In this role, you will join a growing Product Security team and will be empowered to shape the organization and secure design and development practices to build best-in-class, cloud-native products and platforms on. You will own the new acquisitions and bring them up to HON security standards and adopt Product Security practices in the SDLC lifecycle.
RESPONSIBILITIES
- Review & Negotiate Product Security Terms & Conditions on Customer Contracts & 3rd Party Sofware Contracts
- Negotiate Product Security Terms & Conditions with senior security leaders the likes of CISO/BISO of Fortune 100 companies
- Design and Implement Secure SDLC practices that integrate regulatory requirements such as EU CRA, NIS2, FedRAMP
- Stay on top of evolving regulatory requirements, educate security and engineering leadership, and strategize on what to change in organization policy, standards, procedures, and practices
- Work with the SOC 2 Compliance Team to evaluate SOC2 certifications and mature the capabilities to ensure continuous compliance
- Design data protection practices & review data security implementation against data protection practices
- Closely work with legal teams to perform product security evaluations of partnerships and suppliers
- Be data-driven in the approach of managing vulnerabilities and create metrics to inform leadership on the state of security posture on a monthly basis
- Partner with the Director of Cloud Security Architecture to drive the security strategy and provide input into cloud security patterns to develop zero-trust architectures
- Lead and coordinate local cross-functional activities to support incident response
- Hire & build great talent by inclusivity, learning, and inspiring others to build a world-class product security team
YOU MUST HAVE:
- Minimum 10+ years of experience in the software and/or application security space
- 3+ years of strong technical skills in AWS, GCP, or Azure
- Security certifications such as CISSP, CCSP, CSSLP, CompTIA+ etc...
- Bachelor’s degree from an accredited institution in a technical discipline such as the sciences, technology, engineering, or mathematics
- Demonstrated strong knowledge of secure SDLC and practices such as threat modeling, security reviews, penetration tests, and security incident response
- Demonstratable strong interpersonal skills with the ability to facilitate diverse groups, help negotiate priorities, and resolve conflicts among project stakeholders
- Understanding of Zero Trust Architecture principles
- Ability to travel worldwide up to 10%-20%
WE VALUE
- Bachelor’s or Masters degree in computer science, MIS or cyber security
- Experience with PCI, FISMA, HIPAA, GDPR or similar would be preferred
- AWS or Azure Architecture or Developer certification
Additional Information - JOB ID: req455307
- Category: Engineering
- Location: 715 Peachtree Street, N.E.,Atlanta,Georgia,30308,United States
- Exempt