Jobs

    Product Security Engineer - California, United States - Early Warning®

    Early Warning®
    Early Warning® California, United States

    3 weeks ago

    Default job background
    Banking / Loans
    Description

    At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, PazeSM, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

    Overall Purpose

    This position consults with Project Management, Product Management, Product Development and Engineering teams to enable them to build and enhance security in EWS products and Services in line with EWS and industry standards. This position is highly technical and will lead Product Security efforts in maturing our product security program, mentor others and be a hands-on partner to our product teams to deliver innovative and secure products to our customers.

    Essential Functions

    • Completes the Identification, measurement, control and minimization of security risks to information systems across a broad range of disciplines including application and host security
    • Develops and implements repeatable application security architecture patterns working with internal and external partners to ensure that systems are placed within the relevant security zones based on the data they house and their purpose.
    • Contributes to the development of Early Warning security policy and procedures.
    • Develop Threat Models, design and develop Security architectures and publish reference architecture/patterns implementations for Products and drive companywide adoptions
    • Supports Product and Stakeholder teams efforts in building Cloud Native applications by implementing and engineering Cloud Security and Microservices Security best practices and industry standards
    • Document and present risks and security issues that could impact the confidentiality, integrity and/or availability of the business (both internally and externally) by assisting in documentation, tracking and creating solutions for mitigation.
    • Develop reference engineering implementations of Security patterns and Security Guardrails into Software frameworks and technology stack.
    • Support and implement Security technology and security control design proof of concepts and implementations.
    • Contribute and further integration of Secure Development lifecycle into product implementation and engineering efforts.
    • Evaluates all product business cases including functional and security specs to ensure security standards are met.
    • Support efforts with Product Development and Engineering teams to perform security analysis on all internally developed products and services.
    • Participates in the development of EWS DevSecOps security strategy and posture by designing, advocating and helping build secure-by-default CI/CD pipelines and processes
    • Identifies opportunities for automation, develop and build integrations for security automated scans and establishes patterns for product and infrastructure automated security
    • Builds and maintains automation in and improvements in the build and deployment pipelines that are part of Continuous Integration (CI) and Continuous Deployment (CD)
    • Provide support and technical guidance and foster a collective understanding of secure development and deployment of products and infrastructure
    • Assists in the implementation of DevSecOps methodologies while addressing requirements and orchestrating security impact.
    • Implements, tests, and supports the development of CI/CD pipelines in Gitlab, Harness and deployment of cloud native configuration management solutions using 3rd party tools
    • Works with architecture teams to ensure that all newly developed and legacy applications and infrastructure implementations are in line with security policy and are compliance to the required frameworks (ISO, PCI, OWASP, NIST 800-53, etc.)
    • Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.

    Minimum Qualifications

    • Education and experience typically obtained through completion of a Bachelor's degree in Computer Science, Engineering, Math or Physical Science
    • A minimum of 4 or more years of related experience
    • Combined 3 years of application security, Security Architecture, Consulting, related IT or Information Security experience.
    • Application development and/or Software Security background.
    • Experience in Threat Modeling and control implementation.
    • Exposure to Agile SDLC process
    • Advanced knowledge of operating system, application, network, and database security architectures
    • Experience in designing security for Cloud hosted products and containerized workloads
    • Knowledge of Security Integration into CI/CD and experience in driving CI/CD adaptation for Security controls
    • Hands-on experience with a diverse range of cloud security technologies and access management, Kubernetes, mitigation, encryption technologies, security information, threat management and infrastructure as code (IaC).
    • Demonstrate advanced understanding in the field of Information Security in terms of both concepts and technology.
    • Able to work with both technical and business stakeholder to design solutions that bring optimal security posture to products and infrastructure.
    • Working knowledge of one or more general purpose programming/script languages including but not limited to Java, C/C++ and Python.

    Preferred Qualifications

    • Hands-on experience with DevSecOps tools like Gitlab, Github, Ansible, Packer and Harness
    • Hands-on experience with DevOps and cybersecurity domains like vulnerability management and system hardening compliance in hybrid cloud and on-prem environment.
    • CEH/CPT, or CISSP or CSSLP Certification and one of GWEB, GCSAC (GIAC Cloud Security and DevSecOps Automation), CKS (Kubernetes Security Specialist), AWS Cloud practitioner, Solutions Architect or Security Specialist or recognized Application Security certification
    • Familiarity and experience with Security tools for SAST, Composition analysis and runtime testing.
    • In depth knowledge with public cloud architecture, such as GCP, AWS and Azure, and virtualization technologies, such as Kubernetes, VMware and OpenStack
    • Experience with defining and implementing security reference architectures and standards
    • In depth knowledge of threat model, network security, cryptography, authentication and authorization
    • Experience with automation tools and methodologies associated with DevOps and CI/CD pipelines
    • Experience with enterprise architecture and partnering cross functionally
    • Ability to establish priorities, work independently and proceed with objectives
    • Experience with implementing common security frameworks and controls in highly automated environments, especially in CI/CD environments

    The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.

    Physical Requirements

    Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.

    Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.

    The Pay Scale For This Position In

    In USD per year is: $135,000 - $150,000, but will vary dependent on geographic location.

    This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

    Additionally, candidates are eligible for a discretionary bonus, and benefits. Be sure to check our Benefits page here for the latest.

    Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

    Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.



