Назад
10 часов назад

Senior Product Security Engineer (Cybersecurity)

215 000 - 230 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

Senior Product Security Engineer

Company

TRM Labs

Conditions

1 day agoSeniorSalary: 215K - 230KNorth America Remote Full Time Cybersecurity Jobs by TRM Labs

Skills

Secure Coding Red Teaming Bug Bounty Authorization Owasp Secure Sdlc Sca Owasp Zap Cwe Burp Suite Platform Security Authentication Node.Js Agile Aws Gcp React Vulnerability Management Python Application Security Threat Modeling Burpsuite Threat Dragon Sast Dast Encryption Penetration Testing

About the Role

You will lead application security reviews and threat modeling, perform secure code reviews, and test product security across services. You will develop automated security testing, mature the Secure SDLC, own vulnerability management and coordinate penetration testing. You will support engineers with security best practices, run the bug bounty program, bootstrap platform security initiatives, and provide just-in-time secure coding training and mentorship to engineering teams.

Requirements

  • Minimum 8 years of experience in Software Development and testing
  • BS or equivalent in Computer Science, Computer Engineering, or related field
  • Proficiency in Python, NodeJS, React
  • Strong understanding of encryption, authentication, and authorization protocols
  • Deep experience with common software flaws (e.g., OWASP and CWE) and testing methodologies
  • Experience with SAST, DAST, and SCA tools and Github advanced security
  • Professional experience with cloud providers such as GCP and AWS
  • Experience with threat modeling tools (e.g., OWASP Threat Dragon)
  • Experience with web application testing frameworks such as BurpSuite and OWASP ZAP
  • Experience triaging and remediating vulnerabilities in software packages or libraries
  • Experience conducting code security reviews regularly
  • Experience in agile-based software development roles
  • Experience with red teaming or penetration testing applications and infrastructure
  • Strong written and verbal communication skills
  • Security certifications such as OSCP, CEH, GWAPT are a plus
  • Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus

Responsibilities

  • Lead application security reviews and threat modeling
  • Perform secure code reviews and security testing
  • Develop automated testing and mature the Secure SDLC
  • Own application security vulnerability management
  • Coordinate penetration testing engagements
  • Support software engineers and product teams with security best practices
  • Develop and maintain the bug bounty program
  • Bootstrap platform security initiatives to protect data
  • Foster security champions and deliver secure code training

Benefits

  • Eligibility to participate in TRM's equity plan

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -