Start Date
Immediate
Expiry Date
21 Dec, 26
Salary
65000.0
Posted On
28 Sep, 26
Experience
2 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
No
Skills
Industry
Information Technology & Services
Perform threat modeling, risk assessments, and architecture reviews to identify and mitigate risk
Support the engineering teams on detailed security requirements to meet compliance requirements and industry best practices
Perform security code reviews looking for potential security vulnerabilities
Act as a subject matter expert to advise and answer questions from engineering and compliance teams on technical product security matters
Define and oversee the deployment of Software Composition Analysis (SCA) tools to compile SBOMs of software components, helping to identify known vulnerabilities and license compliance violations
Define and oversee the deployment of automated security testing tools into CI pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Secret Detection scanning tools
Manual penetration testing of web applications (backend and frontend).Manual penetration testing skills in the domains of cloud infrastructure, embedded/OS or mobile are desirable
Write custom scripts or unit test cases to check for vulnerabilities or broken/missing security controls
Recommend improvements to existing security scanning tools and processes, and propose new ones
Triage the findings from the automated security scanning tools
Validate potential security vulnerabilities to determine whether they are actual true positives, or false positives (i.e. non-applicable) in the product context. Write proof of concept exploits when necessary to achieve this
Assess the risk of vulnerabilities and threats in order to help the business determine their remediation priority order
Communicate the identified security issues to engineering and compliance stakeholders, and manage them throughout the SDLC process to ensure they are properly addressed
How To Apply:
Incase you would like to apply to this job directly from the source, please click here
Perform threat modeling, risk assessments, and architecture reviews to identify and mitigate risk
Support the engineering teams on detailed security requirements to meet compliance requirements and industry best practices
Perform security code reviews looking for potential security vulnerabilities
Act as a subject matter expert to advise and answer questions from engineering and compliance teams on technical product security matters
Define and oversee the deployment of Software Composition Analysis (SCA) tools to compile SBOMs of software components, helping to identify known vulnerabilities and license compliance violations
Define and oversee the deployment of automated security testing tools into CI pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Secret Detection scanning tools
Manual penetration testing of web applications (backend and frontend).Manual penetration testing skills in the domains of cloud infrastructure, embedded/OS or mobile are desirable
Write custom scripts or unit test cases to check for vulnerabilities or broken/missing security controls
Recommend improvements to existing security scanning tools and processes, and propose new ones
Triage the findings from the automated security scanning tools
Validate potential security vulnerabilities to determine whether they are actual true positives, or false positives (i.e. non-applicable) in the product context. Write proof of concept exploits when necessary to achieve this
Assess the risk of vulnerabilities and threats in order to help the business determine their remediation priority order
Communicate the identified security issues to engineering and compliance stakeholders, and manage them throughout the SDLC process to ensure they are properly addressed