Назад
Company hidden
3 часа назад

Cyber Product Security Engineer, Lead

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Product Security Engineer, Lead (Application Security): Securing products across the software lifecycle through threat modeling, secure design reviews, vulnerability assessments, and security testing with an accent on application security, risk mitigation, and cross-functional security leadership. Focus on implementing an Application Security Posture Management platform, prioritizing remediation across applications and pipelines, and coordinating incident response.

Location: Plano, Texas, United States. Must have the right to work in the United States without current or future Toyota visa or work authorization sponsorship.

Company

hirify.global provides mobility solutions, with Toyota Financial Services delivering finance and insurance products for Toyota and Lexus customers.

What you will do

  • Lead product engineering teams in applying threat modeling, secure design reviews, vulnerability assessments, and security testing.
  • Integrate security requirements and controls into the product development lifecycle in collaboration with product managers, engineers, and architects.
  • Oversee product security risk assessments, mitigation plans, policies, standards, and best practices.
  • Introduce and use an Application Security Posture Management platform to assess applications, services, and pipelines and prioritize remediation.
  • Monitor application security incidents and coordinate incident response and remediation activities.
  • Maintain product security architecture, process, and procedure documentation while tracking emerging threats and vulnerabilities.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field; an advanced degree is preferred.
  • 8+ years of progressive experience in application security and secure software development practices.
  • Strong knowledge of web application vulnerabilities and mitigation strategies, including OWASP Top 10.
  • Proficiency in Java, Python, or JavaScript.
  • Strong analytical, problem-solving, leadership, and communication skills for collaboration with technical and non-technical stakeholders.
  • Authorization to work in the United States without Toyota immigration sponsorship is required.

Nice to have

  • CISSP, CSSLP, CEH, or a similar certification.
  • Experience with cloud security, containerization, and DevSecOps.
  • Experience developing cybersecurity policies and managing risk in regulated environments.
  • Knowledge of cybersecurity regulations and laws, plus cyber incident response experience.

Culture & Benefits

  • Team-oriented, flexible, and respectful work environment.
  • Professional development programs and tuition reimbursement.
  • Comprehensive healthcare and wellness plans, paid holidays, and paid time off.
  • 401(k) savings plan with company matching and an annual retirement contribution.
  • Vehicle purchase discounts, a team member lease vehicle program where applicable, and relocation assistance where applicable.
  • Tax-advantaged health and dependent care accounts and family support referral services.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →