Product Security Resume Samples

4.8 (95 votes) for Product Security Resume Samples

The Guide To Resume Tailoring

Guide the recruiter to the conclusion that you are the best candidate for the product security job. It’s actually very simple. Tailor your resume by picking relevant responsibilities from the examples below and then add your accomplishments. This way, you can position yourself in the best way to get hired.

Craft your perfect resume by picking job responsibilities written by professional recruiters

Pick from the thousands of curated job responsibilities used by the leading companies

Tailor your resume & cover letter with wording that best fits for each job you apply

Resume Builder

Create a Resume in Minutes with Professional Resume Templates

Resume Builder
CHOOSE THE BEST TEMPLATE - Choose from 15 Leading Templates. No need to think about design details.
USE PRE-WRITTEN BULLET POINTS - Select from thousands of pre-written bullet points.
SAVE YOUR DOCUMENTS IN PDF FILES - Instantly download in PDF format or share a custom link.

Resume Builder

Create a Resume in Minutes with Professional Resume Templates

Create a Resume in Minutes
JB
J Beatty
Junius
Beatty
3562 Orie Mount
Dallas
TX
+1 (555) 929 1624
3562 Orie Mount
Dallas
TX
Phone
p +1 (555) 929 1624
Experience Experience
New York, NY
Product Security Architect
New York, NY
Labadie-Thompson
New York, NY
Product Security Architect
  • Leading cross-functional projects and teams in establishing security development lifecycle practices within applications
  • Develop and maintain documentation related to secure software development policies, processes, procedures and reports
  • 7 years of software development with at least 4 years in developing secure systems
  • Assists with the development of secure coding standards
  • Provide product security related coaching/mentoring and security expertise for all software and firmware development teams in HBT
  • Provide thought leadership for, and drive implementation of, a bleeding-edge secure software development lifecyle program
  • Deliver and scale a threat modeling and secure architecture analysis program across a range of software solutions, from shrink-wrapped software, web and mobile applications, and Cloud/Software-as-a-Service (SaaS) plaftforms
Dallas, TX
Senior Product Security Analyst
Dallas, TX
Stoltenberg, Steuber and Koelpin
Dallas, TX
Senior Product Security Analyst
  • Produce clear, concise and unambiguous reports and technical whitepapers, and perform peer reviews and offer constructive criticism of other team member’s outputs
  • Work closely with all product development teams to assist them on improving the maturity of their Secure Software Development Lifecycle
  • Provide feedback to development teams about the security of their applications
  • Assist in tracking the security maturity of all products and solutions pertaining to and in support of Secure Software Development Life Cycles
  • Investigate reported vulnerabilities, provide information about defect types, steps to recreate, exploitation likelihood, impact, risk, etc.
  • Improve security testing methodologies and productivity
  • Actively champion and participate in the perpetual improvement of the organization’s Product Security Assurance Program
present
Philadelphia, PA
Principal Architect, Product Security
Philadelphia, PA
Douglas-Hauck
present
Philadelphia, PA
Principal Architect, Product Security
present
  • Work with big data, metrics and data analytics tools to help manage large volumes of security reporting systems
  • Proficient at software development lifecycle security
  • Contribute to and/or lead various product security architecture efforts to ensure products include security into their design, development and operations
  • Enjoys working in a demanding, and a very dynamic environment
  • Proficient at protocol development
  • Manage third party security technology across multiple platforms and products
  • Mentors team members in relevant security technologies and implementation architecture
Education Education
Bachelor’s Degree in Computer Science
Bachelor’s Degree in Computer Science
Emory University
Bachelor’s Degree in Computer Science
Skills Skills
  • Experience with design & architecture using modern design patterns
  • Experience with cloud security
  • Experience in one or more of the following modern languages/frameworks - HTML5, node.js, PHP, Java, C#..
  • A strong understanding of modern development processes including agile development
  • Solid understanding of application security topics such as authn, authz, encryption, session management, federation
  • Ability to communicate complicated technical issues and risks to engineers, project managers and product managers
  • Extensive experience with application security tools like code scanners, dynamic analysis tools
  • Familiarity with security related certifications such as PCI, ISO27001
  • Strong understanding of public application security projects such as OWASP, BSIMM
  • Expert knowledge of application security attacks
Create a Resume in Minutes

15 Product Security resume templates

1

Product Security Architect Resume Examples & Samples

  • Synthetize customer needs on enterprise security, industry trends, state of the art technology and threats evolution in actionable product definitions. Add significant new features to Intel Security products that could generate differentiators
  • Contribute in the ideation of new Intel Security products
  • Be an active member of security forums
  • Relate technologies and business plans in order to define a technical strategy/architecture for the medium/long term
  • Interact with customers, specifically with those being part of Incident Response Team (CIRT) being able of supporting them in the process of advanced threat detection
  • Proactively analyze data sources to identify indicators of compromise (IoC) for previously reported intrusions
  • Define system & software architectures, integrating both in-house developed components as well as 3rd party vendor solutions. Understand how they meet business and market requirements for the solution
  • Define how Intel SW & HW Platform technologies can be integrated in the solution to drive sustainable competitive differentiation for Intel
  • Coach and evangelize team members in the security domain. Be able to form a productive technical team
  • Act as technical interface, scheduling and attending meetings, explaining the technology in the proposed solutions, articulating design rationale and function strategy as it relates to accomplishing goals
  • Flexibility to embrace change, to manage transition effectively from task to task and to adapt to varying business needs
  • Good influencing skills by earning trust from stakeholders and by being able to obtain agreement from diverse teams
  • LI-LAR-SP1
  • Working experience in developing world-class products. Recognized as an expert in one or more areas of contribution around security, being able to introduce new ideas for impacting the product
  • Experience in content development for an incident response team
  • 3 years of experience in incident response, security engineering, system administration, or network engineering
  • Skilled in SIEM content creation (Boolean logic and RegEx a ), tuning, alert creation, event correlation based on feeds from firewall, Intrusion Detection Systems (IDS), endpoint security, web application logs, proxy logs, NetFlows, etc
  • Knowledge of Intrusion Prevention Systems (IPS) and Intrusion Detection Systems (IDS)
  • Experience with intrusion investigations and network and host based investigation methodologies
  • Knowledge of networking, system administration, architectures and security elements
  • Knowledge of host-based investigations and important artifacts
  • Experience working in a software development environment, preferably with some working experience in Java, Java EE, Spring, Hibernate, Ant, JSP, Tomcat (or similar application servers), MS SQL Server or MySQL
  • Operating Systems: Windows and/or Linux
  • Fluency in written and verbal English communication skills, excellent presentation skills and availability to travel internationally
  • Knowledge of Advanced Persistent Threats actors and their Tactics, Techniques and procedures (TTPs)
  • Experience with full packet capture solutions and the ability to identify Indicators of Compromise from network traffic
  • It is valuable to have some patent approved in the computer security domain
  • Hands on experience performing penetration tests
  • Experience in Agile model and experience in delivering results in small increments is desired
  • It is valuable to have a certification like CISSP, GCIH, SANS, or other industry related certification
2

Global Cyber Security Product Security Response Lead Resume Examples & Samples

  • Respond to product security incidents including internal events and external threats
  • Manage efforts for criticality determination, containment, and mitigation activities
  • Create and maintain incident documentation, and participate in post-mortem incident analysis
  • Apply a well-defined process to identify and reduce the impact of product security incidents
  • Minimum 10 years of experience in information technology with 5 or more years in incident or product security response
  • Ability to work effectively in situations involving uncertainty and adapt to changing priorities
  • Ability to work independently with minimal guidance
  • Strong technical acumen in securing software and hardware
3

Global Cyber Security Product Security Response Engineer Resume Examples & Samples

  • Triage and route valid security vulnerabilities to the appropriate product groups
  • Manage resolution of product security vulnerabilities from initial report to closure while adhering to set SLAs
  • Document cases with analysis and resolution details accurately and thoroughly
  • Work closely with Product Security experts, Technical Support, Legal and Communication teams to deliver security advisories to customers
  • Author high quality security bulletins and advisories
  • Manage technical communication with security researchers and research organizations during lifecycle of vulnerability response
  • First level university degree or equivalent experience required. Advanced university degree preferred
  • Minimum 5 years of related work experience
  • Knowledge of common security vulnerabilities and risk analysis
  • Ability to track and manage numerous parallel activities
  • Ability to work collaboratively and remotely with others across teams and organizations to accomplish goals
  • Knowledge of industry practices for responsible disclosure of security vulnerabilities
4

