Apply📍 USA
💸 105000 - 190000 USD per year
- Experience performing threat modeling and architecture reviews for complex applications.
- Proven experience in application, cloud, and mobile penetration testing in high-risk environments like financial or healthcare companies.
- 2-4 years of Technical Product Security experience around SSDLC tooling, automation, remediation advisory, security testing, threat modeling/attack surface analysis.
- Ability to execute in multifaceted and highly technical organizations.
- Ability to provide pragmatic security advice for web, mobile, and cloud applications.
- Experience working in Agile development with technologies such as application security testing tools (SAST, DAST, etc.), Infrastructure as code (Terraform, etc.), Java Spring Framework, andContainers (Docker, Kubernetes, etc.)
- In-depth knowledge of common application & network protocols, cryptographic primitives, and common security threats.
- Deep knowledge of cloud operational models and secure SaaS architecture in containerized microservices.
- Identifying security issues within the product.
- Design and develop security tools and processes to be leveraged by development teams.
- Work closely with engineering to sustain processes and/or convert manual integrations to automated activities.
- Assist in developing custom Security as Code solutions.
- Participate in expanding/maturing the Navan S-SDLC program.
- Review product designs for security defects, perform threat modeling and recommend remediations.
- Provide training and guidance to development teams early in the SSDLC.
- Cultivate security ownership in product teams.
- Bring visibility to product/application vulnerabilities for proper prioritization and remediation.
DockerAgileHibernateCSSJavaJavascriptJenkinsKubernetesSpringJavaScriptJiraJava SpringAngularCommunication Skills
Posted 2024-10-18
Apply