Security Engineer - Product Security Incident Response Team (PSIRT)
India - Bengaluru
Guidewire Software
Elevate your P&C insurance with Guidewire's industry-leading software! Streamline workflows, enhance customer experience, and drive growth. Learn more today!Guidewire PSIRT (Product Security Incident Response Team) is responsible for:
- Guidewire product vulnerability management process for all Guidewire applications.
- Coordination of customer/external product security incidents and reported security issues affecting various Guidewire products and applications.
- Working cross-functionally with all business units, sustaining engineers, product security team members, customer support, legal and external security researchers to ensure timely resolution of security incidents and events.
- Development, maintenance and continuous improvement of the product security incident monitoring, detection and response tools and process, including all required supporting materials.
- Pen testing Guidewire applications to ensure timely discovery of the vulnerabilities.
- Security Review and Code Review of Guidewire applications
We are looking for a new team member who will be responsible to perform following activities (but not limited to):
- Ensure proper execution of PSIRT Process - triage security related issues (external / internal), verify those on different versions, products.
- Perform root cause analysis to ensure validity of reported issues.
- Triage code defect based issues, quantitatively evaluate risk and provide guidance to engineering teams regarding the impact of security issues using industry standard metrics such as CVSS.
- Work closely with project management, product management, engineering and sustaining teams to drive issues to closure.
- Cultivate strong working relationships with external researchers, reporting organizations and customers to ensure effective collaboration. Work with customer facing and internal teams to continually improve processes used to identify and fix product security issues.
- Enhance existing product security incident response program
- Coordinate with internal product development teams in accomplishing regular security reviews and penetration testing assessments.
- Execute the penetration tests internally to identify critical vulnerabilities.
- Perform security-focused code reviews
- Support the preparation of security releases.
- Assist teams in reproducing, triaging, and addressing application security vulnerabilities.
- Validate findings from security scanning tools and ideate data-driven enhancement strategies for dynamic (DAST), static (SAST), open-source application security testing (SCA) and container security scanning including troubleshooting, and continuous process improvement
Requirements:
- Bachelor's/master’s in computer science or equivalent
- Industry related certifications are preferred (E.g. CSSLP, CISSP, GIAC, OSCP, etc.)
- Minimum 3-5 years of relevant Application Security Experience
- At least 2-3 years of experience with Penetration testing
- Solid understanding of OWASP Top 10, common classes of product security vulnerabilities and attack/defense methodologies.
- Strong written and verbal communications skills
- Proven ability to build relationships and influence individuals at all levels, as well as external security researchers, vendors and service providers
- Experience with various application security tools - Static code analysis, dynamic code analysis, vulnerability scanning, pen testing
- AWS/Cloud Experience a strong plus
- Bug bounty program participation a plus
- Knowledge of the security research community is a strong plus
- Scripting skills (i.e. Python/Perl/Ruby, shell scripting) or development experience (Java/C++/Python) is a significant plus!
Guidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently. We combine digital, core, analytics, and AI to deliver our platform as a cloud service. More than 540+ insurers in 40 countries, from new ventures to the largest and most complex in the world, run on Guidewire.
As a partner to our customers, we continually evolve to enable their success. We are proud of our unparalleled implementation track record with 1600+ successful projects, supported by the largest R&D team and partner ecosystem in the industry. Our Marketplace provides hundreds of applications that accelerate integration, localization, and innovation.
For more information, please visit www.guidewire.com and follow us on Twitter: @Guidewire_PandC.
Guidewire Software Inc. provides equal employment opportunities to all applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. All offers are contingent upon passing a criminal history and other background checks where it's applicable to the position.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics Application security AWS C CISSP Cloud Code analysis Computer Science CVSS DAST GIAC Incident response Java Monitoring OSCP OWASP Pentesting Perl Product security PSIRT Python R&D Ruby SAST Scripting Vulnerabilities Vulnerability management
Perks/benefits: Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Principal Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Staff Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Product Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Cyber Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Chief Information Security Officer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Senior Penetration Tester jobs
- Open Cybersecurity Specialist jobs
- Open Security Researcher jobs
- Open Senior Security Architect jobs
- Open IT Security Engineer jobs
- Open Security Operations Analyst jobs
- Open CISM-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open ISO 27001-related jobs
- Open Pentesting-related jobs
- Open Application security-related jobs
- Open Agile-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open Malware-related jobs
- Open DevOps-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open Forensics-related jobs
- Open CEH-related jobs
- Open EDR-related jobs
- Open Kubernetes-related jobs