Manager, Product Security Resume Examples & Samples

  • Lead a Secure Development Lifecycle team, which focuses on key VMware products to ensure that they are developed with security in mind
  • Guide team in the execution of the VMware Secure Development Lifecycle and industry best practices for secure software development
  • Measure and Report the ongoing progress of team
  • Manage individual members of the team to help them develop and achieve their full potential
  • Keenly observe team execution to identify areas of potential process improvements and drive those improvements with existing team or cross-organizational resources
  • Recruit, grow and retain high caliber talent
5

Product Security Architect Resume Examples & Samples

  • Experience with design & architecture using modern design patterns
  • Experience with cloud security
  • Experience in one or more of the following modern languages/frameworks - HTML5, node.js, PHP, Java, C#.
  • A strong understanding of modern development processes including agile development
  • Solid understanding of application security topics such as authn, authz, encryption, session management, federation
  • Ability to communicate complicated technical issues and risks to engineers, project managers and product managers
  • Extensive experience with application security tools like code scanners, dynamic analysis tools
  • Familiarity with security related certifications such as PCI, ISO27001
  • Strong understanding of public application security projects such as OWASP, BSIMM
  • Expert knowledge of application security attacks
6

Principal Architect, Product Security Resume Examples & Samples

  • Contribute to and/or lead various product security architecture efforts to ensure products include security into their design, development and operations
  • Interfaces with many teams across the organization to ensure an efficient and effective security solution meets the business needs
  • Guide threat analysis, technology assurance and technical auditing
  • Develops, documents, and ensures compliance for security best practices including but not limited to the following coding standards, design, platform, cloud and network specific design concerns
  • Creates, tracks and documents security requirements for development projects and enhancements
  • Monitors current and future security trends, technology and information that will positively affect products and services as well as applies and integrates emerging technological trends to new and existing systems architecture
  • Mentors team members in relevant security technologies and implementation architecture
  • Communicates security technology direction
  • Works with stakeholders to define security requirements
  • Support test, troubleshooting and operational issues alignment with security designs and architectures
  • Work with big data, metrics and data analytics tools to help manage large volumes of security reporting systems
  • Architected security for major products and initiatives
  • Proficient at protocol development
  • Proficient at software development lifecycle security
  • Proficient at identity, authentication and authorization systems
  • Proficient at understanding cryptographic trust based systems
  • Cloud security knowledge preferred
  • Coding experience preferred
  • PKI knowledge helpful
  • Excellent written and verbal communication skills, interpersonal and collaborative skills
  • Poise and ability to act calmly and competently in high-pressure, high-stress situations
  • Enjoys working in a demanding, and a very dynamic environment
  • Security expertise in one or more relevant areas
  • High level of personal integrity
  • 11+ years experience in technology based industry
  • 5+ years experience working with software development lifecycles
  • Preferred Certifications:Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Licensed PEN Tester (LPT), Certified Ethical Hacker (CEH), Global Information Assurance Certification (GIAC), Certified Secure Software Lifecycle Professional (CSSLP), Other software development lifecycle certifications
  • Field of Study:Engineering, Computer Scence
7

Product Security Architect Resume Examples & Samples

  • Functioning as main technical point of contact for product teams as it relates to security & privacy
  • Conducting complete lifecycle security architecture and technical assessments
  • Leading cross-functional projects and teams in establishing security development lifecycle practices within applications
  • Responsible for secure design, development and operation of Autodesk's hardware and software products and services
  • Provides consultation in security architecture design/review of projects and other activities involving the use of security technologies related to the web applications, mobile/cloud computing products and services
  • Works with other security architects responsible for technical security risk assessments of new projects, and mitigation of risk associated with existing projects
  • Works with other security architects in product groups to ensure security reaches high quality standards by managing deficiencies or helping guide security requirements/objectives for product features
  • Promotes security research and internal/external influence on software security community
8

