Cybersecurity
AppSec and Integrations Team Lead
Job Description
Position Summary:
The Cybersecurity organization is seeking an AppSec and Integrations Team Lead to drive the advancement and maturity of the AppSec program and to propel development/automation capabilities.
The successful candidate will have responsibility for maintaining and advising the direction of AppSec initiatives as well as the software development lifecycle of various tools used for security services, consulting and validation tasks. Primarily, this role will focus on secure application development, API security, coordination with business partner development teams, risk and vulnerability mitigation, as well as integration with various security tools and platforms.
Qualified candidates need to be able to interact with software and security vendors, align strategy and execution to increase application security maturity, anticipate future requirements for complex environments, keep up with current security trends, be focused on results, and be a self-starter.
This role will directly support the company’s efforts to mitigate real and potential cyber threats to the company’s applications, services, personnel, technology, operations, and brand – including critical electric and gas utility infrastructure and its privately owned telecommunications network.
Southern Company is headquartered in Atlanta and we bring energy to homes and businesses across the country. We’ve made our name as a leading producer of clean, safe, reliable and affordable energy, and we approach each day as a vital step in building the future of energy. We’re always looking ahead, and our innovations in the industry – from new nuclear to deployment of electric transportation and renewables – help brighten the lives and businesses of millions of customers nationwide. Our team is critical to building the future of energy with secure, resilient, and sustainable cyber solutions.
Defend. Protect. Enable.
Job Responsibilities:
- Provide leadership and work direction to application security analysts.
- Oversee maintenance, integration, lifecycle, and future planning for application security products such as static and dynamic code analysis tools.
- Coordinate and partner with development teams to integrate security into the software development lifecycle.
- Lead efforts in secure development practices, code vulnerability mitigation efforts, and resilient application development.
- Manage and implement API security measures and protocols.
- Conduct dynamic analysis and static code scanning to identify and mitigate vulnerabilities.
- Continuously look for and act on process improvement or automation opportunities.
- Develop and enforce security policies, standards, and guidelines for application security.
- Stay ahead of current security trends and evolving threats to ensure robust application security.
- Engage with service vendors and partners to enhance security capabilities.
- Collaborate with other cybersecurity teams to ensure comprehensive security coverage.
- Contribute to the company’s Architecture Review Board to aide in long-term improvement of secure code standards.
Requirements and qualifications:
Required:
- Excellent abilities to lead a team of people, clearly communicate tasks, and expectations.
- Strong capabilities in application development across multiple languages.
- Extensive experience in application security and secure software development practices.
- Strong knowledge of API security and related technologies.
- Proficiency in dynamic and static code analysis tools.
- Ability to effectively communicate and collaborate with development teams.
- Experience in developing and implementing security policies and guidelines.
- Up-to-date knowledge of the latest security threats and trends.
- Self-starter with a focus on results and continuous improvement.
Desired:
- Experience managing Windows Servers and applications either as a primary or secondary job function.
- A solid understanding of IAM related protocols and standards such as:
SAML, OAuth/OIDC, WS-Fed, SCIM, FIDO, RADIUS, LDAPS, Kerberos. - Strong verbal communication, and presentation skills.
- Competency in APIs (Rest, Graph) and/or JavaScript/Python/JSON/SQL.
- Experience prioritizing and executing with minimal direction or oversight.
- Industry certifications such as: CISSP, CCSP, CISA, GIAC, OSCP, CRISC, CCNP, etc.
- Experience with information security frameworks such as: COBIT, NIST, OWASP, etc.
- Familiarity with nation state, sophisticated criminal, and supply chain threats.


