Skip to main contentA logo with &quat;the muse&quat; in dark blue text.
ASCAP

Senior Information Security Analyst (Architect)

New York, NY

Job Description

About ASCAP

The American Society of Composers, Authors and Publishers (ASCAP) is a membership association of more than 900,000 songwriters, composers and music publishers, and represents some of the world's most talented music creators. Founded and governed by songwriters and composers, it is the only performing rights organization in the U.S. that operates as a not-for-profit. ASCAP licenses a repertory of over 18 million musical works to hundreds of thousands of businesses that use music, including streaming services, cable television, radio and satellite radio and brick and mortar businesses such as retail stores, hotels, clubs, restaurants and bars. ASCAP collects the licensing fees; identifies, matches and processes trillions of performances every year; and returns nearly 90 cents of every dollar back to its members as royalties. The ASCAP blanket license offers an efficient solution for businesses to legally perform ASCAP music while respecting the right of songwriters and composers to be paid fairly. ASCAP puts music creators first, advocating for their rights and the value of music on Capitol Hill, driving innovation that moves the industry forward, building community and providing the resources and support that creators need to succeed in their careers. Learn more and stay in touch at www.ascap.com, on Twitter and Instagram @ASCAP and on Facebook.

Want more jobs like this?

Get jobs in New York, NY delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


# # #

Job Description:

We are looking for a motivated, detail-oriented individual with strong technical skills. This role's primary focus is on working to secure in-house built software and software as a service integrated applications. Plus working with management on security strategies and product owners/designers/developers/platform engineers/endpoint engineers to design, develop and implement secure systems, networks, and applications. This person will be the point of escalation for Jr. Security Analysts who investigate and respond to security event alerts, manage technical aspects of incident response, work on third party applications/services reviews and the organizations vulnerability management program. This role will also address the management of a true SDLC program with DevSecOps for our in-house built applications and work with developers to implement information security best practices ensuring that our code is proactively secured while in the pipeline prior to moving to production.

The person in this role will need to prioritize and ensure the timely completion of tasks from the scrum masters and management. They should also be able to shift and adjust priorities based on changing business needs in our dynamic environment, while also remaining task-oriented to ensure completion of work from start to finish with appropriate solutions.

Responsibilities:

  • Work independently with developers, system/network administrators, product owners, design teams and other colleagues to ensure secure design, development, and implementation of applications and networks - defining and promoting a full SDLC program.
  • Perform security architecture design reviews of our applications (primarily cloud).
  • Perform code analysis of large applications manually and conduct manual vulnerability analysis.
  • Provide remediation guidance and recommendations to developers and administrators.
  • Work with development teams to help prioritize and validate urgency of mitigation of identified product vulnerabilities and security feature enhancement requests.
  • Define security best practices and standards to ensure development teams understand them and receive pertinent annual secure coding training.
  • Researches, evaluates, tests, and assists on implementation of new security solutions around DevSecOps and the application pipeline.
  • Works closely with Jr. Security Analysts and security platform engineers to investigate and resolve security related events.
  • Works alongside project management in a SCRUM environment to successfully monitor progress and implementation of security initiatives.

Qualifications:

  • Minimum five (5) years of experience at the senior level working in depth with various versions of Mac/MS/Unix/Linux operating system, networking, security devices, and securing web based and back office applications.
  • Experience working with development teams to build secure solutions.
  • Experience breaking down complex systems and applications to find flaws.
  • Proficiency in reading, writing, and auditing Java and the ability to pick up new languages/technologies.
  • Experience with secure coding practices and architecting secure applications written in Java.
  • The ability to communicate complicated technical issues and the risks they pose to developers, network engineers, system administrators, and management.
  • Security certification such as CISSP is preferred.
  • Cloud security experience with AWS and Salesforce is a plus.
  • Bachelor's degree in Computer Science or Information Security.
  • A keen eye for detail, an analytical thinker and the ability to multitask.
  • The ability to thrive in fast-paced, high stress situations.
  • A problem solver with the ability to communicate effectively with peers, business partners and management.
  • Self-starter, positive attitude, ability to work independently, enjoys learning and staying current with industry developments, regulations and best practices.
  • Experience providing security training to developers.

Besides providing a unique and dynamic work environment, there are a few other reasons you should consider ASCAP in your career planning. We also offer generous benefit options that are comprehensive and provide the flexibility that most employees want and need. These health care and financial plan options include the following:

  • A choice of either network only provider medical and dental plans or more flexible medical and dental plans where you can see providers in or out-of-network
  • Vision plan that offers both in and out- of network provider options
  • Immediate eligibility for 401(k) participation with an employer provided match
  • An additional Employer paid retirement savings program regardless of your participation in the 401(k) Plan
  • Generous time-off policy
  • Health care and dependent care flexible spending accounts
  • Short term disability Insurance / salary continuation and Long term disability insurance
  • Company provided basic life and accidental death and dismemberment insurance
  • Supplemental and dependent life insurance options

Please be aware that ASCAP is not a nut-free or other allergen-free workplace.

As a condition of employment, ASCAP requires all employees to be fully vaccinated (including a first booster, when eligible) against COVID-19. ASCAP will make reasonable accommodations for those who are unable to obtain a COVID-19 vaccination, where required by federal, state and local law, and in accordance with ASCAP's policies.

ASCAP is an equal opportunity employer. All ASCAP employment decisions are made on the basis of individual qualifications and performance and not on the basis of race, national origin, ethnicity, sex, age, marital status, sexual orientation or preference, gender identity, genetic information, disability, handicap, color, creed, religion, veteran status, or any characteristic protected by applicable federal, state or local laws.

Occasional travel for in-person meetings may be required.

The anticipated base salary range for this position is $140,000.00 to $145,000.00 and will be determined on an individualized basis depending on several factors that are unique to each candidate including geographic location (due to differences in the cost of labor), skills, education and prior relevant experience.

Client-provided location(s): New York, NY, USA
Job ID: Ascap-aVB-lYa6Dk3BqJwa9JRONX
Employment Type: Other

Company Videos

Hear directly from employees about what it is like to work at ASCAP.