Jobs
>
Scottsdale

    Product Security Engineer - Scottsdale, United States - Early Warning Services, LLC

    Show more Collapse job
    Default job background
    Description
    At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, PazeSM, and so much more.

    As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

    Overall Purpose


    This position consults with Project Management, Product Management, Product Development and Engineering teams to enable them to build and enhance security in EWS products and Services in line with EWS and industry standards.

    This position is highly technical and will lead Product Security efforts in maturing our product security program, mentor others and be a hands-on partner to our product teams to deliver innovative and secure products to our customers.

    Essential Functions

    Completes the Identification, measurement, control and minimization of security risks to information systems across a broad range of disciplines including application and host security

    Develops and implements repeatable application security architecture patterns working with internal and external partners to ensure that systems are placed within the relevant security zones based on the data they house and their purpose.

    Contributes to the development of Early Warning security policy and procedures.
    Develop Threat Models, design and develop Security architectures and publish reference architecture/patterns implementations for Products and drive companywide adoptions
    Supports Product and Stakeholder teams efforts in building Cloud Native applications by implementing and engineering Cloud Security and Microservices Security best practices and industry standards

    Document and present risks and security issues that could impact the confidentiality, integrity and/or availability of the business (both internally and externally) by assisting in documentation, tracking and creating solutions for mitigation.

    Develop reference engineering implementations of Security patterns and Security Guardrails into Software frameworks and technology stack.

    Support and implement Security technology and security control design proof of concepts and implementations.
    Contribute and further integration of Secure Development lifecycle into product implementation and engineering efforts.
    Evaluates all product business cases including functional and security specs to ensure security standards are met.
    Support efforts with Product Development and Engineering teams to perform security analysis on all internally developed products and services.
    Participates in the development of EWS DevSecOps security strategy and posture by designing, advocating and helping build secure-by-default CI/CD pipelines and processes

    Identifies opportunities for automation, develop and build integrations for security automated scans and establishes patterns for product and infrastructure automated security
    Builds and maintains automation in and improvements in the build and deployment pipelines that are part of Continuous Integration (CI) and Continuous Deployment (CD)
    Provide support and technical guidance and foster a collective understanding of secure development and deployment of products and infrastructure
    Assists in the implementation of DevSecOps methodologies while addressing requirements and orchestrating security impact.
    Implements, tests, and supports the development of CI/CD pipelines in Gitlab, Harness and deployment of cloud native configuration management solutions using 3rd party tools

    Works with architecture teams to ensure that all newly developed and legacy applications and infrastructure implementations are in line with security policy and are compliance to the required frameworks (ISO, PCI, OWASP, NIST 800-53, etc.)
    Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.

    Minimum Qualifications

    Education and experience typically obtained through completion of a Bachelor's degree in Computer Science, Engineering, Math or Physical Science

    A minimum of 4 or more years of related experience
    Combined 3 years of application security, Security Architecture, Consulting, related IT or Information Security experience.
    Application development and/or Software Security background.
    Experience in Threat Modeling and control implementation.
    Exposure to Agile SDLC process

    Advanced knowledge of operating system, application, network, and database security architectures
    Experience in designing security for Cloud hosted products and containerized workloads
    Knowledge of Security Integration into CI/CD and experience in driving CI/CD adaptation for Security controls

    Hands-on experience with a diverse range of cloud security technologies and access management, Kubernetes, mitigation, encryption technologies, security information, threat management and infrastructure as code (IaC).

    Demonstrate advanced understanding in the field of Information Security in terms of both concepts and technology.


    Able to work with both technical and business stakeholder to design solutions that bring optimal security posture to products and infrastructure.

    Working knowledge of one or more general purpose programming/script languages including but not limited to Java, C/C++ and Python.

    Preferred Qualifications

    Hands-on experience with DevSecOps tools like Gitlab, Github, Ansible, Packer and Harness

    Hands-on experience with DevOps and cybersecurity domains like vulnerability management and system hardening compliance in hybrid cloud and on-prem environment.

