Product Security Specialist
Geotab
This job is no longer accepting applications
See open jobs at Geotab.See open jobs similar to "Product Security Specialist" Work In Tech.How you’ll make an impact:
- Review existing/new/proposed products with a variety of source code, dynamic and dependency scanners, manual code reviews and security-based architecture reviews as required
- Manually validates scanner findings by tracing source code for a variety of code bases (C#, .net, Java, js/ts/html, swift, kotlin, python, C, firmware) (Not all Required) and provides developer level suggestions for code remediation.
- Explain risk assessments at both the developer (technical) and management (Non technical) levels.
- Write and maintain scripts/code (bash and python) to generate scan input packages, automate security scanner execution and integrate scanners with CI pipelines and Google Cloud storage and reporting mechanisms.
- Update scanning scripts quickly, and refactor as needed.
- Contribute to secure coding standards (involves developing secure coding training for current and future developers).
- Perform technical writing of assessment reports and vulnerability descriptions for product owners and developers.
- Look at the bigger picture and question whether the coverage is sufficient, and if not make recommendations to address coverage gaps.
- Follow through to prevent things falling through the cracks. Prioritizes work that benefits the team. Escalates issues in a timely manner.
- Support Geotab global strategic initiatives.
What you’ll bring to this role:
- 3-5 years of experience with security evaluation/analysis and security code reviews or relevant development experience
- Bachelor’s degree in Computer Science, Information Management, Engineering or a related field
- Security certifications are an asset.
- Experience using source code, dynamic and dependency scanners (e.g. Veracode, Fortify, Sentinel, owasp dependency, NetSparker, Qualys etc.)
- Can evaluate security tools, identify their strengths and weaknesses, and make recommendations about tools, configuration
- Knowledge of programming languages (e.g. C, C#, .NET, Python, Javascript/Typescript); web service technologies (e.g. XML, JSON, SOAP, and REST.); dependency package managers such as npm, nuget, and how they are specified in code.
- Ability to pick up new programming languages quickly.
- Able to dive deeply into convoluted or difficult code to evaluate the validity of potential vulnerabilities.
- Competent with Linux, Windows, GCE, bash, python.
- Ability to work through build issues to create scan packages
- Experience working within a technical or engineering organization/knowledge of the high-technology industry is an asset.
- High accuracy and meticulous attention to detail.
- Able to work well under pressure and respond to fast changing priorities and deadlines.
- Highly organized and able to manage multiple tasks and projects simultaneously.
- Excellent verbal and written communication skills.
- Strong interpersonal relationship building skills.
- Strong analytical skills with the ability to problem-solve to well-judged decisions.
- A strong team-player with the ability to engage with all levels of the organization.
- Technical competence using software programs, including, but not limited to, Google Suite for business (Sheets, Docs, Slides).
This job is no longer accepting applications
See open jobs at Geotab.See open jobs similar to "Product Security Specialist" Work In Tech.