drjobs Senior Product Security Engineer

Senior Product Security Engineer

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

San Francisco, CA - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

About GoodLeap:
GoodLeap is a technology company delivering bestinclass financing and software products for sustainable solutions from solar panels and batteries to energyefficient HVAC heat pumps roofing windows and more. Over 1 million homeowners have benefited from our simple fast and frictionless technology that makes the adoption of these products more affordable accessible and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeaps proprietary AIpowered applications and developer tools to drive more transparent customer communication deeper business intelligence and streamlined payment and operations. Our platform has led to more than $27 billion in financing for sustainable solutions since 2018.
GoodLeap is also proud to support our awardwinning nonprofit GivePower which is building and deploying lifesaving water and clean electricity systems changing the lives of more than 1.6 million people across Africa Asia and South America.

Position Summary
The GoodLeap security team is responsible for both business enablement and safeguarding the organizations information assets; it is involved in virtually all aspects of the business from product safety and resilience to building security paved roads customer partner and regulatory trust managing technology governance and compliance and ensuring the privacy and safety of GoodLeaps customers partners and employees information.
The product and application senior engineer role provides a unique opportunity to shape the security and resilience of GoodLeap products services and applications. In this role you will work closely with the product engineering and business teams within GoodLeaps business units acting as the key individual with both the authority and responsibility to ensure the safety and resilience of the products and services developed and operated by the business unit.
You will be embedded within the business unit and have a dottedline reporting relationship to the product or business lead for the unit.

Your oversight will encompass:

Product features:Identifying potential misuse and abuse cases proposing features to address these scenarios and defining product features to meet resilience requirements.
Buildtime controls: Managing application security controls and activities during development.
Runtime controls: Overseeing security measures for deployed products.
Additionally you will represent all areas of security for the business unit(s) you are embedded in spanning governance risk and compliance (GRC) to security monitoring. You will also have the authority and ability to involve other security team members as needed.
While you will take on multiple responsibilities from advisor to builder and beyond your primary focus will be designing and building product security services and processes creating product and application security patterns and practices and fostering strong relationships with product business and engineering teams.

Essential Job Duties and Responsibilites

    • Lead participate in and contribute to partnerships between security engineering product and operations teams to build orchestrate and automate security controls and services in GoodLeap products and services.
    • Define and refine processes such as threat modeling embedment models and the prioritization of features defects and vulnerabilities.
    • Assist the red team with ongoing activities including bug bounty programs and continuous penetration testing platforms.
    • Support or develop components of the security analytics platform.
    • Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
    • Contribute to investigations threat hunting and incident response activities in a supporting role. Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations incidents and playbooks may address security fraud privacy resilience and related concerns.
    • Ensure technical alignment for the products and services you oversee with team initiatives including GRC security operations and monitoring and response activities.

Required Skills Knowledge and Abilities


Job duties include additional responsibilities as assigned by ones supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities reassign or transfer job position or assign additional job responsibilities subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment perform the essential functions of the job or enjoy the benefits and privileges of employment as required by the law.


Required Experience:

Senior IC

Employment Type

Full-Time

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.