In this role you will scope and lead focused security reviews on critical internet scale applications and supporting infrastructure. You will learn the services architecture and risk profile to build a scope that enables a meaningful security review. You will be:A technical expert responsible for the enumerating risks or exploit chainsCapable of identifying scope of engagement planning reviews and executing those reviews to identify vulnerabilities and improvement opportunitiesAble to identify areas that are ripe for improvement and establish appropriate security goalsAdept at building relationships with engineering and leadership teams to drive security improvementsCurrent on new security technologies vulnerabilities and methodologiesAn excellent verbal and written communicatorAble to develop proof of concept systems to automate security recommendations vulnerability discovery and process workflows
8 years in an information security field or software engineering; four or more of those years conducting security reviews
Extensive infrastructure cloud and application security experience
Experience clearly communicating risk to engineering and leadership teams
Ability to reason about security of a large and complex application or infrastructure
Experience going deep on complex systems for extended engagements
Bachelors degree in Computer Science / Engineering or a related with emphasis in security related fields (or equivalent experience)
Experience constructing narratives and building exploit chains
Ability to reason about and influence software architecture for security
Community contributions like public CVEs bug bounty recognition open source tools blogs talks etc.
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.