The Director of Engineering Security is responsible for policy, implementation and operation of the secure development lifecycle within a globally distributed engineering function. They will manage a small team responsible for the implementation and operation of security tooling, the delivery of best practice, process monitoring and internal auditing.
About The Role:
The Director of Engineering Security is responsible for policy, implementation and operation of the secure development lifecycle within a globally distributed engineering function. They will manage a small team responsible for the implementation and operation of security tooling, the delivery of best practice, process monitoring and internal auditing.
Key Accountabilities:
Define and own the Secure Development Lifecycle policy and process
Embed a secure by design culture within the organization
Build security communities and a network of security champions
Own and operate the security toolchain within the Engineering group
Establish training programs to ensure engineers are equipped with the necessary and up-to-date security foundations
Work with operations to ensure penetration tests and scans are completed in accordance with established policy. Work with Engineering teams to ensure remediations are processed in accordance with the policy
Work with CISO functions to ensure standard joined-up security incident management handling system is in place
Establish appropriate monitoring of Skyhigh SaaS products
Regular exec-level reporting
Assist the Skyhigh compliance function with the maintenance of SOC, ISO, FedRAMP and other certifications
Undertake threat modelling and prioritize security practices accordingly
About You:
Experience implementing a Secure Development lifecycle with associated toolchain for a SaaS product business
Working knowledge of ISO, SOC and any other regulations desirable
Well versed in security frameworks such as MITRE ATT&CK
Experience working with globally distributed teams in Europe, America and India
Strong influencing skills
Company Benefits and Perks:
We work hard to embrace diversity and inclusion and encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees.