StackRox
Docker
Kubernetes
Jenkins

Job description

ADP is hiring a Director, Container Application Security

This Hybrid role can sit in Alpharetta, GA or Roseland, NJ

Unlock Your Career Potential: Global Security Organization at ADP. Do you have a passion for going on the offensive to safeguard critical information? As ADP’s Global Security Organization (GSO), we know that our clients rely on us for human capital management solutions, but beyond that, they entrust us with one of their most valuable assets — their employee data. We are honored by this trust and are laser focused on securing data at every step in the information lifecycle, ensuring integrity, confidentiality and compliance with industry and government regulations at all times. From the cloud to the data center and across every emerging device, you’ll join a team of experts in the GSO who are always staying one step ahead in this ever-changing world of data by continually evolving our strategies and technologies to protect ADP and our clients.

The mission of the GSO Enterprise Application Security [EAS] team is to protect ADP's internally developed products from existing and emerging security threats. We improve internal product security posture by integrating and automating security controls early in the product development life cycle and aid in uncovering security risks. This work empowers and supports development teams to recognize and address security risks in a timely manner.

The EAS team has an opening for Software Supply Chain- Container Application Security Director to drive design, implement, and manage the container application security scanning services partnering with key stakeholders and deliver to assess the security risks and establish a governance framework for the secure use of models before released to the production use.

Like what you see?

Learn more about ADP at tech.adp.com/careers

What You’ll Do:
  • Drive container application security including supply chain risk initiatives across ADP’s different business units.
  • Institutionalize the container security scanning of images in line with shift left strategy in DevSecOps.
  • Manage supply chain, container application security vulnerability remediation flow.
  • Develop and maintain the roadmap for container security & supply chain risk.
  • Customize policies, rules, and alerts to comply with established policies and settings.
  • Drive culture around secure application development through effective training, governance, and metrics
  • Bring thought leadership into the program and drive excellence.
  • Manage the project timelines and delivery.
  • Maintain awareness of Kubernetes cybersecurity threats and best practices to enable securing and hardening Kubernetes clusters at scale
  • Metrics/Reporting
    • Identify meaningful KPIs/KRI’s to drive progress, improvement & improvement.
    • Create dashboards to monitor significant events, traffic and data collection.
    • Provide weekly Scanning and Monitoring reports.
    • Create weekly, monthly and in-progress review presentations, as needed.
  • Create and maintain Standard Operating Procedures (SOP)
  • Establish strong partnership with key stakeholders in technology and product organizations.
  • Manage communication upwards, downwards, and horizontally.
Experience You'll Need:
  • Deep knowledge and understanding of container application security vulnerabilities (SANS, OWASP).
  • Candidate should be very thorough in internet technologies and highly versed with web development secure coding best practices.
  • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, Rally, JIRA, Artifactory, Nexus, SonarQube, git, Snyk).
  • Previous software engineering/architecture experience (Java, C#,.Net, JavaScript, Python) preferred.
  • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
  • Strong experience in training development teams on secure coding
  • Ability to communicate security-related concepts to a broad range of technical and non-technical staff.
  • Some experience with development of RESTful and SOAP web services preferred.
  • Understanding of advanced iterative Agile, Cloud and Container Security
  • Familiarity with micro services architecture and design Patterns.
To Succeed in This Role:
  • You’ll need a bachelor's degree in computer science, Information / Cyber Security, Computer Systems Engineering, Computer Information Systems or equivalent experience.
Qualifications:
  • Ten years or more experience in various IT or cybersecurity roles with 3+ years leadership experience and management in multi-cloud computing and containerized environments, specifically secure operation in Kubernetes
  • Experience leading efforts in Container Application Security programs
  • Deep knowledge and understanding of application security vulnerabilities (OWASP SANS,)
  • Candidate should be very thorough in internet technologies and highly versed with web development best practices.
  • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, Rally, JIRA, Artifactory, Nexus, SonarQube, git)
  • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
  • Understanding of Container Security Scanning, Application Security Test Automation tools and frameworks such as SAST, DAST, IAST, Container Application Security testing, and Burp Suite
  • Ability to communicate security-related concepts to a broad range of technical and non-technical stakeholders.
  • Knowledge in securing cloud deployment and containers (familiarity with Ansible, Chef, DeMisto, Docker, Helm, and/or Kubernetes)
  • Understanding of advanced iterative Agile and container & cloud security
  • Familiarity with micro services architecture and design Patterns
  • Excellent analytic skills, including qualitative and quantitative data analysis to support and defend data-driven decision-making regarding system threats, vulnerabilities, and risk
  • Experience in an enterprise environment orchestrating multiple pods and containers.
  • Hands-on experience with container security tools such as Snyk, Chainguard, Grype, Prisma (Twistlock), or StackRox
  • Experience with other cloud container solutions, such as Docker, Containered, or Rancher
  • Experience configuring disaster recovery (DR) environments.
  • Previous software engineering/architecture experience (Java, C#,.Net, JavaScript) preferred
  • Some experience with development of RESTful and SOAP web services preferred
  • Any of the following are a plus but not necessary: CEH, CISSP, CSSLP, GCIA, GPEN, GWAPT,

What are you waiting for?

