Overview
Build mission-critical infrastructure and practices that support application security for TRM products as they are built and deployed. Work with engineering and engineering leadership on technical strategy, company-wide best practices and implementation.
What you'll do
- Lead application security reviews and threat modeling, including secure code review, architectural design and testing.
- Develop automated testing and mature the Secure SDLC.
- Own and perform application security vulnerability management.
- Coordinate penetration testing engagements.
- Support software engineers and product teams by developing application security best practices.
- Develop and maintain the bug bounty program.
- Bootstrap platform security initiatives that help protect TRM data.
- Foster security champions within engineering teams and coordinate secure code training to inspire a culture of security across the engineering organization.
- Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business.
- Embed security testing and reviews within the Product Shipping Framework and CI/CD pipelines.
- Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews.
- Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments.
What you'll need
- Minimum 8 years of experience in software development and testing.
- BS (or equivalent) in Computer Science, Computer Engineering or a related field.
- Proficiency in software development languages: Python, NodeJS and React.
- Strong understanding of encryption, authentication and authorization protocols.
- Deep experience with common software flaws, including OWASP and CWE, testing methodologies and common security tooling for testing.
- Professional experience with open source, commercial or native security solutions for cloud providers such as GCP and AWS.
- Experience with modern secure software development lifecycles, threat modeling and best practices.
- Experience conducting efficient and comprehensive code security reviews on a daily or weekly basis.
- Experience triaging and remediating vulnerabilities in software packages or libraries.
- Experience with software security tools such as GitHub Advanced Security or other SAST, DAST and SCA tools.
- Experience with web application testing frameworks such as Burp Suite and OWASP ZAP.
- Experience with threat modeling tools such as OWASP Threat Dragon.
- Experience working in a previous agile-based software development role.
- Experience red teaming or penetration testing applications and infrastructure.
- Professional experience with cloud providers such as GCP and AWS, modern secure software development lifecycles and best practices.
- Strong written and verbal communication skills.
Nice to have
- Security certifications such as OSCP, CEH or GWAPT.
- Familiarity with security frameworks such as NIST SP 800-171 and SSDF.
Details
- Location: United States.
- Team time zones include Eastern Standard Time (EST - GMT-4), Pacific Standard Time (PST - GMT-7) and Central European Summer Time (CET - GMT+2).
Read the full description and apply on the company’s own careers page.