Application Security Engineer III (Remote)

United States - Remote /
CFO Group – CFO Shared Services - GESA /
Full - Time
Rackers:  Valued members of a winning team Our employees, affectionately called “Rackers,” are our true strength and differentiator. As valued members of a winning team on an inspiring mission, Rackers make a real difference for our customers. It’s why we’re frequently recognized as an employer of choice by global industry-leading programs, including Great Place to Work, Forbes and Fortune.  They embody our Core Values, demonstrating that Fanatical Experience is:
·       Excellence. We are an accountable, disciplined, high-performing company with proven results.
·       Customer-driven. We are proactive, collaborative and committed to success for our customers.
·       Expertise. Rackers are passionate learners who are embedded in our customers’ businesses to provide unbiased solutions.
·       Agility. We adopt new technologies and evolve services to meet customers where they are in their journey.
·       Compassion. We’re one team doing the right thing for our customers, communities, and each other.

Position Overview:  In this role, you will lead Rackspace’s application security program by developing and coordinating strategic projects and initiatives, including capabilities such as static and dynamic application security testing, application penetration testing, and our bug bounty program, and supporting and establishing the reporting, processes, and automation to make remediation of any findings above successful.
Work Location:  100% Remotely from within the continental United States.
Key Duties and Responsibilities:
·       Be a technical leader for application security, developing a strategy to improve the application security program, including capabilities, processes, metrics, user experience, partnerships, and overall maturity.
·       Select, build, improve, integrate, and/or manage tools to perform automated and manual application security testing of web applications, APIs, containers, and other software components
·       Interpret, prioritize, and summarize findings into clear remediation actions, and create a vulnerability reporting process to ensure successful follow through
·       Respond to external vulnerability disclosure, or bug bounty, reports
·       Prioritize projects and vulnerability findings based on expected value and impact to the organization
·       Identify, track, and report KPIs for the health of the application security program
·       Create and improve security processes through automation, integration, and documentation
·       Build up your team, by regularly sharing skills, knowledge, and advice
·       Be called on as a subject matter expert for challenging and sometimes time sensitive security events
·       Work independently with general guidance on new assignments
Required Knowledge, Skills, and Abilities:     
·       Experience being a member of, or leading, an application security or DevSecOps team
·       Strong understanding of the SDLC, security concepts and strategy, and vulnerability assessments
·       Experience with or strong understanding of programming and scripting languages including one or more of the following:  Python, C, Java, Node.js, Go, Ruby, Groovy, PHP, and Scala; databases such as SQL; and other related tools such as Github, Gitlab, Jenkins, and CircleCI
·       Deep understanding of vulnerabilities, remediation, and industry-standard classification and prioritization schemes (CVE, CWE, CVSS, OWASP Top 10) and how to prioritize and communicate vulnerabilities to stakeholders
·       A general understanding of relevant compliance regulations, such as PCI, SOX, HIPAA, HITRUST, or FedRAMP
·       Passion for security, staying up to date on new technologies and security vulnerabilities
·       Desire to be a team player that help train and build team members up, and partner closely with key contacts external to the team and company to solve complex problems 

·       5+ years in the information security field
·       At least two advanced security certifications, or equivalent work experience. For example, Offensive Security certification (OSCP, OSEE, OSWE), GIAC certification (GCIH, GWAPT, or GPEN), or (ISC)2 certification (CISSP, SSCP, CCSP).
·       Prefer Bachelor’s Degree within an Information Technology field of study; HS diploma is required.
 Pay and Benefits:
·               The anticipated starting pay range is $104,200- $168,000.  Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, licenses, and certifications.
·               Information on benefits offered is here:
#LI-MF1 #LI-Remote

About Rackspace Technology
We are the multicloud solutions experts. We combine our expertise with the world’s leading technologies — across applications, data and security — to deliver end-to-end solutions. We have a proven record of advising customers based on their business challenges, designing solutions that scale, building and managing those solutions, and optimizing returns into the future. Named a best place to work, year after year according to Fortune, Forbes and Glassdoor, we attract and develop world-class talent. Join us on our mission to embrace technology, empower customers and deliver the future.
More on Rackspace Technology
Though we’re all different, Rackers thrive through our connection to a central goal: to be a valued member of a winning team on an inspiring mission. We bring our whole selves to work every day. And we embrace the notion that unique perspectives fuel innovation and enable us to best serve our customers and communities around the globe. We welcome you to apply today and want you to know that we are committed to offering equal employment opportunity without regard to age, color, disability, gender reassignment or identity or expression, genetic information, marital or civil partner status, pregnancy or maternity status, military or veteran status, nationality, ethnic or national origin, race, religion or belief, sexual orientation, or any legally protected characteristic. If you have a disability or special need that requires accommodation, please let us know.