Application & Product Security Principal
Global Relay Voir toutes les offres
- Vancouver, BC
- 125.000-160.000 $ par an
- Permanent
- Temps-plein
- Extensive experience in Application Security, Product Security or DevSecOps roles
- Deep understanding of secure software development practices, including threat modeling, secure coding and vulnerability management
- Serve as the liaison for deployment of DevSecOps standards and input into new standards or policies
- Embed security and DevSecOps practices throughout the organization, within SDLC and support an automated continuous integration (CI) and continuous delivery (CD) system
- Work with APIs and plugins to integrate security tools into established CI/CD pipelines using agile delivery methodology
- Partner with developers and engineering teams to prevent vulnerabilities and 'shift-left' security testing in the SDLC
- Focus on automation to aid in efficiencies with both testing and development
- Provide hands-on technical expertise and support in general DevSecOps tasks
- Review and analyze vulnerability data to identify security risks to the organization's network, infrastructure, and applications, and effectively address false positives
- Investigate security issues in order to determine specific steps for reproduction and scope of vulnerabilities and risks
- Provide encouragement to team members, including identifying areas for additional training or skills development
- Mentor less experienced members of the team to help build a strong culture, improve security efficacy, and oversee team member work for quality and guideline compliance
- Create security documentation and developer training material
- Improve test case documentation and grouping
- Act as the senior subject matter expert for Global Relay software security testing related to the CI/CD pipeline
- Lead the selection, deployment, and management of appropriate scanning tools for security testing in the CI/CD pipeline
- Develop competency in the OWASP Top 10 and derive new test methodologies based on Global Relay applications
- Work with Application and Product Security Team Lead to identify areas where security test coverage is lacking, and work to improve the security test coverage
- Provide suggestions on improvements and see these through to completion
- 8+ years of application security and operations experience and expert knowledge of software security
- Experience with at least one of each of the following:
o SAST, DAST, SCA
o Python, Java, Bash, PowerShell
o Puppet, Ansible, Git repositories, Jenkins, Docker/Podman, CI/CD technologies
o Container - OpenShift / Kubernetes
o API security * Working with Security, Developers, DevOps, and Engineering teams in a dynamic environment
- Secure development, coding, and engineering practices
- Experience with the following would be an asset:
o ISO 27000, SOC 2, GDPR and other security and privacy standards
o CISM, CISSP, OSCP, or other relevant security certifications
o Networking technologies, particularly with OSI layers and TCP/IP
o Web-based protocols, including cookie management, encrypted traffic, TLS, HTTPS, HSTS, and webhooks
o Security tools such as firewalls, IDS/IPS, anti-virus, anti-spam, and server and network device hardening
o Encryption protocols and methodologies * Ability to work under broad supervision with little instruction
- Ability to communicate effectively, in both written and verbal forms, with technical and non-technical cross-functional teams.
- Ability to communicate diplomatically and effectively at all levels of the organization with all classifications, including the very technical
- Proven competence using MS Office and other desktop applications
- Methodical and creative approach to problem-solving
- Excellent verbal and written communication skills
- Strong attention to detail and follow-up