- Identify security threats in applications and infrastructure and provide remediation mentorship to system owners by performing security certifications/review.
- Drive Security certification activities like architecture reviews, threat modeling, source code reviews, penetration testing, cloud security audit etc.
- Build tools to automate repeatable/reusable security processes and frameworks.
- Promote secure by design and secure by default development strategies.
- To own and drive the resolution of different security events, policy questions, and technical security risks.
- Support the security risk acceptance and exception processes, when required.
Your experience should include...
- 7+ years of security engineering experience with expertise in Secure Development Lifecycle.
- Problem-solver with excellent interpersonal skills, and a deep technical understanding of security engineering.
- Required scripting skills in JS/Python.
- Experience in manual code reviews to assess consistency to secure coding standards, and compliance with project security requirements.
- Applying tooling to perform static code analysis and identifying security vulnerabilities.
You might also have...
- Experience in developing software applications or security automation tools.
- DevSecOps experience with a focus on integrating SAST tools with the CI/CD pipeline