Selling Partner Service is looking for an experienced and self-driven Senior Security Engineer to join our team. We are looking for a self-starter with the drive and conviction to do things right the first time and challenge the status quo. You will be a thought leader in the team. You will actively contribute to our security strategy and its implementation. You will lead information security engineering projects to safeguard our services and data. You will perform risk assessments, threat modelling, security reviews and vulnerability remediation. You will design and implement security mechanisms, processes and tools to protect against risks. You will participate in architectural and system design discussions and share your security expertise with technical and business stakeholders across the organization, from engineers to executives. You will collaborate with other security team and share best practices across the organization. The ideal candidate for this role is a security technical expert with experience in technical leadership on large-scale systems.- Methodical, empirical and experimental in approach and evaluation without being bound by over paralysis-by-analysis;
- Work to improve knowledge of the security field, threat landscape, security intelligence, moving proactively toward prevention and detection of threats;
- Be a learner and curiosity seeker, focusing on what can be done rather than hindered by notions of what cannot be;- Have excellent time management skills along with the ability to deliver results in the face of uncertainty; and
Key job responsibilities- Identify and prioritize security problems that can be detected using automation.
- Develop detection prototypes for these security problems to enhance our tool-set for static and dynamic analysis.- Identify opportunities to prevent security problems at scale.
- Develop prototypes to prevent these security problems.
- Document and provide security guidance that will be used across Selling Partner Foundation.
- Deliver metrics to show effectiveness of our security initiatives.
- BS/B.Tech in Computer Science, Information Security, or equivalent professional experience.
- 5+ years of experience in application security, product security, or systems security.
- 5+ years writing production-level code in at least one scripting or compiled language such as Java, Python, JavaScript, Go, Ruby, C# or C/C++
- Proven experience in threat modeling, code reviews, security testing, vulnerability detection, attacker exploit techniques, and methods for their remediation.
- Strong technical understanding of OWASP Top 10 and application security concepts.
- 5+ years of experience securing cloud services, preferably AWS.
- A strong understanding of payments processing and financial services technologies.
- Master’s degree in Computer Science, Information Security, Computer Engineering or equivalent.
- Relevant industry certifications from SANS, GIAC, CISSP, OSCP, etc.
- In-depth technical understanding of OWASP Top 10, and SANS 25 vulnerability identification and remediation.
- Experience with securing financial and payment processing systems, evaluating from Layer 3 to Layer 7 and with end-to-end security ownership.
- Excellent written and verbal communication skills with the ability to adapt messaging to technical and non-technical audiences at all levels including senior leadership.
- History of working autonomously and delivering results in a fast-paced, highly ambiguous environment.
- Experience driving multiple technically complex security initiatives while remaining effective at providing security guidance to stakeholders.
משרות נוספות שיכולות לעניין אותך