Назад
Company hidden
10 дней назад

Product Security Specialist (IoT)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Specialist (IoT): Evaluating connected transportation products through source-code analysis, automated scanning, penetration testing, and architectural security reviews with an accent on vulnerability validation, secure coding, and security automation. Focus on tracing vulnerabilities across diverse codebases, integrating scanners with CI pipelines and cloud storage, and designing threat models and secure architectures.

Location: Atlanta, Georgia, USA; flexible hybrid working model with support for in-person and virtual work.

Company

hirify.global develops IoT and connected transportation products, web-based fleet analytics, and an open platform for integrating vehicle data.

What you will do

  • Review internal and external products using source-code, dynamic, dependency, and architectural security assessments.
  • Trace scanner findings across C#, .NET, Java, JavaScript, TypeScript, HTML, Swift, Kotlin, Python, C, and firmware codebases, then provide remediation guidance.
  • Conduct vulnerability assessments, penetration testing, threat modeling, manual code reviews, and secure architecture reviews.
  • Develop and maintain Bash and Python automation for scanner execution, CI pipeline integration, cloud storage, and reporting.
  • Explain risk assessments and write vulnerability reports for developers, product owners, and management.
  • Collaborate with development, security operations, and global stakeholders to improve security-by-design practices and product security posture.

Requirements

  • 5–8 years of experience in security evaluation, security analysis, security code reviews, or relevant software development.
  • Bachelor’s degree in Computer Science, Information Management, Engineering, or a related field, or equivalent experience.
  • Experience with source-code, dynamic, and dependency scanners such as Veracode, Fortify, Sentinel, OWASP Dependency-Check, Netsparker, or Qualys.
  • Knowledge of C, C#, .NET, Python, JavaScript/TypeScript, XML, JSON, SOAP, REST, npm, and NuGet.
  • Competency with Linux, Windows, Google Cloud Engine, Bash, and Python, plus the ability to learn new programming languages quickly.
  • Eligibility to work in the United States is verified through E-Verify.

Nice to have

  • Security certifications.
  • Experience in a technical or high-technology engineering industry.

Culture & Benefits

  • Flexible hybrid work supported by cloud applications, collaboration tools, and asynchronous working.
  • Home office reimbursement and online learning and networking opportunities.
  • Medical and dental benefits, a retirement savings program, and parental leave top-up program.
  • Electric vehicle purchase incentive program and work-life balance initiatives.
  • Benefits listed above are available to full-time permanent employees only.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →