Назад
Company hidden
14 часов назад

Cyber Product Security Engineer, Lead

Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Product Security Engineer, Lead (Application Security): Securing products across the software lifecycle through threat modeling, secure design reviews, vulnerability assessments, and security testing with an accent on embedding security controls into product development and managing application risk. Focus on implementing an Application Security Posture Management platform, coordinating incident response, and leading cross-functional security initiatives.

Location: Plano, Texas, United States

Company

hirify.global Financial Services is hirify.global and Lexus’s finance and insurance business, operating within hirify.global’s North American mobility organization.

What you will do

  • Lead threat modeling, secure design reviews, vulnerability assessments, and security testing with product engineering teams.
  • Integrate security requirements and controls into the product development lifecycle.
  • Oversee security risk assessments, mitigation plans, and product security posture across the software lifecycle.
  • Develop and implement product security policies, standards, architecture documentation, processes, and procedures.
  • Introduce an Application Security Posture Management platform to assess applications, services, and pipelines and prioritize risk remediation.
  • Monitor application security incidents and coordinate response and remediation efforts.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field; an advanced degree is preferred.
  • 8+ years of progressive experience in application security and secure software development practices.
  • Strong knowledge of web application vulnerabilities and mitigation strategies, including OWASP Top 10.
  • Proficiency in Java, Python, or JavaScript.
  • Strong analytical, problem-solving, leadership, and communication skills.
  • Must already have the right to work in the United States and must not require immigration-related employment sponsorship now or in the future.

Nice to have

  • CISSP, CSSLP, CEH, or a similar certification.
  • Experience with cloud security, containerization, and DevSecOps.
  • Experience developing cybersecurity policies, managing risk in regulated environments, understanding cybersecurity regulations, and responding to cyber incidents.

Culture & Benefits

  • Team-oriented, flexible, and respectful work environment.
  • Professional growth programs and tuition reimbursement.
  • Vehicle purchase and lease programs.
  • Comprehensive healthcare and wellness plans.
  • 401(k) savings plan with company match and annual retirement contribution.
  • Paid holidays, paid time off, family support services, and relocation assistance if applicable.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →