Product and Solution Security Expert (PSSE)
Job Description
You'll make a difference by:
1. Integration with SDLC:
Collaborate with software development teams to integrate security practices throughout the Software Development Life Cycle (SDLC).
Perform security code reviews and analyze vulnerabilities during different SDLC phases.
Ensure security requirements are included in the design, development, testing, and deployment stages of software projects.
2. Security Activities:
Develop and implement security protocols, guidelines, and best practices for software development.
Conduct threat modelling and risk assessments to identify potential security issues early in the development process.
Provide guidance on secure coding practices and remediation of identified vulnerabilities.
3. Stakeholder Interaction:
Work closely with key stakeholders, including product managers, project managers, and business analysts, to support and promote security activities within products.
Communicate security risks, issues, and mitigation strategies effectively to both technical and non-technical stakeholders.
Foster a security-aware culture within the development teams and across the organization.
4. Security Tools and Technologies:
Implement and manage security tools such as static and dynamic analysis tools, intrusion detection systems, and vulnerability scanners.
Stay updated with the latest security tools, trends, and best practices to enhance the organization's security posture.
5. Incident Response:
Assist in the development and implementation of incident response plans and procedures.
Participate in security incident investigations and provide expertise in resolving security breaches.
6. Training and Awareness:
Conduct security training and awareness programs for development teams.
Promote continuous improvement and knowledge sharing related to application security.
You'll win us over by:
1. Technical
Skills:
In-depth knowledge of application security, secure coding practices, and common vulnerabilities (e.g., OWASP Top Ten).
Experience with security tools and technologies such as static analysis tools (SAST), dynamic analysis tools (DAST), and vulnerability scanners.
Proficiency in programming languages such as Java, C#, Python.
Understanding of DevOps practices and integration of security into CI/CD pipelines.
Promote continuous improvement and knowledge sharing related to application security.
2. Soft
Skills:
Strong communication and interpersonal skills.
Ability to explain complex security concepts to non-technical stakeholders.
Strong analytical and problem-solving skills.
Collaborative mindset and ability to work effectively with cross-functional teams.
3. Certification Preferred:
Certified Secure Software Lifecycle Professional (CSSLP).
Experience:
Proven experience working with software development teams and integrating security practices into the SDLC.
Experience interacting with key stakeholders and supporting security activities within software products.