Director, Product Security Resume Examples & Samples

  • Passion for product and infrastructure security
  • Minimum of 15 years’ experience with any combinations of the following: standards compliance, penetration testing, automation, threat modeling, secure coding, identity management and authentication, software development, cryptography, system and network security
  • Successful track record of ownership and delivery of product security roadmaps
  • Experience leading compliance initiatives that require detailed control documentation; e.g., FedRAMP, PCI, ISO-27001, NIST 800-53, as well as FERPA, HIPAA and/or COPA
  • Understanding of how to leverage our security investments to bolster our brand
  • Expert knowledge of security testing tools and methodologies
  • Track record of successfully executing security audits, which could include leading product audits, client driven audits, Federal or DoD ATOs and Infrastructure audits
  • Familiarity with risk management frameworks; e.g., SEI OCTAVE and OCTAVE Allegro
  • Proven management experience, with a minimum of 5 years’ leadership experience, including management of direct reports
  • Strong presentation skills with total comfort presenting to an executive audience
  • Comfort redlining contracts and other agreements
  • Knowledge of modern CI/CD DevOps environments, including security automation
  • Expert knowledge of Public Cloud security architecture and best practices
  • Experience with government certification, including taking an organization through ATO; e.g., FedRAMP, FISMA, Agency ATO
  • Programming experience in Java and JavaScript
  • Experience performing security reviews on: RESTful web services, Java web applications, JSON, Server-side JavaScript (e.g. Node.js), jQuery
  • Technical knowledge in web server, application server, operating system and network security
  • Experience with source code reviews and using static analysis tools for critical areas of an application
9

Senior Director, Product Security & Privacy Resume Examples & Samples

  • Degree in Computer Science or technical field
  • At least 5 years hands-on experience as a developer
  • At least 5 years experience in managing / leading / mentoring / coaching teams
  • Experience as a Scrum Master/Product Owner
  • Experience in security tools, metrics, and analytics
  • Advanced degree in Computer Science or technical field
  • 12+ years of overall experience in engineering / software development field
  • Experience in security engineering, system and network security, authentication and security protocols, cryptography, and application security
  • Experience in security management, auditing methodology, technology risk assessments
  • Proficiency in Linux/Windows platforms and good working knowledge of mobile technologies
  • Experience with commercial and/or open source security tools
  • Self-motivated, positive attitude and a team player
10

Executive Director, Product Security Resume Examples & Samples

  • 15+ years experience in leading security initiatives and security technology
  • 5+ years experience in a senior technology leadership role
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security technology concepts to technical and nontechnical audiences, up through and including the Board of Directors
11

Senior Director, Product Security & Privacy Resume Examples & Samples

  • Hands-on experience as a developer
  • Experience with Security and Privacy in Wireless Networks
  • Experience in Forensic Auditing
12

Senior Product Security Architect Resume Examples & Samples

  • 6-8 years’ experience in cybersecurity or software development
  • Technical leadership experience in the software or cybersecurity field
  • Familiarity with both PC/server based software and embedded software in the automation and control systems domain
  • Familiarity with software development lifecycle
  • Familiarity with unmanaged and managed programming languages
  • Knowledge and experience with key management using Trusted Platform Modules and Secure Elements
  • Experience and knowledge of penetration testing methodologies and tools such as OSSTMM and Metasploit
  • Understanding of multiple development processes and practices such as RUP, Agile/SCRUM, etc
  • Research and development experience in cyber security
  • Experience in system penetration testing
13

Senior Director, Product Security Resume Examples & Samples

  • Elevate our product capabilities, development processes, and our profile in the Information Security community, establishing Pegasystems and your reputation as a trusted provider of secure software
  • Through your newly established SDL, you will ensure that Pegasystems builds secure software by focusing on the design and implementation process, eliminating security defects before they can happen
  • Develop a thorough and auditable security testing regime
  • Lead the team that will successfully deliver required security features for our customers’ Pega 7 applications
  • Partner with others in the security space (Pega Cloud security, IT security, and Pega Consulting) to ensure that our security features fit coherently into our overall security strategy for the company and all products
  • Act as an evangelist through speaking engagements and publications to enhance Pegasystems’ excellent reputation
  • Significant knowledge in software security, including
  • Security development lifecycle and practices
  • Threat protection (OWASP TOP 10’s, botnets, malware, etc.)
  • Authentication and authorization technology
  • Browser, email, and mobile OS security
  • Security assurance and compliance certifications
  • Experience driving organizational change
  • Information Security incident management, including internal and external communication, and managed, rapid response
  • Demonstrable success in software product management and/or software engineering management
  • BA/BS Degree in Engineering or Computer Science or equivalent work experience
  • Excellent verbal and written communication skills, including poise in pressure situations
14

