Website State Street
The Senior Security Engineer is a significant technical contributor to the effort of maintaining and enhancing the software security program at Charles River Development. The security program encompasses vulnerability identification and tracking, assessment and scoring (via CVSS), vulnerability remediation management, software design review, code review and threat modeling.
The role requires comprehensive knowledge of security attack vectors from the operating system through the application layer and persistent layer and related defensive controls for preventing, detecting, and mitigating attacks in both on premise and public cloud scenarios.
The Senior Security Engineer will work with the Principal Security Architect to establish security policies, procedures, and best practices. In addition, this role will work very closely with various teams and stakeholders to execute the security policies, procedures and best practices
- Perform security code reviews and identify implementations that will lead to security vulnerabilities.
- Deliver security awareness training. Provide security training to the development organization on a periodic basis.
- Know the industrial security best practices. Identify key security controls that could apply to secure Charles River products.
- Work with subject matter experts to develop vulnerability remediation action plans and drive implementation.
- Conducting threat modeling exercises for a defined scope.
- Assist in design of security features such as authentication and authorization, data protection.
- Employ common security testing tools to verify common security vulnerabilities and effective fixes.
- Establish or recommend design and implementation patterns for the development team to use.
- Participate in security incident investigations and remediation actions.
- Triage vulnerability findings through industry standard threat scoring practices (CVSS).
- Keep apprised of new offensive threats and the defensive technologies to defeat or mitigate attacks. Monitor the software industry for vulnerabilities that could affect Charles River products.
- Work under minimal supervision to secure SDLC.
- Proven leadership and program management skills
- Proven strong communication, interpersonal, decision-making and negotiation skills
- Proven ability to work effectively with executive management
- Ability to influence and work collaboratively across multiple organizations to reach common goals
- Organized with the ability to multi-task in a fast-paced environment
- Proficient in managing agile projects
Qualification & Experience:
- Strong written and verbal communication skills.
- Knowledge of data modeling and data security is preferred.
- Detailed technical knowledge of techniques, standards and state-of-the art capabilities for authentication and authorization, applied cryptography, security vulnerabilities and remediation.
- CISSP or CEH certifications is preferred
- A minimum of 5+ years of progressively responsible experience as software engineer, with at least 3+ years of focus on secure SDLC is required.
- Demonstrated knowledge of common vulnerabilities and corresponding remediation approaches.
- Strong analytical and problem-solving skills.
- Current knowledge of web related technologies and attack vectors.
Company: State Street
Vacancy Type: Full Time
Job Location: New Bedford, MA, US
Application Deadline: N/A