Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Bank of America

Product Manager – Tech Delivery, Application Security Adjudication, Risk Management

Bank of America

. Develop a deep understanding of business applications, technology platforms, and software delivery processes .

Posted 9/18/2026full-timeWashington • Colorado • United StatesSeniorLead💰 $135,000 - $217,100 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Application Security, Secure Software Development, and Vulnerability Management, with a strong focus on risk-based analysis and secure coding practices. Proficient in evaluating and validating application security findings and communicating technical security insights to diverse stakeholders.

Highest-signal resume keywords
Application SecurityVulnerability ManagementSource Code AnalysisCheckmarx OneSecure SDLC

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application Security AssessmentsVulnerability ValidationThreat ModelingSecure Coding PracticesRisk-Based AnalysisExploitability EvaluationAPI SecuritySecurity TestingSoftware Design PatternsData Flow Analysis
Soft Skills
Analytical SkillsProblem-SolvingStakeholder ManagementCommunication SkillsRisk Assessment
Tools & Technologies
Checkmarx OneGitHub CopilotSASTSCACloud-Native TechnologiesDevSecOps Practices
Certifications & Qualifications
CISSPCSSLPCISMCRISCGIACOSCP
Industry Keywords
NISTISOPCI DSSApplication Security FrameworksSecure Software Development Initiatives

Tech Stack

Tools & technologies
CloudCyber SecurityMicroservicesSDLC

About the role

Key responsibilities & impact
  • Develop a deep understanding of business applications, technology platforms, and software delivery processes
  • Support specialized information security and application security risk discussions
  • Partner with LOB CIOs, CTOs, application development teams, architects, and technology partners
  • Serve as the primary technical reviewer and adjudicator for application security findings generated through Checkmarx One and other approved security testing technologies
  • Review, analyze, validate, and disposition application security findings using evidence-based technical analysis
  • Independently validate vulnerability findings rather than relying solely on automated scanner results, developer rationale, AI-generated recommendations, or previous dispositions
  • Analyze source code, application architecture, APIs, business logic, trust boundaries, data flows, and software design patterns
  • Evaluate exploitability, reachability, attack paths, compensating controls, exposure conditions, and real-world security risk
  • Review and validate developer-submitted adjudication requests, including Proposed Not Exploitable determinations and supporting evidence packages
  • Partner with development teams, architects, security engineers, product owners, and risk partners to drive secure development practices, vulnerability remediation, and risk-based security decision making across the enterprise

Requirements

What you’ll need
  • 10+ years of Information Security, Application Security, Secure Software Development, or Technology Risk Management experience
  • 5+ years of experience in Application Security, Secure Software Development, Vulnerability Management, Security Architecture, or Information Security Risk Management
  • Strong experience performing source code analysis, vulnerability validation, application security assessments, and security testing
  • Subject matter expertise in Application Security, Secure SDLC, Vulnerability Management, Threat Modeling, Secure Coding Practices, OWASP Top 10, and Common Weakness Enumerations (CWE)
  • Experience with Checkmarx One or comparable enterprise application security testing platforms
  • Ability to evaluate, validate, and adjudicate complex SAST, SCA, API Security, and related application security findings using risk-based analysis
  • Experience identifying false positives, exploitability constraints, compensating controls, and appropriate risk treatment strategies
  • Strong understanding of modern application architectures, APIs, microservices, cloud-native technologies, and DevSecOps practices
  • Experience evaluating application security controls across cloud, SaaS, PaaS, distributed, and on-premises environments
  • Strong knowledge of NIST, ISO, PCI DSS, and related security frameworks
  • Ability to communicate technical security findings, risk decisions, and remediation guidance to both technical and non-technical stakeholders
  • Strong analytical, problem-solving, stakeholder management, and risk assessment skills
  • Bachelor's and/or Master's degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field (desired)
  • CISSP, CSSLP, CISM, CRISC, GIAC, OSCP, or equivalent industry certifications (desired)
  • Experience supporting enterprise application security programs and secure software development initiatives (desired)
  • Experience with AI-assisted development and code-analysis tools such as GitHub Copilot (desired)

Benefits

Comp & perks
  • Annual discretionary incentive plan eligibility
  • Industry-leading benefits
  • Paid time off
  • Resources and support for employees
  • In-office flexibility based on role-specific responsibilities and business needs