Ver más Contraer

Sr. Product Security Engineer

hace 1 mes


Madrid, España Incode Technologies A tiempo completo

The Opportunity We seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting as our customers expect. We're looking for someone who loves to solve significant challenges in Product Security. These challenges include ensuring a secure software supply chain from idea to operation, providing software provenance, automating everything in CI/CD, and building and breaking software to make it more secure. To be successful as a Product Security Engineer, you should have hands-on experience securing the software supply chain and products of a SaaS and mobile-first company, enjoy partnering with fellow engineers, and be able to speak to the big picture of the SDLC and how to achieve a desired state in reasonable chunks. As an engineer, you should lead with a hacker mindset and be able to roll up your sleeves and design, architect, and threat model security critical solutions. Reporting to the Sr. Director of Information Security, you will be an early hire to the security team and will have the opportunity to influence and evolve our product security program. Responsibilities Partner with engineering and product management teams to perform threat modeling, architecture & design, and code reviews. Assess security implications, requirements for the secure development of new systems, features, and technologies.Provide hands-on remediation guidance to development teams and design security architecture, features and controls that keeps our customers' data safe and preserves their privacy.Build a security paved road through automation and tooling (SAST, SCA, MAST, IaC, DAST, Fuzzing, etc.) into the SDLC and CI/CD integrations that enables our developers to easily produce secure software.Define, architect, build, improve and validate secure software supply chain and build provenance mechanisms.Manage, triage, and provide support to external researchers in our vulnerability disclosure and bug bounty programs.Provide proof of concept exploits, facilitate vulnerability remediation, and drive adherence to software security standards through policy as code.You'll help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.Qualifications: Deep expertise in at least one domain: web application and browser security, mobile application security, applied cryptography, machine learning and artificial intelligence security, offensive security, cloud security, hardware security.Experience in software engineering, infrastructure engineering, site reliability engineering, or offensive security for a SaaS product company.Experience with a variety of security tooling, to include: SAST, DAST, SCA, IaC Scanning, Image and Container Scanning, MAST, IAST, and offensive security and proxy tooling.Deep expertise with common application security flaws, security controls, and common security libraries and identifying security issues through code review, threat modeling, penetration testing, and other techniques manually and with tools.You are a strong communicator who is comfortable working cross-functionally, with a track record of delivering results and demonstrating strong ownership.Extensive experience in SaaS product development and security space; securing complex interconnected web and mobile applications and their architectures using Python, Javascript, Swift, Java, C++, Kotlin, or any other modern language.You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.Preferred Experience and Certification: Have SaaS Startup experience in security-focused industries, such as fintech, security software and services, healthtech, and identity and access management.Experience with virtualization, containerization technology, orchestration, and cloud native security.Certifications in Security, Product Securityand/or Offensive Security (eg. OSCP, OSWP, OSEP, OSWA, OSED, OSMR, OSWE, OSEE, GPEN, GWAPT, CEH, etc).Cloud Certifications, such as AWS Certified Solutions Architect, AWS Security SpecialtyHands-on experience in offensive security, and CVEs to prove it.
#J-18808-Ljbffr


Tenemos otros empleos actuales relacionados con este campo que puede encontrar a continuación


  • Madrid, Madrid, España Incode Technologies A tiempo completo

    The Opportunity We seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting as...


  • Madrid, Madrid, España Incode Technologies A tiempo completo

    The Opportunity We seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and...


  • Madrid, España Incode Technologies A tiempo completo

    .The OpportunityWe seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting as...


  • Madrid, España Incode Technologies A tiempo completo

    .The Opportunity We seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting...


  • Madrid, España Incode Technologies A tiempo completo

    The Opportunity We seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting as...


  • Madrid, España Incode Technologies A tiempo completo

    The OpportunityWe seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting as...


  • Madrid, España Incode Technologies A tiempo completo

    .The OpportunityWe seek a trustworthy and proactive Senior Product Security Engineer (Privacy specialty) to be the technical thought leader and driver of a paved-road, holistic product security program. The Product Security Engineer works across various engineering groups in our organization to ensure that our products are as secure and privacy-protecting as...

  • Mid/Sr Security Engineer

    hace 2 semanas


    Madrid, Madrid, España Incode Technologies A tiempo completo

    The Opportunity We seek a trustworthy and proactive Mid/SR Security Engineer as a technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations program development,...

  • Mid/Sr Security Engineer

    hace 1 semana


    Madrid, España Incode Technologies A tiempo completo

    .The OpportunityWe seek a trustworthy and proactive Mid/SR Security Engineer as a technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations program development,...


  • Madrid, España Incode Technologies A tiempo completo

    .The Opportunity We seek a trustworthy and proactive Mid/SR Security Engineer as a technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations program...


  • Madrid, España Databricks A tiempo completo

    .RDQ324R8While candidates in the listed location(s) are encouraged for this role, candidates in other locations will be considered.The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing...

  • Mid/Sr Security Engineer

    hace 4 semanas


    Madrid, España Incode Technologies A tiempo completo

    The Opportunity We seek a trustworthy and proactive Mid/SR Security Engineer as a technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations program development,...


  • Madrid, España Incode Technologies A tiempo completo

    The OpportunityWe seek a trustworthy and proactive Mid/SR Security Engineer as a technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations program development,...

  • Mid/sr Security Engineer

    hace 2 semanas


    Madrid, España Incode Technologies A tiempo completo

    **REIMAGINE TRUST** Incode is the leading provider of world-class identity solutions that is reinventing the way humans authenticate and verify their identities online to power a world of digital trust. Through our revolutionary identity solutions, we are unleashing the business potential of universal industries including finance, government, retail,...


  • Madrid, España Okta A tiempo completo

    .Get to know OktaOkta is The World's Identity Company. We free everyone to safely use any technology-anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and...


  • Madrid, Madrid, España Okta A tiempo completo

    Get to know OktaOkta is The World's Identity Company. We free everyone to safely use any technology-anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and...


  • Madrid, España Incode Technologies A tiempo completo

    .The OpportunityWe seek a trustworthy and proactive Mid/SR Security Engineer as a technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations program development,...


  • Madrid, España Kudelski Security A tiempo completo

    Stimulating. Motivating. Challenging. Leveraging its long-standing expertise in securing digital content as well as fighting piracy, Kudelski Security, a division of the Kudelski Group, is a provider of cybersecurity solutions and services focused on protecting data, processes and systems for companies and organizations around the world, safeguarding...


  • Madrid, España Databricks Inc. A tiempo completo

    .While candidates in the listed location(s) are encouraged for this role, candidates in other locations will be considered.The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new...


  • Madrid, España Kudelski Security A tiempo completo

    Stimulating. Motivating. Challenging. Leveraging its long-standing expertise in securing digital content as well as fighting piracy, Kudelski Security, a division of the Kudelski Group, is a provider of cybersecurity solutions and services focused on protecting data, processes and systems for companies and organizations around the world, safeguarding...