  • USA Tech Recruitment California, United States

    Senior Security Engineer · USA Tech Recruitment are working closely with a leading security tech company who are looking for an experienced Senior Security Engineer to join their team. · This role can be based out of either their Bay Area or Boston office in the US or their Munic ...


  • HCLTech California, United States

    Scope this work role will be part of the global security group responsible for developing and implementing security projects to protect our global computing, messaging, and larger M365 environment. The security engineer is part of the security group responsible for developing and ...


  • Databricks California, United States

    While candidates in the listed locations are encouraged for this role, we are open to remote candidates in other locations. · RDQ125R45 · The Detection & Response team's mission is to protect Databricks products, cloud infrastructure, endpoints and employees from security threats ...


  • Russell Tobin California, United States

    Russell Tobin is working with an internationally leading AEC firm to add to their growing team We are looking for an experienced Electronic Security Systems/Information, Communication, and Technology Engineer who can be based out of Los Angeles or San Francisco. This is a permane ...


  • PDSSOFT INC. California, United States

    Palo Alto Firewall and Security Engineer · Location: :Bay Area(Remote) · Duration: 18 Months · Job Description: · We are seeking a highly skilled Palo Alto Firewall and Security Engineer to join our team. The ideal candidate will possess extensive experience in firewall configur ...


  • Glocomms California, United States

    Glocomms is partnered with an industry-leading media platform seeking to bring on a talented and experienced Senior Security Engineer to join its growing Payments technology team. The ideal candidate will have a Bachelor's or Master's degree in Computer Science, Information Secur ...


  • Infojini Inc California, United States

    Job Title: Network Administrator (ITS Administrator, Sr.) · Location: Orange, 92868 California · Duration: Full time · Work Arrangement: Partial Telework-2 days in office (Tues/Thurs) · Description: · Client is seeking a highly motivated and experienced Network Administrator (ITS ...


  • INSPYR Solutions California, United States

    Title: Senior Application Security Engineer · Location: Remote in Southern California · Duration: 8 months+ · Compensation: $96/hr - $103/hr · Work Requirements: US Citizen, GC Holders or Authorized to Work in the U.S. · Job Description: · Our client's team is looking for a Senio ...


  • Glocomms California, United States

    This position requires the ability to obtain and maintain a Secret level United States Security Clearance. As such, candidates must be United States citizens. · Glocomms is partnered with a leading aerospace and motion control systems manufacturer, specializing in cutting-edge te ...


  • PER International California, United States

    COMPANY OVERVIEW · Our Client is one of the world's largest global Fabless Semiconductor Company. They are a leading provider of ICs for a wide range of applications, including mobile devices, home entertainment, and connectivity products. Their chips are used by some of the bigg ...


  • Code Red Partners California, United States

    Code Red is Partnered with one of the most innovative companies in the world. They have raised $100M+ funding and are backed by leading investors like a16z. The CISO is ready to make the first core security team hires, with great impact and scope. We are hiring a first applicatio ...


  • Russell Tobin California, United States

    Russell Tobin is working with an internationally leading AEC firm to add to their growing team We are looking for an experienced Electronic Security Systems/Information, Communication, and Technology Engineer that can be based out of Los Angeles or San Francisco. This is a perman ...


  • PER International California, United States

    OVERVIEW · Our highly regarded client stands as a prominent player among the leading global companies in the Semiconductor industry, securing a spot within the top 5 worldwide. They have earned widespread recognition for their pioneering work in developing state-of-the-art system ...


  • PER International California, United States

    Overview · Our esteemed client is a leading figure in the global Semiconductor industry, ranking among the top 5 companies worldwide. Renowned for their innovative development of state-of-the-art systems-on-chip (SoC), their technology spans a diverse array of applications, inclu ...


  • Titan Industries Golden, United States

    Golden Berlin is growing, and so is the Berlin S-Bahn network. With the construction of a new north-south axis for the S-Bahn, known as S 21, additional capacities are being created and new routes are being made possible in the Berlin S-Bahn network. The main train station will b ...


  • Stealth Startup California, United States

    Title: Sr. Network Engineer. · Location: US Remote (Must be in US Eastern Time Zone) · Looking for a Senior Network Engineer who will be responsible for managing routing, switching, VPN, and firewall infrastructure at our office locations and in the cloud. · Best candidates will ...


  • Energize Group California, United States

    Title: Contract AI/ML Engineer · Duration: Immediate Start, Part-time (20 hours per week) · Description: · We are seeking a skilled Contract AI/ML Engineer to join one of our clients for an immediate project. As an AI/ML Engineer, you will be instrumental in building and deployin ...


  • Branch Metrics California, United States

    At Branch, we're transforming how brands and users interact across digital platforms. Our mobile marketing and deep linking solutions are trusted to deliver seamless experiences that increase ROI, decrease wasted spend, and eliminate siloed attribution. Our Branch team consists o ...

  • Kismet Search

    Head of Engineering

    1 week ago


    Kismet Search California, United States

    Company and Position Overview: · Our client is a well-funded Bay Area Startup, having recently raised $30M+, and is at the forefront of secure data analytics and confidential AI. · We are seeking a strategic Head of Software Engineering to join their team, who has expertise mana ...


  • Cypress HCM California, United States

    We have an exciting opportunity for an Automation Engineer 2 with the top leading multimedia and creative software company in the world. · Responsibilities: · Support triage and incident response with SOAR automation within a SOC setting. · Build automated solutions for manual ...