Manager, Global Product Security Resume Examples & Samples

  • Proactively identify and deploy intelligence gathering capabilities from the internet, social media, e-commerce, investigative reports, industry trends, and other open-sources. Produce smart, predictive analytics and provide visualization of results
  • Manage cases of product theft, diversion and counterfeiting initiated and escalated through Global Security, utilizing incident management software, and other investigative analysis tools
  • Identify opportunities to support Global Security’s mission, defining the project scope, requirements, and deliverables, developing and/or modifying project plans, ensuring project plans meet functional and technical business objectives
  • Using advanced analytics, conduct continuous analysis of multiple data sources to link seemingly unrelated incidents, identify new activity and evolving trends. Provide ongoing reports, fostering continuous improvement in data collection systems and reports provided
  • Coordinate closely with and evaluate services of outside consultants, information providers and other external investigational resources to support intelligence analysis for internet monitoring and other product security programs
  • Continuously analyze Mylan’s global product portfolio, generating product security risk profiles for efficient resource and countermeasure allocation
  • Facilitate and provide support with regulatory and law enforcement notifications and/or requests, to include updating case files, data analysis and document preparation
  • Ensure evidence is properly inventoried, secured, labeled and preserved
  • Minimum of a Bachelor's degree (or equivalent) and 5 years of global risk and analytical experience with a multi-national pharmaceutical industry corporation and/or entity experience. A Master of Science Degree and ­­8 years of experience is preferred. However, a combination of experience and/or education will be taken into consideration
  • Ability to conduct Internet monitoring of publicly available information and intelligence profiling
  • Must possess excellent communication and interpersonal skills. Maintain frequent contacts with internal personnel and representatives of external organizations at various management levels concerning operations or scheduling of specific phases of projects or contracts. Conduct briefings and participate in technical meetings for internal and external representatives concerning specific operations. Must possess time management skills, organizational skills, writing skills, and computer skills including Microsoft Word, Excel and PowerPoint and Lotus Notes. Functions as an advisor to a unit regarding tasks, projects, and operations. Becomes actively involved in daily operations only when required to meet schedules or to resolve complex problems
  • Able to communicate effectively with law enforcement and regulatory agencies on a global scale. Ability to write comprehensive reports and detailed business correspondence. Ability to work with managers or directors and communicate ambiguous concepts. Ability to present to groups across the organization
  • Ability to add, subtract, multiply and divide in all units of measure, using whole numbers, common fractions and decimals. Ability to compute rate, ratio and percent and to draw and interpret bar graphs
  • Ability to solve problems with a variety of concrete variable through semi-standardized solutions that require some ingenuity and analysis. Ability to draw inferences and follow prescribed and detailed procedures to solve moderately complex problems
  • Typically sitting at a desk or table. Intermittently sitting, standing, walking or stooping. Periodic travel is required
  • Normal office situation
15

Product Security Architect Resume Examples & Samples

  • Provide thought leadership for, and drive implementation of, a bleeding-edge secure software development lifecyle program
  • Partner with product management teams to review product roadmaps and advise on applicable technology and/or data security requirements
  • Engage and provide consistent support to Agile software architecture and engineering teams to identify and groom user stories that incorporate applicable technology and/or data security requirements
  • Deliver and scale a threat modeling and secure architecture analysis program across a range of software solutions, from shrink-wrapped software, web and mobile applications, and Cloud/Software-as-a-Service (SaaS) plaftforms
  • Develop enterprise-wide secure software development and application security requirements and standards aligned to business and product strategy
  • Serve as a security subject matter expert and main point of technical contact for product and software engineering teams
  • Develop and maintain documentation related to secure software development policies, processes, procedures and reports
  • Performs research into threats or risks and drives innovation in software security
  • Bachelor’s Degree in Computer Science or Engineering, or equivalent experience with software development and information security technologies
  • The ideal candidate has at least 8-10+ years of combined, hands-on experience in product management, software development and information security engineering
  • Active Certified Secure Software Lifecycle Professional (CSSLP), Certified Information Systems Security Professional (CISSP), or equivalent industry certifications
  • Demonstrated ability to perform software architecture security analysis, secure code reviews, web application penetration testing, or application reverse engineering
  • Strong understanding of bleeding edge software development methodologies, especially Agile and DevOps in cloud computing-based environments
  • Experienced with multiple compiled and interpreted software and web programming, such as Java, ASP.net, C#, Ruby, Groovy, Javascript or Node.js
  • Current or previous expertise with static and dynamic application security, penetration testing and vulnerability assessment tools, such as IBM AppScan, HP Fortify, Burp Suite, Metasploit, HP Webinspect, Nexpose, Nessus and NMAP
  • 2+ years of experience with securing cloud platforms and services
  • Understanding of TCP/IP networking; comfort working with Linux and Microsoft Windows-based operating system platforms and relational database management systems such as Oracle, MS SQL, and MySQL
  • Understanding of cryptographic controls and the application and use of encryption to safeguard network traffic, system and application data
  • Team player; demonstrated ability to develop positive relationships and effectively communicate with product managers and architects, software and systems engineers, quality assurance and operations staff
16

