Lead Secure Software Development Lifecycle best practices and standards.
Perform security architecture and design reviews of applications.
Collaborate with empowered teams to ensure secure design, development, implementation, and verification of applications.
Provide remediation guidance and recommendations to developers and administrators.
Participate in and advance threat modelling practices across the division.
Help stakeholders make risk-based decisions.
Train developers and create educational presentations.
Develop tools and automation supporting responsibilities.
What You Bring to The Team :
More than 4+ years of application Security Architecture experience or relevant training and/or experience.
Background experience in software and development.
Proficiency in securing cloud technologies
Proficiency in reading, writing, and auditing code and the ability to learn new languages/technologies.
Experience with OWASP Top10 or SANS Top 25
Experience breaking down complex systems and applications to identify threats.
Excellent ability to communicate, verbally and in writing, complicated technical issues and the risks they pose to developers, network engineers, system administrators, and management.
Strong experience in threat modelling software systems.
Certification in CISSP or CCSP, it s a plus.
Strong problem-solving capabilities using various technologies.
Capability to research a new topic and to learn quickly.
Requires sitting or standing at will while performing work on a computer (or any other physical requirements). The role requires communication with managers, peers, and other colleagues of the company in person, and by utilizing Microsoft Teams chat, calling, and meeting functions.
What would make you stand out:
Knowledge of OAuth 2.0/OpenID Connect.
Knowledge/Experience of containerization solutions, such as Kubernetes, Docker, and Istio.
Knowledge/Experience of web technologies (JavaScript, HTML5, HTTP, REST, etc.).
Good knowledge of some of the following programming platforms/languages: .Net Core. Node.js, C#, Java, JavaScript/TypeScript, C/C++.
Ability to make risk-based, unbiased, judgments that include both technical and business impacts.