Sr. Product Security Engineer
Warsaw, Poland
Box
Box empowers your teams by making it easy to work with people inside and outside your organization, protect your valuable content, and connect all your apps.- Perform architectural review of product designs to perform a threat analysis, identify security risks, and provide recommendations to make our products secure and resilient
- Incorporate secure code tools, technologies and processes in build pipelines and work with Director of Product Security on establishment of secure development practices
- Deliver Threat Models in collaboration with engineering teams, enumerating potential attack scenarios.
- Review of source code for secure coding best practices
- Uplift our security champions program within the development organizations
- Ability to automate using Python, Java or other languages
- Create improvements to uplift vulnerability management program
- Consult with development teams to improve security posture and processes
- Web / Mobile Application Penetration Testing to identify security vulnerabilities, risks & mitigations
- Develop and implement novel and advanced security analysis techniques
- Working with engineering teams to prioritize security concerns, fix security risks, and provide mitigation recommendations
- Communicate security risks and recommendations effectively with technical and non-technical audiences through verbal and written communications that lead to actionable and measurable improvements
- Use your technical expertise to advise Product Support & Sales regarding security risks and their mitigations
- Provide perspective on trends, recommendations, and best practices for customer success
- Owns or co-owns team level projects; executes with minimal guidance
- Influence across teams with similar function (i.e. identifying and coordinating dependencies)
- Degree in Computer Engineering, Computer Science, or a related field
- 6+ Years Experience in the security field with a focus on securing products and applications
- Expertise on OWASP Top 10, Threat Modeling, Securing Microservices, Rest API, OAUTH, SAML, Container Security, Securing SaaS solutions, CI/CD build eco systems
- Familiarity with one or more programming languages, AWS/GCP cloud infrastructure services
- Experience and understanding of Cloud orchestration technologies like Kubernetes, Microservices, Docker
- Comfortable performing architecture and design reviews for security posture assessment
- You enjoy the challenge of a penetration test
- Proven track record of finding zero days/CVEs
- Strong understanding of past, current, and emerging security exploits
- Knowledge of Threat modeling and other risk identification techniques
- Cybersecurity-related certification(s), including CCSP, CISSP, OSCP, OSWE, CEH, GPEN is a plus
- Programming experience in the following but not limited to : C/C++, Java, Python, Go, Rust
- Excellent problem solving skills
- Excellent written and verbal communication skills
- 10% Coding
- 10% Documentation
- 25% Penetration Testing
- 10% Meetings
- 25% Secure By Design / Threat Modeling
- 20% Project
- Agile management - Scrum
- Issue tracking tool - Jira
- Knowledge repository - GitHub Enterprise, Confluence
- Code reviews - GitHub Enterprise
- Version control system - GIT
Tags: Agile APIs AWS C C++ CCSP CEH CI/CD CISSP Cloud Computer Science Docker Exploits GCP GitHub GPEN Java Jira Kubernetes Microservices OSCP OSWE OWASP Pentesting Privacy Product security Python Rust SaaS SAML Scrum Security analysis Vulnerabilities Vulnerability management
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Senior Cyber Security Engineer jobs
- Open Principal Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Staff Security Engineer jobs
- Open Product Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Senior Information Security Analyst jobs
- Open Cyber Security Specialist jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Chief Information Security Officer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Cybersecurity Specialist jobs
- Open Senior Security Architect jobs
- Open Sr. Security Engineer jobs
- Open IT Security Engineer jobs
- Open CISM-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open ISO 27001-related jobs
- Open Pentesting-related jobs
- Open Application security-related jobs
- Open Agile-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open Malware-related jobs
- Open DevOps-related jobs
- Open Security Clearance-related jobs
- Open IDS-related jobs
- Open EDR-related jobs
- Open Forensics-related jobs
- Open CEH-related jobs
- Open Kubernetes-related jobs