Find out why people come to ADP and why they stay: https://youtu.be/ODb8lxBrxrY

(ADA version: https://youtu.be/IQjUCA8SOoA )

Base salary offers for this position may vary based on factors such as location, skills, and relevant experience. Some positions may include additional compensation in the form of bonus, equity or commissions. We offer the following benefits: Medical, Dental, Vision, Life Insurance, Matched Retirement Savings, Wellness Program, Short-and Long-Term Disability, Charitable Contribution Match, Holidays, Personal Days & Vacation, Paid Volunteer Time Off, and more. The compensation for this role is USD $123,400.00 - USD $303,800.00 / Year* *Actual compensation will not be less than the applicable minimum wage or minimum exempt salary requirement under federal, state and local laws.

A little about ADP: We are a comprehensive global provider of cloud-based human capital management (HCM) solutions that unite HR, payroll, talent, time, tax and benefits administration and a leader in business outsourcing services, analytics, and compliance expertise. We believe our people make all the difference in cultivating a down-to-earth culture that embraces our core values, welcomes ideas, encourages innovation, and values belonging. We've received recognition for our work by many esteemed organizations, learn more at ADP Awards and Recognition.

Diversity, Equity, Inclusion & Equal Employment Opportunity at ADP: ADP is committed to an inclusive, diverse and equitable workplace, and is further committed to providing equal employment opportunities regardless of any protected characteristic including: race, color, genetic information, creed, national origin, religion, sex, affectional or sexual orientation, gender identity or expression, lawful alien status, ancestry, age, marital status, protected veteran status or disability. Hiring decisions are based upon ADP’s operating needs, and applicant merit including, but not limited to, qualifications, experience, ability, availability, cooperation, and job performance.

Ethics at ADP: ADP has a long, proud history of conducting business with the highest ethical standards and full compliance with all applicable laws. We also expect our people to uphold our values with the highest level of integrity and behave in a manner that fosters an honest and respectful workplace. Click https://jobs.adp.com/life-at-adp/ to learn more about ADP’s culture and our full set of values.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Container Security Analyst
Container Security Analyst

Fairygodboss • Roseland (NJ)

Hybrid
USD 120,000 - 150,000
Hybrid work model
Diversity, Equity & Inclusion
Lead Security Engineer - Developer, Cloud, Kubernetes
Lead Security Engineer - Developer, Cloud, Kubernetes

Socket.dev • Roseland (NJ)

Hybrid
USD 140,000 - 190,000
Cyber Security Analyst
Cyber Security Analyst

ADP, Inc. • Roseland (NJ)

Hybrid
USD 75,000 - 184,000
Principal Cloud Security Architect - Google Cloud Platform (GCP)
Principal Cloud Security Architect - Google Cloud Platform (GCP)

ADP, Inc. • Roseland (NJ)

Hybrid
USD 123,000 - 304,000
Medical benefits
Dental benefits
Vision benefits
+6
Lead Information Security Analyst
Lead Information Security Analyst

Fairygodboss • Alpharetta (GA)

On-site
USD 120,000 - 180,000
Network Security Engineer
Network Security Engineer

ADP, Inc. • Alpharetta (GA)

On-site
USD 110,000 - 160,000
Network Security Engineer
Network Security Engineer

ADP • Alpharetta (GA)

On-site
USD 120,000 - 160,000
Sr Lead Platform Engineer
Sr Lead Platform Engineer

Fairygodboss • Alpharetta (GA)

On-site
USD 88,000 - 238,000
Medical, Dental, Vision, Life Insurance
Matched Retirement Savings
Wellness Program
+2
Director, Container Security & Software Supply Chain
Director, Container Security & Software Supply Chain

ADP, Inc. • Roseland (NJ)

Hybrid
USD 123,000 - 304,000
Medical Insurance
Dental Insurance
Vision Coverage
+3
Senior Application Security Architect
Senior Application Security Architect

Socket.dev • Alpharetta (GA)

On-site
USD 150,000 - 210,000