Product Security Engineer II
at Thermo Fisher Scientific
Tijuana, B.C., Mexico -
Start Date | Expiry Date | Salary | Posted On | Experience | Skills | Telecommute | Sponsor Visa |
---|---|---|---|---|---|---|---|
Immediate | 29 Dec, 2024 | Not Specified | 03 Oct, 2024 | N/A | Python,Eclipse,Javascript,Java,Addition,Application Security Assessments,Bash,Application Security,Automation,Training,Jira,Jenkins,Git,Computer Science,Development Tools,Docker,Security,Powershell,Software Development,Visual Studio Code,Aws,Visual Studio | No | No |
Required Visa Status:
Citizen | GC |
US Citizen | Student Visa |
H1B | CPT |
OPT | H4 Spouse of H1B |
GC Green Card |
Employment Type:
Full Time | Part Time |
Permanent | Independent - 1099 |
Contract – W2 | C2H Independent |
C2H W2 | Contract – Corp 2 Corp |
Contract to Hire – Corp 2 Corp |
Description:
JOB DESCRIPTION
As part of the Thermo Fisher Scientific team, you’ll discover meaningful work that makes a positive impact on a global scale. Join our colleagues in bringing our Mission to life every day to enable our customers to make the world healthier, cleaner, and safer. We provide our global teams with the resources needed to achieve individual career goals while helping to take science a step beyond by developing solutions for some of the world’s toughest challenges, like protecting the environment, ensuring our food is safe, or helping find cures for cancer.
The Product Security team is a group of Builders, Breakers, and Fixers that specialize in collaborative security engagement. The goal of the Software Security (DevSecOps) team is to provide self-service security and to that end, the team is passionate about enabling the 3 Ways of DevOps: Fast Flow, Rapid Feedback, and Continuous Learning. As the business moves through its digital transformation, the DevSecOps team is a vanguard for promoting and enabling DevOps practices across the organization. We strive to integrate and enhance current processes, remove bottlenecks, and enable safe experimentation whenever possible.
DISCOVER IMPACTFUL WORK:
We are seeking a highly skilled and experienced Software Security Engineer to join our Product Security team. The successful candidate will be responsible for ensuring the security of Software Development Life Cycle (SDLC) practices across the organization, from design to deployment.
EDUCATION
- A bachelor’s degree in Engineering or Computer Science is preferred (equivalent combinations of education, training, and meaningful work experience may be considered).
EXPERIENCE
We are looking for candidates with 3+ years of experience in software development with a focus on security, including:
- Experience writing and/or testing software applications; experience with automation.
- Basic understanding of container technologies and cloud providers such as AWS.
- Familiarity with one or more of the following languages: C/C++, Java, .NET, JavaScript, Python, Bash, PowerShell and/or Ruby.
- Familiarity with one or more development tools such as: Eclipse, Visual Studio, Visual Studio Code, IntelliJ, Git, Jira, Jenkins, and/or Docker.
- Strong attention to detail.
- The ability to communicate effectively and professionally with a diverse group of people.
KNOWLEDGE, SKILLS, ABILITIES
In addition to the experience requirements, we are looking for candidates with the following:
- Self-motivated person with an agile approach
- A track record of performing application security assessments either via Bug Bounty programs or capture-the-flag events.
- Experience with mobile application security is a plus.
- A history of involvement in general information security practice and/or the community.
- Proficient in written and verbal communication in the English language.
Responsibilities:
- Work closely with development teams to identify and mitigate security risks in our software and systems.
- Implement and maintain security tools and processes to ensure the security of our software development lifecycle.
- Conduct security assessments and code reviews to identify vulnerabilities and ensure compliance with security standards and best practices.
- Collaborate with multi-functional teams to ensure the timely and successful delivery of secure software.
- Promote and implement Secure SDLC practices based on compliance requirements.
- Develop solutions to automate processes and workflows.
- Develop and promote automated scanning tools and practices throughout the organization.
- Identify and drive process improvement initiatives to increase our productivity and/or reduce costs.
- Develop performance indicators and reporting from aggregated sources to assist Software Security Management with remediation prioritization within the company.
- Contribute to the team’s strategy and long-term roadmap
REQUIREMENT SUMMARY
Min:N/AMax:5.0 year(s)
Computer Software/Engineering
IT Software - Network Administration / Security
Software Engineering
Graduate
Engineering or computer science is preferred (equivalent combinations of education training and meaningful work experience may be considered
Proficient
1
Tijuana, B.C., Mexico