    CEH/CPT, or CISSP or CSSLP Certification and one of GWEB, GCSAC (GIAC Cloud Security and DevSecOps Automation), CKS (Kubernetes Security Specialist), AWS Cloud practitioner, Solutions Architect or Security Specialist or recognized Application Security certification

    Familiarity and experience with Security tools for SAST, Composition analysis and runtime testing.
    In depth knowledge with public cloud architecture, such as GCP, AWS and Azure, and virtualization technologies, such as Kubernetes, VMware and OpenStack
    Experience with defining and implementing security reference architectures and standards
    In depth knowledge of threat model, network security, cryptography, authentication and authorization
    Experience with automation tools and methodologies associated with DevOps and CI/CD pipelines

    Experience with enterprise architecture and partnering cross functionally
    Ability to establish priorities, work independently and proceed with objectives
    Experience with implementing common security frameworks and controls in highly automated environments, especially in CI/CD environments

    The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.

    Physical Requirements

    Working conditions consist of a normal office environment.

    Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours.

    Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.

    Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.

    The pay scale for this position in:

    In USD per year is:
    $135,000 - $150,000, but will vary dependent on geographic location.


    This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer.

    Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers).

    The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

    Additionally, candidates are eligible for a discretionary bonus, and benefits.

    Some of the Ways We Prioritize Your Health and Happiness


    • Healthcare Coverage - Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
    • 401(k) Retirement Plan - Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
    • Paid Time Off - Unlimited Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
    • 12 weeks of Paid Parental Leave
    • Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.


    And SO much more We continue to enhance our program, so be sure to check our Benefits page here for the latest.

    Our team can share more during the interview process


    Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.


    Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws.

    The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.

    #J-18808-Ljbffr

    We have other current jobs related to this field that you can find below

  • Insight Global

    Security Engineer

    3 days ago


    Insight Global Scottsdale, United States

    Job Description · Insight Global is looking for a Security Engineer to join the Info Sec division of a large organization specializing in educational technology. This team is responsible for overseeing a specific line of business that provides credential services to students and ...

  • Cloud Analytics Technologies LLC

    Security Engineer

    1 week ago


    Cloud Analytics Technologies LLC Scottsdale, United States

    Work Authorization: · US Citizen, Green Card, H-1B, GC-EAD, OPT-EAD, L2-EAD, TN Visa · US citizens (USC) and Permanent Residents (GC) are encouraged to apply. We are unable to offer any sort of Visa sponsorship for this position. · Local Candidates Preferred. Non-local candidate ...

  • Vaco

    IT Security Engineer

    2 weeks ago


    Vaco Scottsdale, United States

    Vaco is on the market with a local client to hire two IT Security Engineers. In this role, you will represent security and mitigate risks throughout the company to improve and mature our security posture. You will bring a well-rounded background in IT and a working knowledge of s ...

  • Virtual

    IT Security Engineer

    2 weeks ago


    Virtual Scottsdale, United States

    Vaco is on the market with a local client to hire two IT Security Engineers. In this role, you will represent security and mitigate risks throughout the company to improve and mature our security posture. You will bring a well-rounded background in IT and a working knowledge of s ...

  • Insight Global

    Security Engineer

    2 days ago


    Insight Global Scottsdale, United States

    Job Description · Insight Global is looking for a Security Engineer to join the Info Sec division of a large organization specializing in educational technology. This team is responsible for overseeing a specific line of business that provides credential services to students and ...


  • Contract Professionals, Inc. Scottsdale, United States

    Systems Cybersecurity Engineer · Location: Scottsdale, AZ · Work Arrangement: Fully On-Site · Salary: Pay according to experience · Position Objectives: · As a Cybersecurity/Information Assurance Engineer for Cyber Systems, you will be part of a cross-functional team responsible ...


  • GTN Technical Staffing and Consulting Scottsdale, United States

    IT Security Engineer III · ​​​​ · HIGHLIGHTS · Location: Scottsdale, AZ · Position Type: Direct Hire · Hourly / Salary: Based on experience $130K · Residency Status: US Citizen or Green Card Holder ONLY · Hybrid · Our client is looking for an IT Security Engineer III to join thei ...