Senior Product Security Eng Resume Examples & Samples

  • Member of the s-Lab application vulnerability testing practice working in collaboration with others on the s-Lab team
  • Executes web application vulnerability scans as requested by EMC quality engineering groups using a combination of tools (e.g. IBM AppScan and Burp)
  • Exercises creative judgment in deciding what combination of WAV tools to use per request
  • Produces test reports and maintains a dashboard of completed scans
  • Engages with developers and quality engineers throughout the company to encourage cross-business collaboration
17

Technical Lead-product Security Resume Examples & Samples

  • Perform secure code reviews and penetration tests across a wide variety of products
  • Build and update threat models and conduct architecture risk analysis activities
  • Interact directly with development teams to help them understand and mitigate security issues
  • Collaborate with the Security Research Lab to create new ways to detect and mitigate issues
  • Create and implement new application security development initiatives
  • Own the Incident Response process and lead Incident Response efforts
  • Establish and track metrics that define and measure security excellence across the business unit
  • Bachelor’s or Master's degree in computer security or related fields with 5+ years of experience
  • Demonstrated expertise in application security topics such as application (web, mobile, and/or embedded) security assessments
  • Strong experience in Penetration Testing and Secure Code Review; Deep knowledge on mitigation techniques for security defects
  • Experience with Threat Modeling and Architecture Risk Analysis
  • Experience with a range of security analysis tools
  • Knowledge of at least one of Java, JavaScript, C/C++ programming languages; proficiency with one or more scripting languages (python, ruby, etc.) is a plus
  • Strong communication skills, both verbal and written; ability to lead and coordinate discussions in a small group as well as present them in an organized fashion to larger groups
  • Good interpersonal skills, with the ability to empathize with and mediate between engineering, customer, and management audiences
  • MSJA
18

Director of Product Security Resume Examples & Samples

  • Work collaboratively to establish strategic plans and objectives
  • Design, develop and implement policies that ensure effective achievement of our security objectives
  • Participate in corporate development of methods, techniques, and evaluation criteria for projects and programs
  • Develop budgets for approval and assure adherence once budget is approved
  • Apply technical, project management, and people management experience to effectively manage your direct team and impact teams globally
  • A minimum of 7 to10 years of experience as a people manager is required
  • Demonstrated ability to manage multiple, critical projects is required
19

Product Security Response Engineer Resume Examples & Samples

  • Ability to consistently assess severity and impact of security issues
  • Strong knowledge of operating system internals
  • Proficiency with debuggers such as lldb and gdb
  • Proficiency in scripting languages like Python and Ruby
  • Ability to work in a fast-paced dynamic environment
  • Lateral thinking is critical for handling incomplete information
  • Strong communication skills, technical writing experience is a plus
20

Senior Product Security Eng Resume Examples & Samples

  • Act as a technical resource for the EMC Security Response Center
  • Perform analysis on the vulnerability reports as submitted by the finder (customers, third party security researchers and research organizations) and work with engineering organizations to verify the existence of the vulnerability
  • Must be able to communicate the nature and severity of the vulnerability and work with the various engineering organizations to determine the impact on VCE product(s)
  • Assist the engineering organizations in interpreting the results of penetration testing and vulnerability scanning tools such as Nessus, Cenzic, Qualys, WebInspect
  • Monitor vulnerability alerts from various resources like Bugtraq, CERT, US-CERT and vendor specific security bulletins on a daily basis and assess relevance of these to VCE products
  • Apply industry standards like Common Vulnerability Scoring System (CVSS) for assessing the severity of security vulnerabilities and Common Vulnerabilities and Exposures (CVE) for responding to publicly known security vulnerabilities
  • Produce technical reports by mapping EMC product vulnerabilities to Common Weakness Enumeration (CWE) and industry resources such as OWASP Top 10, CWE/SANS TOP 25 Most Dangerous Software Errors etc
  • Publish technical root cause analysis on EMC product vulnerabilities and coordinate with internal resources to create a technical position statement on these for EMC engineering organization consumption
  • Broad knowledge of all aspects of information security
  • Ability to work in a high-pressure environment
  • Experience Required: 2-3 Years
21

