Completes the Identification, measurement, control and minimization of security risks to information systems across a broad range of disciplines including application and host security.
Develops and implements repeatable application security architecture patterns working with internal and external partners to ensure that systems are placed within the relevant security zones based on the data they house and their purpose.
Contributes to the development of Early Warning security policy and procedures.
Develop Threat Models, design and develop Security architectures and publish reference architecture/patterns implementations for Products and drive companywide adoptions.
Supports Product and Stakeholder teams efforts in building Cloud Native applications by implementing and engineering Cloud Security and Microservices Security best practices and industry standards.
Document and present risks and security issues that could impact the confidentiality, integrity and/or availability of the business (both internally and externally) by assisting in documentation, tracking and creating solutions for mitigation.
Develop reference engineering implementations of Security patterns and Security Guardrails into Software frameworks and technology stack.
Support and implement Security technology and security control design proof of concepts and implementations.
Contribute and further integration of Secure Development lifecycle into product implementation and engineering efforts.
Evaluates all product business cases including functional and security specs to ensure security standards are met.
Support efforts with Product Development and Engineering teams to perform security analysis on all internally developed products and services.
Participates in the development of EWS DevSecOps security strategy and posture by designing, advocating and helping build secure-by-default CI/CD pipelines and processes.
Identifies opportunities for automation, develop and build integrations for security automated scans and establishes patterns for product and infrastructure automated security.
Builds and maintains automation in and improvements in the build and deployment pipelines that are part of Continuous Integration (CI) and Continuous Deployment (CD).
Provide support and technical guidance and foster a collective understanding of secure development and deployment of products and infrastructure.
Assists in the implementation of DevSecOps methodologies while addressing requirements and orchestrating security impact.
Implements, tests, and supports the development of CI/CD pipelines in Gitlab, Harness and deployment of cloud native configuration management solutions using 3rd party tools.
Works with architecture teams to ensure that all newly developed and legacy applications and infrastructure implementations are in line with security policy and are compliance to the required frameworks (ISO, PCI, OWASP, NIST 800-53, etc.).
Support the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data.
Requirements
Education and experience typically obtained through completion of a bachelor’s degree in computer science, Engineering, Math or Physical Science.
A minimum of 4 years of combined work experience including experience gained with an advanced degree in relevant field.
Combined 3 years of application security, Security Architecture, Consulting, related IT or Information Security experience.
Application development and/or Software Security background.
Experience in Threat Modeling and control implementation.
Exposure to Agile SDLC process.
Advanced knowledge of operating system, application, network, and database security architectures.
Experience in designing security for Cloud hosted products and containerized workloads.
Knowledge of Security Integration into CI/CD and experience in driving CI/CD adaptation for Security controls.
Hands-on experience with a diverse range of cloud security technologies and access management, Kubernetes, mitigation, encryption technologies, security information, threat management and infrastructure as code (IaC).
Demonstrate advanced understanding in the field of Information Security in terms of both concepts and technology.
Able to work with both technical and business stakeholder to design solutions that bring optimal security posture to products and infrastructure.
Working knowledge of one or more general purpose programming/script languages including but not limited to Java, C/C++ and Python.
Tech Stack
Cloud
Java
Kubernetes
Microservices
Python
SDLC
Benefits
Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
12 weeks of Paid Parental Leave
Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.