  • Staffing Science Scottsdale, United States

    Our client is a mid-sized company in Scottsdale AZ and works hyrbid on site, so must be local and willing to go into an office 3 days per week. · As a Senior IT Security Engineer, you'll play a crucial role in safeguarding our systems and ensuring compliance with industry best pr ...


  • GTN Technical Staffing Scottsdale, United States

    IT Security Engineer III (FOCUS IS AWS CLOUD SECURITY) · ​​​​ · HIGHLIGHTS · Location: Scottsdale, AZ first 30 days onsite for training, hybrid remote/2 days a week onsite after training.) · Position Type: Direct Hire · Hourly / Salary: Based on experience, up to $130K · Residenc ...


  • PayPal Scottsdale, United States

    At PayPal (NASDAQ: PYPL), we believe that every person has the right to participate fully in the global economy. Our mission is to revolutionize commerce globally to make moving money, selling and shopping, personalized and secure. · Job Description Summary: · What you need to ...


  • Axon Scottsdale, United States

    Join Axon and be a Force for Good. · At Axon, we're on a mission to Protect Life. We're explorers, pursuing society's most critical safety and justice issues with our ecosystem of devices and cloud software. Like our products, we work better together. We connect with candor and ...


  • Contract Professionals, Inc Scottsdale, United States

    Systems Cybersecurity Engineer · Location: Scottsdale, AZ · Work Arrangement: Fully On-Site · Salary: Pay according to experience · Interested in this role You can find all the relevant information in the description below. · Position Objectives: · As a Cybersecurity/Inform ...


  • GTN Technical Staffing Scottsdale, United States

    IT Security Engineer III · ???? · HIGHLIGHTS · Location:Scottsdale, AZ · Position Type:Direct Hire · Hourly / Salary:Based on experience - up to $130K · Residency Status:US Citizen or Green Card Holder ONLY · Hybrid · Our client is looking for an IT Security Engineer III ...


  • Staffingscience Scottsdale, United States

    Our client is a mid-sized company in Scottsdale AZ and works hyrbid on site, so must be local and willing to go into an office 3 days per week. · As a Senior IT Security Engineer, you'll play a crucial role in safeguarding our systems and ensuring compliance with industry best pr ...

  • TEKsystems

    Security Engineer

    1 week ago


    TEKsystems Tempe, United States

    Job Description · Job DescriptionJob Title · Cybersecurity engineer · Top Skills' Details · 1. 2+ years experience with SIEM ( deploying, configuration, query languages) · 2. Experience with linux virtual machines and Windows administration · 3. 2+ years experience with Python sc ...


  • GeoLogics Corporation Scottsdale, United States Contract

    GeoLogics is partnering with a leading aerospace and defense company on an exciting career opportunity in Scottsdale, AZWe are looking for a Cybersecurity / Information Assurance Engineerto help develop secure solutions to protect next generation defense systems and warfighters. ...


  • SmartSource Technical Solutions Tempe, United States

    SmartSource is seeking 2 Network Security Engineers (one in Chicago, IL and one in Tempe, AZ) for a 6 month contract to hire opportunity that is 60% on-site, 40% remote. · USC or GC only · Position overview: · We are seeking a talented and experienced Network and Security Engine ...


  • SUNSOFT Scottsdale, United States

    This job was posted by : For more information, please see: · Roles & Responsibilities · The STARS Information Security Engineer Will Support The Planning, Design, Engineering, Upgrading, And Monitoring Of Security Protocols And Systems For The Protection Of The Organization\'s ...


  • Axway Scottsdale, United States

    · Cloud Security Engineer · Job ID · Category · Technical/Engineering · Job Location · US-AZ-Scottsdale · Overview · In 2024, we are pursuing our ambitions to continue to enable organizations' digital transformation. We are looking for our new Senior Cloud Security Engineer to ...


  • GTN Technical Staffing Scottsdale, United States

    IT Security Engineer III · HIGHLIGHTS · Location: · Scottsdale, AZ · Position Type: · Direct Hire · Hourly / Salary: · Based on experience $130K · Residency Status: · US Citizen or Green Card Holder ONLY · Hybrid · Our client is looking for an IT Security Engineer III to join ...