drjobs Application Security Engineer - EXTEND

Application Security Engineer - EXTEND

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

London - UK

Monthly Salary drjobs

£ 42000 - 52000

Vacancy

1 Vacancy

Job Description

JOB DETAILS

JOB BAND: C
CONTRACT TYPE: Permanent
DEPARTMENT: BBC Information Security
LOCATION: All UK
PROPOSED SALARY RANGE: 42000 - 52000 depending on relevant skills knowledge and experience. The expected salary range for this role reflects internal benchmarking and external market insights.


Were happy to discuss flexible working. If youd like to please indicate your preference in the application though theres no obligation to do so now. Flexible working will be part of the discussion at offer stage.

PURPOSE OF THE ROLE


The BBC Information Security Team works with BBC teams around the world to provide expert advice review systems and deal with threats. We ensure risks are identified managed and mitigated. We are a multi-disciplinary team who work together and with the rest of the business to ensure the BBC stays secure and our audience trust is protected.


Youll be joining the Security Engineering & Architecture team in Information Security. The teams focus is to ensure the BBCs digital products and platforms are secure by leveraging our collective development and security experience. To ensure security requirements are considered and implemented we work with product teams during the early stages of the SDLC and provide our expert technical advice to allow them to progress effectively. The team also designs develops and deploys systems and processes to help teams understand the risks in their own systems.
Another key part of the teams function is to foster relationships across the business and ensure that security issues are discussed and actioned rather than ignored. The team runs a large network of Security Champions across the BBC which focuses on awareness and education of technical security topics which helps amplify Information Securitys effectiveness. The team also provides technical expertise to other areas of the wider Information Security Team and BBC.


WHY JOIN THE TEAM


The BBC reaches over half a billion people online every week. By joining this team you will help keep these systems secure. Youll regularly collaborate with critical BBC product teams such as iPlayer Sounds and News.
Youll also get continual exposure to the latest security vulnerabilities the new technologies teams are leveraging and the security considerations around these technologies. Youll also become a key part in helping to evolve our digital security strategy and drive transformation within the BBC.

YOUR KEY RESPONSIBILITIES AND IMPACT

Digital Policy & Guidance

o Contribute to the BBC Security Champions network by engaging with the champions.
o Help deliver training and internal sessions to build engineering and product security awareness.
o Share technical insights with broader InfoSec through demos playbooks and documentation.

Development

o Develop and maintain security tooling automation and platforms that support the InfoSec function
o Contribute code and engineering support to Infosec platforms and systems
o Work closely with the senior team members to design and build security solutions

Vulnerability Management

o Assist with application security tooling and interpreting results (e.g. SAST/DAST outputs).
o Support vulnerability validation and triage efforts across cloud-native and on-prem systems.

YOUR SKILLS AND EXPERIENCE


ESSENTIAL CRITERIA

Familiarity with at least one programming language (e.g. Python JavaScript etc) with demonstrable experience of building and developing digital software projects using this language.

Ability to explain technical concepts to both technical and non-technical stakeholders.

Demonstrable experience learning collaboratively with others on technical concepts and using this to break down complex problems.

Demonstratable experience of some technical security knowledge and common security vulnerability categories.

Experience leading building or actively engaging in a community through roles such as coordinating events engaging with members and/or attracting new members

DESIRED BUT NOT REQUIRED:

Familiarity with threat modelling (STRIDE or similar) secure coding best practices and DevSecOps principles.

Experience contributing to open-source or internal engineering tools.

Experience deploying operating and troubleshooting applications in AWS environments.

Participation in security or developer communities and/or experience in mentoring or leading peer education sessions.

Familiarity with CI/CD pipelines infrastructure as code (e.g. Terraform) and container security.


If you can bring some of these skills and experience along with transferable strengths wed love to hear from you and encourage you to apply.

Employment Type

Full-Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.