Senior Product Security Engineer

Atlanta

Applications have closed

OneTrust

Meet the industry-leading trust intelligence platform for managing Privacy and Data Governance, GRC and Security, Ethics and Compliance, and ESG and Sustainability.

View company page

Strength in Trust  

At OneTrust, we exist to unlock every company's potential to thrive by doing what's good for people and planet. Using cutting-edge technology and a real-world approach to privacy, GRC, ethics, and ESG, we’ve created a no-nonsense platform to help supercharge the global push for Trust Intelligence. 

The Challenge   

We are hiring a Senior Product Security Engineer to execute required testing against OneTrust applications in order to detect security flaws that need to be fixed by Product/Dev teams.

Your Mission   

  • Review results of application scanning tools, vulnerability management tools, penetration results.
  • Have conversations and working sessions to fix vulnerabilities in the code, API, mobile applications.
  • Work to roll out new security products and tools in order to product the companies code and products
  • Mentor testers and teach them how to test web-based applications using typical penetration testing tools
  • Review new features and functionality for platform modules
  • Tests modules for flaws in coding or business logic
  • Author reports summarizing findings
  • QA reports written by other team members
  • Peer review results of other team members
  • Coordinate with developers to produce fixes to address flaws found
  • Explain to product managers why vulnerabilities should be prioritized appropriately
  • Re-test remediated items to validate the issues are resolved

You Are    

A self motivated engineer who is able to learn from multiple sources and operate without need for direct guidance. You are able to work independently with high level tasking and able to communicate issues effectively to development teams.

  • Ability to review application security scanning tool results and discuss the results with developers
  • Ability to dive deep into code, API’s, mobile apps, discuss security issues and fixes
  • Ability to execute web application testing with Burp Suite penetration testing tool and other tools
  • Ability to understand and test against OWASP Top 10 Web Application Flaws
  • Ability to review new requirements and module functionality to scope testing appropriately
  • Ability to generate clear reports that outline the flaws detected during application testing

Your Experience Includes   

  • Bachelor's Degree focused on development and/or pen-testing or practical experience (e.g. – military)
  • Experience with application scanning tools SAST, DAST, Open source, vulnerability management
  • Development background. Or extensive experience with some coding languages:  Java, .Net, C#, Python, Perl, PHP, etc. 
  • Able to talk about security vulnerabilities in code, API’s, mobile applications, etc.
  • Ability to role out new security tools and products to protect the company
  • Practical experience as a penetration tester

Extra Awesome

  • Pentest certifications (OSCP, GPEN, GWAPT, GCPN, GXPN)
  • Active security researcher with proven submissions

Benefits

As an employee at OneTrust, you will be a part of the OneTeam. That means equity, bonuses, unlimited PTO, and 100% paid medical benefits (and that’s just the beginning!).  

Our employee rewards philosophy spans mental, physical, and emotional well-being because we want our people to succeed both in and out of the office. Some benefits differ depending on region, but here’s what you can expect from our OneTeam Total Rewards Program: 

  • Competitive Compensation: We offer top pay for top talent with competitive total packages including equity for all, performance bonuses, and retirement savings with match. We’re also committed to fair and equitable pay practices. 
  • Workstyle Flexibility: At home or in the office, we trust you to get the job done. Our people have the option to work in the office, fully remote, or a hybrid based on their role. Go green with commuter program discounts and in-office perks.  
  • Career Development: You’re not just joining any company; you’re joining the company that built the category-defining software platform for trust. You can become an expert and earn industry certifications with training and exams paid for by us and access to our learning & development program and guest speaker series.  
  • Employee Recognition: We celebrate our accomplishments the best way we know how – together. Our people are invited to attend employee appreciation social events (including our awesome annual holiday party), participate in ticket giveaways for local city events based on your home office location, and celebrate one another through our #CheersforPeers channel. 
  • Focus on Wellbeing: Take the vacation or volunteer - we have unlimited PTO globally. You’ll also have access to ClassPass memberships, generous company holidays and your birthday off, paid sick days, Employee Resource Groups (or, as we call them, Employee Trust Groups), and other ways to get connected or support company diversity, equity, and inclusion goals.  
  • Health Benefits: No package is complete without great health benefits. This role may receive company-paid employee healthcare premiums, parental leave, and access to mental health benefits and employee assistance programs. Specific benefits differ by location, so please check with your recruiter to specify what this role will receive. 

Our Commitment to You

When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career.

OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Resources  

Check out the following to learn more about OneTrust and its people: 

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: APIs Application security Burp Suite C DAST GPEN GWAPT GXPN Java Open Source OSCP OWASP Pentesting Perl PHP Privacy Product security Python SAST Vulnerabilities Vulnerability management Web application testing

Perks/benefits: Career development Competitive pay Equity Flex vacation Health care Medical leave Parental leave Salary bonus Startup environment Team events Unlimited paid time off

Regions: Remote/Anywhere North America
Country: United States
Job stats:  12  1  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.