Senior Application Security Engineer

United Kingdom - Oxford

Veeva Systems

Veeva Systems Inc. is a leader in cloud-based software for the global life sciences industry. Committed to innovation, product excellence, and customer success, Veeva has more than 1,100 customers, ranging from the world's largest...

View company page

Veeva is a mission-driven organization that aspires to help our customers in Life Sciences and Regulated industries bring their products to market, faster. We are shaped by our values: Do the Right Thing, Customer Success, Employee Success, and Speed. Our teams develop transformative cloud software, services, consulting, and data to make our customers more efficient and effective in everything they do. Veeva is a work anywhere company. You can work at home, at a customer site, or in an office on any given day. As a Public Benefit Corporation, you will also work for a company focused on making a positive impact on its customers, employees, and communities.
The Role
Veeva’s Security Engineering Team is seeking Application Security Engineers to help keep Veeva secure and safe. Our team in Columbus is growing, and we want you to join us! This role has a broad scope, ranging from developing Dev Sec Ops automation services, to system integrations using APIs, Webhooks, or other custom integrations of Veeva’s infrastructure. Development of automated processes of security tools, the coloration of data through analytics, and the design of integrated dashboards tools across our multiple platforms. This role presents an ultimate test of one’s security knowledge and ability, along with the support of a team of highly skilled individuals.

What You'll Do

  • Work closely with teams throughout Security, such as the Threat Intelligence, Application Security and Security Operations teams, as well as provide technical leadership and advice to teams and leaders throughout Veeva.
  • Direct contact with numerous teams in a variety of business platforms, giving you firsthand knowledge about how Veeva is built and how it operates at a deep, technical level.
  • Leverage the knowledge you gain about Veeva to find new ways to break software and processes throughout the company.
  • Show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals.
  • Demonstrate resilience and navigate difficult situations with composure and tact.
  • Provide thought leadership for the organization as you discover, invent and innovate throughout the course of their duties.
  • A strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Veeva and its customers secure.
  • Understanding of OSWAP Top 10, SANS Top 20, NIST 800-53, CIS, CSC or other security standards
  • Strong coding skills in at least one primary languages such as Java or Python. 
  • Integration of security tools through API’s, webhook or other custom integration.
  • Conduct full life cycle engagements with business units independently, or as part of a team.
  • Create and maintain integrated security dashboards pulling multiple security systems into a unified global view.
  • Develop and maintain global ticket management dashboard consolidating data from tools such as JIRA, FreshService, and Veeva applications.
  • Create automated Security Incident Response system to move playbooks to an automated tracking platform integrated with other Veeva Systems.
  • Automation of security tools into the Dev Ops process to utilize true Dev Sec Ops.
  • Communicate issues or findings and discoveries prioritize and execute remediation plans.
  • Train other members of the application security engineers, developers or platform engineers of the automation efforts.
  • Assist in Security Incident Response and Cyber Forensics during and post an incident and assist in reverse engineering the attack and designing security controls.
  • Validate exploits findings from third party penetration testers.
  • Review and validate findings from Veeva’s bug bounty program.
  • Maintain automation of securities AWS VPC and related testing systems for our third-party testers and bug bounty programs.
  • Backup the Security Architect working with the Veeva platform teams on secure code practices, vulnerability reviews of third-party libraries or other security findings. 

Requirements

  • BS in Computer Science or related field, or equivalent work experience
  • 4+ years as a principal or senior application developer or engineer role
  • Advanced knowledge and understanding in various disciplines such as security engineering, system and network security, authentication and security protocols, cryptography, and application security
  • Experience with interpreted or compiled languages: Python, Ruby, Perl, PHP, C/C++, Java, C#
  • Experience with cloud service providers and their offerings, preferably AWS and its various technologies and APIs
  • Experience with data analytics, indexing, and data algorithms
  • Familiar with Jenkins, Bamboo, CI/CD Pipeline, and other automation tools
  • SDLC, ITIL, Agile development methods, and testing
  • Experience with Big Data technologies such as Elastic, Cloudera, Hadoop, Datadog, and others
  • Experience with Redhat, AWS Linux, AWS Linux 2, Windows Server 2008, 2012, 2016, 2019, etc.

Nice to Have

  • Master of Science in Cyber Security, Information Security, MIS or equivalent
  • Knowledge of the MITRE ATT&CK Framework
  • Industry security certifications such as CISSP, CEH, or others
  • Experience in conducting social engineering-focused assessments
  • Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
  • Experience in Web and Mobile (Android/iOS) based application/service assessment
  • Experience in Wireless and Network assessment in enterprise infrastructure
  • Experience in reverse engineering and associated tooling such as IDA
  • Knowledge of fuzzing, memory corruption, and exploit development
  • Knowledge about hardware hacking
  • Intermediate to advanced communication and presentation skills
  • Experience providing training and mentorship
  • Demonstrable teamwork skills and resourcefulness
  • Ability to make concrete progress in the face of ambiguity and imperfect knowledge
#RemoteUK
Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world.
Veeva is committed to fostering a culture of inclusion and growing a diverse workforce. Diversity makes us stronger. It comes in many forms. Gender, race, ethnicity, religion, politics, sexual orientation, age, disability and life experience shape us all into unique individuals. We value people for the individuals they are and the contributions they can bring to our teams.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Agile Analytics Android APIs Application security Automation AWS Big Data C C++ CEH CI/CD CISSP Cloud Computer Science Cryptography CTF DevOps Exploit Exploits Forensics Incident response iOS Java Jira Linux MITRE ATT&CK Network security NIST Perl PHP Python Reverse engineering Ruby SANS SDLC Threat intelligence Windows

Region: Europe
Country: United Kingdom
Job stats:  6  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.