Senior Security Engineer (Application Security)
Job Summary
Positively disrupting an industry that has not seen any innovation in over 50 years Tekion has challenged the paradigm with the first and fastest cloud-native automotive platform that includes the revolutionary Automotive Retail Cloud (ARC) for retailers Automotive Enterprise Cloud (AEC) for manufacturers and other large automotive enterprises and Automotive Partner Cloud (APC) for technology and industry partners. Tekion connects the entire spectrum of the automotive retail ecosystem through one seamless platform. The transformative platform uses cutting-edge technology big data machine learning and AI to seamlessly bring together OEMs retailers/dealers and consumers. With its highly configurable integration and greater customer engagement capabilities Tekion is enabling the best automotive retail experiences ever. Tekion employs close to 3000 people across North America Asia and Europe.
As part of our world-class engineering team atTekion we are expanding ourApplication Security Engineeringfunction. Our development teams work across a variety of modern technology stacks in a fast-moving environment making security both a challenge and an opportunity to innovate.
We prioritizeguardrails over roadblocksin our security culture empowering developers to move fast while ensuring security is built in scalable and resilient. This role will partner closely with engineering teams to integrate security into all phases of the SDLC from design through deployment.
Leads application security initiatives acrossTekionsproducts and engineeringecosystem. Drives secure-by-design principles threat modelingDevSecOpsintegration vulnerability reduction developer enablement and scalable application security controls across web mobile APIs and cloud-connected systems.
Secure SDLC & Security Engineering
Drive integration of security across all phases of the software development lifecycle from design to deployment.
Partner with development teams to implement scalable application security controls standards and guardrails.
Promote secure-by-design principles across web mobile cloud APIs and distributed systems.
Threat Modeling & Architecture Reviews
Lead threat modeling exercises and security design reviews for high-impact systems services and product features.
Conduct architectural reviews and risk assessments for new capabilities services and major design changes.
Assistengineering teams inidentifyingpractical mitigation strategies and reducing design-level security risks early.
DevSecOps& Security Automation
Build and improve security automation within CI/CD pipelines.
Integrate andoptimizeapplication security tooling such asSAST DAST SCAsecretsscanningIaCscanning and API security controls.
Develop andmaintainreusable security patterns libraries and automation to reduce friction for developers.
Vulnerability Management Advisory
Review and help prioritize application security findings from internal testing third-party assessments and VAPT exercises.
Guide engineering teams on remediation of common vulnerability classes and secure coding improvements.
Interpret testing and assessment results and translate them into scalable engineering-friendly recommendations.
Security Enablement & Collaboration
Develop secure coding guidance patterns and developer-facing best practices.
Partner with product engineering cloud security and infrastructure teams toidentifyand remediate security risks early.
Participate in security education initiatives and promote strong security culture across engineering.
Bachelors orMasters degree in Computer Science Cybersecurity or related field; equivalent experience considered.
69yearsof experience in application security product securityDevSecOps or security engineering.
Strong understanding of information security fundamentals and ability to communicate them clearly to engineering and product teams.
Hands-on experience with secure codingDevSecOps and security automation.
Familiarity with application architecture threat modeling CI/CD pipelinesIaC serverlessandIAM.
Experience integrating security controls into developer workflows.
Proficiencyin at least one programming or scripting language such asPython Bash Java JavaScript or Go.
Strong collaboration skills and a pragmatic solution-oriented mindset.
Experience withOWASP Top 10 OWASP ASVS API security and modern software assurance practices.
Experience reviewing code and supporting remediation across modern application stacks.
Penetration testing experience is optional and good to have;abilityto interpret findings isrequired.
Industry recognized and accepted relevant certificationsare a plus.
Competitive compensation
Generous stock options
Medical insurance coverage
Opportunity to influence secure engineering practices across a modern product organization
Ownership of impactful security initiatives at scale
Innovative collaborative and fast-paced culture
Current Tekion Employees: Please apply via the Internal Job Board in Ashby
Note: Tekion recently transitioned to a new recruiting tool and we appreciate your patience and feedback as we adjust to our new system!
Tekion is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race religion color national origin gender (including pregnancy childbirth or related medical conditions) sexual orientation gender identity gender expression age status as a protected veteran status as an individual with a disability victim of violence or having a family member who is a victim of violence the intersectionality of two or more protected categories or other applicable legally protected characteristics.
For more information on our privacy practices please refer to our Applicant Privacy Notice here.
Required Experience:
Senior IC
About Company
One platform that seamlessly connects your entire automotive retail business. Unify DMS, CRM, Digital Retail, Analytics, and more. Request a demo.