Sr. Product Security Engineer
US Remote
Box
Box empowers your teams by making it easy to work with people inside and outside your organization, protect your valuable content, and connect all your apps.- Perform architectural review of product designs to perform a threat analysis, identify security risks, and provide recommendations to make our products secure and resilient
- Deliver Threat Models in collaboration with engineering teams, enumerating potential attack scenarios.
- Review of source code for secure coding best practices
- Incorporate secure code tools, technologies and processes in build pipelines and work with Director of Product Security on establishment of secure development practices
- Ability to automate using Python, Java or other languages
- Web / Mobile Application Penetration Testing
- Working with engineering teams to prioritize security concerns, fix security risks, and provide mitigation recommendations
- Communicate security risks and recommendations effectively with technical and non-technical audiences through verbal and written communications that lead to actionable and measurable improvements
- Provide perspective on trends, recommendations, and best practices for customer success
- Owns or co-owns team level projects; executes with minimal guidance
- Influence across teams with similar function (i.e. identifying and coordinating dependencies)
- Degree in Computer Engineering, Computer Science, or a related field
- 5+ Years Experience in the security field with a focus on securing products and applications
- Expertise on OWASP Top 10, Securing Microservices, Rest API, OAUTH, SAML, Securing SaaS solutions, CI/CD build eco systems
- Familiarity with one or more programming languages, AWS/GCP cloud infrastructure services
- Comfortable performing architecture, design reviews, threat modeling for security posture and risk assessment
- You enjoy the challenge of a penetration test
- Programming experience in the following but not limited to : Javascript, Python, Java, C/C++, Go, Rust
- Excellent problem solving skills
- Excellent written and verbal communication skills
- Cybersecurity-related certification(s), including CCSP, CISSP, OSCP, OSWE, CEH, GPEN is a plus
- Expertise on Container Security
- Experience and understanding of Cloud orchestration technologies like Kubernetes, Microservices, Docker
- Proven track record of finding zero days/CVEs
- Strong understanding of past, current, and emerging security exploits
BENEFITS
Visit this webpage to check out all of our exciting benefits: https://join.collectivehealth.com/box
EQUAL OPPORTUNITY We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. For details on how we protect your information when you apply, please see our Personnel Privacy Notice. #LI-RemoteTags: APIs AWS C C++ CCSP CEH CI/CD CISSP Cloud Computer Science Docker Exploits GCP GPEN Java JavaScript Kubernetes Microservices OSCP OSWE OWASP Pentesting Privacy Product security Python Risk assessment Rust SaaS SAML
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Principal Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Manager Pentest H/F jobs
- Open Cyber Security Specialist jobs
- Open Product Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Chief Information Security Officer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Security Specialist jobs
- Open Senior Information Security Engineer jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open Security Operations Analyst jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open Application security-related jobs
- Open Pentesting-related jobs
- Open Agile-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open SaaS-related jobs
- Open Analytics-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Security assessment-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open DevOps-related jobs
- Open IDS-related jobs
- Open Malware-related jobs
- Open EDR-related jobs
- Open Kubernetes-related jobs
- Open CEH-related jobs
- Open Forensics-related jobs