Senior Security Engineer
Warsaw, Poland
Box
Box empowers your teams by making it easy to work with people inside and outside your organization, protect your valuable content, and connect all your apps.- Perform architectural review of product designs to perform a threat analysis, identify security risks, and provide recommendations to make our products secure and resilient
- Incorporate secure code tools, technologies and processes in build pipelines and work with Director of Product Security on establishment of secure development practices
- Deliver Threat Models in collaboration with engineering teams, enumerating potential attack scenarios.
- Review of source code for for secure coding best practices
- Uplift our security champions program within the development organizations
- Ability to automate using python, java or other languages
- Create improvements to uplift vulnerability management program
- Consult with development teams to improve security posture and processes.
- Web / Mobile Application Penetration Testing to identify security vulnerabilities, risks & mitigations
- Develop and implement novel and advanced security analysis techniques
- Working with engineering teams to prioritize security concerns, fix security risks, and provide mitigation recommendation
- Communicate security risks and recommendations effectively with technical and non-technical audiences through verbal and written communications that lead to actionable and measurable improvements
- You will use your technical expertise to advise Product Support & Sales regarding security risks and their mitigations
- You are expected to provide perspective on trends, recommendations, and best practices for customer success
- Degree in Computer Engineering, Computer Science, or a related field
- 6+ Years Experience in the security field with a focus on securing products and applications
- Expertise on OWASP Top 10, Threat Modeling, Securing Microservices, Rest API, OAUTH, SAML, Container Security, Securing SaaS solutions, CI / CD build eco systems
- Familiarity with one or more programming languages, AWS/GCP cloud infrastructure services
- Experience and understanding of Cloud orchestration technologies like Kubernetes, Microservices, Docker
- Performing architecture and design reviews for security posture assessment
- Performing Web Application / Mobile Application penetration testing
- Proven track record of finding zero days/CVEs
- Strong understanding of past, current, and emerging security exploits
- Knowledge of Threat modeling and other risk identification techniques
- Cybersecurity-related certification(s), including CCSP, CISSP, OSCP, OSWE, CEH, GPEN is a plus
- Programming experience in the following but not limited to : C/C++, Java, Python, Go, Rust
- Excellent problem solving skills
- Excellent written and verbal communication skills
Tags: APIs AWS C C++ CCSP CEH CISSP Cloud Computer Science Docker Exploits GCP GPEN Java Kubernetes Microservices OSCP OSWE OWASP Pentesting Privacy Product security Python Rust SaaS SAML Security analysis Vulnerabilities Vulnerability management
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Information Security Analyst jobs
- Open Product Security Engineer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Cybersecurity Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Specialist jobs
- Open Security Specialist jobs
- Open Chief Information Security Officer jobs
- Open Security Researcher jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Cyber Security Specialist jobs
- Open Information System Security Officer (ISSO) jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Windows-related jobs
- Open Application security-related jobs
- Open Network security-related jobs
- Open CISM-related jobs
- Open Pentesting-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open IAM-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Java-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open Malware-related jobs
- Open APIs-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open DevSecOps-related jobs
- Open CI/CD-related jobs