Software Engineer Red Hat Product Security Resume Examples & Samples

  • Understand current and emerging threats in the cloud product space
  • Work with developers to guide new security technologies
  • Communicate flaw information with our software developers, managers, quality engineers, upstream project developers, and peers on vendor security response teams
  • Provide in-depth analysis of security issues
  • Prioritize tasks to ensure that serious vulnerabilities get immediate attention
  • Document vulnerabilities, flaws, mitigation, and their fixes through the entire update release life cycle in the team's knowledge base
  • Ensure proper description of the flaw with as much technical data as possible
  • Ensure proper reference and other data as used by CVE pages
  • Coordinate as needed for embargoed bugs, their patches, and common release dates with upstream and vendors
  • Bachelor's degree in computer science or equivalent, or relevant work experience
  • Proficiency in multiple languages and ability to learn new ones; knowledge of Python, Java, Ruby, Go, or JavaScript
  • Linux operating system knowledge
  • Proficiency in software development processes, with 5+ years of experience in a release engineering, QA, operations, or development environment
  • Windows, Mac OS X, iOS, and Android operating system knowledge is a plus
  • Understanding of security technologies
  • Previous experience in reverse engineering (RE) and security research is a plus
  • Experience and skills with debugging and analysis, using tools like GDB, Valgrind, strace, and other programming level or system-level debuggers
  • Experience using cloud-based technologies is preferred
  • Excellent organizational skills (e.g. GTD)
  • Ability to work in a fast-paced environment with multicultural team dispersed across multiple countries and time zones
  • Experience working in a cross-functional, collaborative environment and an ability to bring groups of people together to collaborate
  • Fluent written and verbal English communication skills
  • Familiarity with open source software is a significant advantage
  • Highly organized and analytical with the ability to quickly learn new technologies in this fast-paced area of Red Hat
22

Sig-product Security Risk Specialist Resume Examples & Samples

  • Assist Philips business units in the development and implementation of product security practices including policies, standards, guidelines, and procedures
  • Verify that security requirements defined in the security plans, policies, and procedures are followed and protection measures are functioning as intended
  • Conduct security reviews to determine compliance
  • Guide the business unit in their management of the resolution of security audit or review findings
  • Provide security risk management and security advice as well as advice on strategic direction relating to product and information security
  • Work with deployment/operations information security officer to proactively and cooperatively communicate and mitigate risks
  • Assist with security incidents and review risk and impact of breaches to protected systems
  • Participate in architecture and design of services providing information and product security advice
  • Review proposed services, engineering changes, and feature requests for security implications and needed security controls
  • ~10 years of security experience including responsibility for the security of a software application and IT infrastructure including both defining product roadmap and operational experience
  • Product/Information security experience in all phases of service development and deployment including architecture, design, development, testing, release, and operational maintenance
  • Incident management, including analysis and response
  • Experience architecting security solutions
  • Experience with software development especially skills in programming languages and frameworks such as Java, spring, SOAP & REST API in a Linux/Tomcat environment
  • Experience with SQL database encryption and Key management system
  • Global working experience in enterprise application development & Cloud Computing
  • Technical leadership experience in the Software Security field
  • Experience and knowledge of penetration testing methodologies and tools
  • Conducting information security analyses, audits, and reviews
  • Experience in the healthcare sector and HIPAA
  • Experience leading change management systems
  • Experience with NIST 800-53
  • Ideal candidate would have worked on the software development initially and then graduated in to either -S/W architecting/security assessments ensuring security in the product design
23

Smart Energy Product Security Leader Resume Examples & Samples

  • Govern and enforce the effective implementation of product security practices in NPI (New Product Introduction) projects
  • Review and approve mandatory product security activities for the Smart Energy Product Approval Committee (PAC)
  • Participate in HBT Software Security Group providing input on cyber policies, risk management, processes, technology development and strategy
  • Provide training, coaching, and expert consultation in secure development practices to the business and development teams
  • Enable SBU leadership team to understand security risk, participate in technology and resource needs planning
  • Ensure adoption of Product Security initiatives and ACS standard components across the Smart Energy product lines
  • Act as the focal point for Smart Energy critical customer cybersecurity issues (PSIRT), product security compliance, and external security certifications
  • Be the Smart Energy liaison to the US Department of Homeland Security, and other government agencies as appropriate, for Smart Energy product cyber security issues
  • Interface with Legal and Marketing Communications group to manage communications of security vulnerabilities in Smart Energy products
  • Review and approve security notifications to inform customers of urgent security issues which may impact their Honeywell products
  • Coordinate and track remediation of product security incidents
  • 3+ Familiarity with Cloud-based applications, PC/server based software, mobile applications, and embedded software in the Automation and Control Systems domain
  • 2+ Technical leadership experience in the software security field
  • Master's degree in Computer Science, Electrical Engineering or similar discipline with an emphasis on electronic system security
  • Background in systems engineering
24

