Software Guidance & Assistance, Inc. (SGA, Inc.) is seeking a Product Security Engineer for a contract assignment with one of their premier SaaS clients. The role involves managing vulnerability backlogs and risk hygiene while partnering with engineering product teams to ensure security best practices are adhered to.
Responsibilities:
- Act as the technical security point-of-contact when partnering directly with engineering product teams
- Strategically prioritize the risk reduction of vulnerabilities
- Drive vulnerabilities to remediation within SLA
- Act as the lead security contact during incidents
- Own metrics and escalations, such as Time-To-Remediation and SLA adherence, to ensure visibility of engineering product team's risk posture
- Identify and implement strategic improvements and paved road solutions to improve resilience
Requirements:
- Over 4 years of experience in vulnerability management
- Vulnerability Management / Triage
- Vulnerability Risk Assessment
- Vulnerability Incident Response
- Knowledge of application security vulnerabilities (OWASP Top 10) and mitigation techniques
- Knowledge of infrastructure vulnerabilities, mitigation techniques, and tooling (e.g. Spotlight Crowdstrike, Rapid7 Nexpose)
- Dependability: Meets commitments, works independently, accepts accountability, handles change, sets personal standards, stays focused under pressure
- Strong understanding of common security concepts that support root-cause analysis to make data-driven decisions on vulnerability patterns and trends
- Ability to speak and communicate professionally