2 дня назад
Product Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Product Security Engineer (Cybersecurity): Maintaining and maturing a product security program for cloud-based software with an accent on DevSecOps, application security testing, and vulnerability remediation. Focus on integrating SAST, DAST, SCA, and API security tooling into CI/CD pipelines, reviewing system designs, and securing development, testing, and hosting environments.
Location: Hybrid in Mexico City, with office attendance on Tuesday, Wednesday, and Thursday at the Reforma office
Company
develops a cloud-native Identity Security Platform that secures human and machine identities through centralized authorization and AI-powered intelligence.
What you will do
- Maintain and mature product security tooling, including SAST, DAST, SCA, and ASPM solutions.
- Assess software vulnerabilities and guide developers and administrators through remediation.
- Secure environments used to develop, test, and host software and cloud-based services.
- Execute and improve the company’s secure software development lifecycle program.
- Perform security reviews of software system designs and configurations.
- Support teams in analyzing and responding to product and service security questions and issues.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- At least 2 years of professional experience in a product security role.
- Experience integrating security testing tools into CI/CD pipelines and using source code management systems such as ADO Repos, GitLab, or GitHub.
- Experience with SAST, DAST, IAST, SCA, containers, authentication and authorization methods, including OAuth, SAML2, Kerberos, and x509 certificates.
- Ability to script and automate with Python, JavaScript, PowerShell, or similar languages.
- Strong verbal and written communication skills for explaining technical concepts.
Nice to have
- Software engineering or development experience.
- Experience with ASPM tools and AI-assisted software security testing.
- Knowledge of NIST, BSIMM, OWASP Top 10, FedRAMP, or similar security frameworks and standards.
- Understanding of cloud security for containers, serverless functions, network segmentation, and access management.
- Cybersecurity certifications and proficiency with Azure and AWS.
Culture & Benefits
- Meaningful work protecting human and machine identities for large organizations.
- Collaborative, innovative environment focused on respect, integrity, ownership, and continuous adaptation.
- Competitive salary and a bonus program.
- Healthcare insurance, pension or retirement matching, life insurance, and an employee assistance program.
- Paid time off and company holidays.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →