Application Security Engineer Job at Johnson Controls, Milwaukee, WI

eTg3WHVQeDYyamdmZ0dBeU5QYUYranY2QXc9PQ==
  • Johnson Controls
  • Milwaukee, WI

Job Description

Build your best future with the Johnson Controls team

As a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet.  Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience, focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard – your next great opportunity is just a few clicks away! 

What we offer:

  • Competitive salary

  • Paid vacation/holidays/sick time

  • Comprehensive benefits package including 401K, medical, dental, and vision care

  • On the job/cross training opportunities

  • Encouraging and collaborative team environment

  • Dedication to safety through our Zero Harm policy

What you will do:

In this high impact opportunity within the Application Security organization, you will report directly to the Manager, Application Security. You will drive continuous improvement initiatives aligned to our cybersecurity maturity framework and roadmap, ensuring proactive management of security and data privacy risk across the full lifecycle of our products, applications, platforms, and service offerings.

You will apply your expertise in secure software development practices to ensure security and privacy by design requirements are fulfilled and that applications are delivered with strong cybersecurity as a core feature. In this role, you will play a pivotal role in managing cybersecurity risk, differentiating Johnson Controls, and enabling business success.

How you will do it:

  • Provide cybersecurity expertise and guidance to application development teams, security champions, and business leaders throughout all phases of the software development life cycle.

  • Drive policy compliance and high quality for secure SDLC activities – security requirements, security architectures, threat and attack models, supply chain security, code reviews, SAST, DAST, IAST, penetration testing, and security, hardening. Architect security and privacy by design and secure-by-default into software applications for mobile, embedded systems, and cloud.

  • Drive efforts to quantify residual product and application risk and identify appropriate security controls.

  • Review application architectures for security design gaps and vulnerabilities and consult with development teams to remediate or mitigate cyber risk.

  • Assist coordination of third-party penetration testing vendor engagements with product teams.

  • Help engineers and product managers identify solutions to meet cybersecurity requirements.

  • Maintain current knowledge of security threats and vulnerabilities that could impact products and applications.

  • Support incident response operations, training, and exercises, including exploitation analysis and countermeasure testing.

  • Assist coordination and tracking of vulnerability remediation activities.

  • Raise security awareness and drive security training and certification for people and products.

  • Support periodic reporting to senior executive leadership on health and status of the application security program, cybersecurity risks, risk mitigations, and trends.

  • Use agile project management to manage resources and track milestones and deliverables.

  • Support internal audits and assessments to identify risks and determine mitigation actions.

  • Identify cybersecurity opportunities that enhance the developer and customer experience.

  • Support cybersecurity risk and technology assessments.

What we look for:

  • Knowledge of cybersecurity compliance, regulations, industry standards and certifications.

  • Excellent written and verbal communication and presentation skills.

  • Experience with Operational Technologies (e.g. Controls Systems, Building Management) a plus.

  • Customer relations acumen with ability to explain complex technical details to a wide audience.

  • Excellent interpersonal, organizational, written and verbal communication skills.

  • Relevant work experience.

  • BS/BA in cybersecurity, computer science, engineering, or related technical degree or equivalent years of experience.

  • Cybersecurity certifications, e.g. CISSP, GSEC, Sec+, or related are preferred.

  • Up to 10-15% travel, including international.

NOTE: This is a virtual/remote position considering candidates who reside within the United States

HIRING SALARY RANGE: $84,000 -$105,000 (Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, location and alignment with market data.) This position includes a competitive benefits package. For details, please visit the About Us tab on the Johnson Controls Careers site at

#LI-Remote

Job Tags

Full time, Work experience placement, Remote work,

Similar Jobs

Breckenridge Ski Resort

Assistant Property Manager Job at Breckenridge Ski Resort

 ...Create Your Experience of a Lifetime! Come work and play in the mountains! Whether...  ...Job Summary: The Housing Assistant Manager is responsible for overseeing the Breckenridge...  ...Degree Preferred ~2+ years experience in property management or related fields ~... 

Haldeman Auto Group

Lexus Auto Mechanic/Technican Job at Haldeman Auto Group

Job SummaryThe Haldeman Auto Group is a well-established and reputable car dealership specializing in offering a wide range of service...  ...continue to grow, we are seeking a skilled and dedicated Auto Mechanic to join our dynamic team. So if you are looking for a great... 

Greenbrier Management

Assistant Property Manager-Roanoke/Salem Job at Greenbrier Management

 ...Greenbrier Management Company is based in Williamsburg, Virginia. Founded in 1984 by corporate owners to manage their own properties, the company expanded to include third-party property management...  ...residents and owners. We have the experience and dedication sought by property... 

State of Colorado Job Opportunities

CDOC Boiler Operator Supervisor Trainee/Correctional Officer I (Denver) Job at State of Colorado Job Opportunities

 ...Contribution Plan plus 401K and 457 plans. Member Contribution Rates. Correctional Officers I-IV qualify as "Safety Officers" and are eligible for...  ...program provides the opportunity to gain relevant work experience toward promotion to a Correctional Support Trades... 

Principal Financial Group

Equity Analyst, Aligned Investors Job at Principal Financial Group

What You'll Do: Were looking for an Equity Analyst to join the Aligned Investors team. Aligned Investors has a very successful long-term...  .... The process relies completely on fundamental company research. Our team is made up of passionate analysts who all work to deliver...