Full-Time Senior Security Software Engineer
Job Description
What you’ll be doing:
- Build relationships with software development teams to establish automated security controls embedded in the software development lifecycle
- Leverage the latest technologies in codification of security to represent organizational security policy through automation and software delivery mechanisms
- Drive DevSecOps through secure container image management lifecycles, increasingly stronger quality gates for code promotion, and fast feedback loops as close to the point of change as possible
- Ensure that the company maintains a strong security posture, leveraging best practices around application security, compliance with regulations and safeguarding Deem customer data
- Keep-up with current and emerging security alerts, trends, and issues
- Play a key role in Deem’s transition to the cloud, implementing/recommending security focused cloud centric solutions and setting policies accordingly
- Assist with the monitoring of all security systems and their corresponding or associated software, including Deem’s applications, firewalls, intrusion detection systems, cryptography capabilities, and anti-virus software
- Ensure the security of databases and data transferred both internally and externally
- Capable of performing penetration testing against Deem systems in order to identify system vulnerabilities
- Analyze and prioritize vulnerabilities coming from results of internal and external scans
- Leveraging the SIEM, monitor application logs, server logs, firewall logs, intrusion detection logs, and network traffic for unusual or suspicious activity. Interpret activity and make recommendations for resolution.
- Recommend (where appropriate) applying fixes, security patches, and any other measures required in the event of a security breach.
- Recommend / test new security software and/or tools and technologies
- Coordinate information protection effort to comply with industry standard audits including SOC2, PCI, and ISO 27001
What you’ll bring to the table:
- 7+ years in a similar position or experience in the security field
- Experience embedding security controls into application development methodologies
- Fluent with the latest technologies to codify security and compliance such as InSpec, Sentinel, etc.
- Leverage latest security frameworks such as NIST, CIS, Cloud Security Alliance, etc. along with threat intelligence sources to ensure hardened positions and strong postures
- Experience conducting security assessments and improving velocity in a Continuous Delivery/DevOps/Cloud environment
- Experience with web application security scanning and penetration testing with close collaboration with software engineering teams to strengthen and harden applications
- Fluent with OWASP and strong understanding of web application security threats (XSS, code injection, etc.) along with other industry standard application security standards and frameworks
- Capable of running, analyzing and recommending solutions based on internal/external network scans as part of vulnerability management program
- Familiarity with network equipment and software such as switches, IDS/IPS, firewalls, VPN, SIEM, WAF, and endpoint security along with a variety of assessment tools
- Splunk Enterprise Security fluency a strong preference
- Cisco Firepower fluency a strong preference
- Qualys VMDR fluency a strong preference
How to Apply
Please send your resume to cpringle@deem.com or simply apply by using this link please indicate where you did find the position. Cheers! Chad137 total views, 0 today