Security Architecture:Develop, maintain, and enforce security architectures and standards for our software products.
Threat Modeling: Conduct comprehensive threat modeling assessments to identify potential vulnerabilities and risks.
Risk Management: Develop and implement risk mitigation strategies to protect our software and data.
Innovation: Stay abreast of the latest security trends and technologies, and incorporate them into our security practices.
Compliance: Ensure that our software products comply with relevant security regulations and industry standards.
Collaboration:Work closely with development teams to integrate security into the software development lifecycle.
Incident Response: Provide technical guidance and support during security incidents.
Education and Awareness: Conduct security training and awareness programs for development teams and other stakeholders.
Security Guidelines and Tools: Contribute the development and maintenance of secure-development guidelines and standards. Manage security tools, provide training, and assist developers in utilizing these tools and interpreting reports.
Code and Design Reviews: Initiate and participate in code reviews, design reviews, and other critical assessments to ensure security standards are met.
Qualifications
Bachelor’s degree in Computer Science, Information Security, or a related field.
6+ years of experience in software development
3+ years of experience in software security
Strong understanding of security principles, including authentication, authorization, encryption, and vulnerability management.
Experience with security frameworks and methodologies (e.g., OWASP, NIST, ISO 27001).
Knowledge of programming languages, scripting, and security tools.
Excellent problem-solving, analytical, and communication skills.
Ability to work independently and as part of a team.
Personal Attributes
Demonstrated leadership, motivational, and mentorship abilities.
Ability to think like a hacker and anticipate potential security threats.
Fluent in English, with excellent communication, presentation, and crowd-facing skills.
Experience with Agile development methodologies.
Preferred Qualifications
Certifications such as CISSP, CISM, or CSSLP.
Experience with cloud security and DevOps practices.
Knowledge of emerging security threats and trends.