HBS Product Security Leader Resume Examples & Samples

  • Provide cyber Security leadership to HBS’s organization and grow the product cyber security knowledge and talent within the business
  • Govern and enforce the effective implementation of product security practices in our products
  • Review and approve mandatory product security activities for the HBS Product Approval Committee (PAC)
  • Institutionalize practices for identifying and quantifying product and portfolio product security risks
  • Participate in Honeywell security community providing input on cyber policies, risk management, processes, technology development and strategy
  • Maintain and report product security metrics of SBU products through their development life cycle for continuous improvement
  • Enable SBU leadership team to understand security risk, participate in technology and resource needs & planning
  • Ensure adoption of Product Security initiatives and HBS standard components across the HBS product lines
  • Act as the focal point for HBS critical customer cybersecurity issues (PSIRT), product security compliance, and external security certifications
  • Be the HBS liaison to the US Department of Homeland Security, and other government agencies as appropriate, for HBS product cyber security issues
  • Monitor external security sources for vulnerabilities which impact SBU products
  • Interface with Legal and Marketing Communications group to manage communications of security vulnerabilities in HBS products
  • 2+ years with incorporating cyber security into software development processes and programs
25

Lead Product Security Analyst Resume Examples & Samples

  • Perform application layer security vulnerability assessments and penetration tests, exercising expertise with SAST and DAST tools and methodologies
  • Investigate reported vulnerabilities, provide information about defect types, document steps to recreate, assess exploitation likelihood, impact, risk, etc
  • Work closely with product development teams to assess and improve the maturity of security vulnerability detection procedures and mitigation
  • Threat and vulnerability management, research, internal dissemination and tracking of risks
  • Train, mentor, and support
  • Author clear, concise and unambiguous reports and technical whitepapers, and perform peer reviews, offering constructive criticism of other team member’s outputs
  • Liaise with customers on security assurance needs and issues
26

Product Security, Senior Manager Resume Examples & Samples

  • Passionately promote integrating security as early as possible into all products, processes and the engineer’s mind
  • Create and execute a strategic plan with a detailed phased roadmap that includes SDLC initiatives, testing, HR and budget planning
  • Deploy a program to ensure the security of all of Splunk’s products extending a BSIMM-like approach
  • Research emerging security threats, vulnerability outbreaks, new test tools, techniques and designs methods
  • Implement architecture, design and threat model reviews and articulate security requirements as part of SDLC to ensure proper signs offs and the business can make smart decisions regarding security risks
  • Evaluate commercial and open source tools. Coordinate 3rd party test vendors
  • Coordinate internal and external bug bounties
27

Product Security Resume Examples & Samples

  • Ensure Tesla's products are implemented to the highest security standards: Model S / Model X / Model 3 / Powerwall / infrastructure
  • Provide security expertise and drive implementations that advance security at Tesla Motors
  • Review, design and build cryptographic solutions (both in products and core corporate projects)
  • Architect and design end to end security solutions for products and corporate CA solutions
  • Build and develop software to interface with HSMs
  • Embedded platforms experience
  • Automotive and Hardware experience
28

Product Security Ethical Hacker Resume Examples & Samples

  • Own the risk ranking of identified threads to prioritize mitigation and remediation activities
  • Provide vulnerability assessment and penetration test reports to key stakeholders
  • Produce reports to demonstrate assessment coverage and remediation effectiveness, and work with the product engineers and software teams to ensure that corrective actions are implemented
  • Master’s degree in computer science or a related discipline
  • Experience in reverse engineering, dissassemblers, debuggers, and exploit development is a plus
29

Associate Director, Regional Product Security Resume Examples & Samples

  • Supply Chain Security which implements regional practices and policies to promote the secure storage, handling, movement and disposition of product and materials throughout the global supply chain; conducts audits and assessments to ensure compliance with Celgene requirements; and, conducts investigations and due diligence assessments related to Supply Chain Security
  • Support Brand Protection investigations and activities to proactively and reactively monitor potential illegal diversion, counterfeits and other brand protection related threats
  • Assist the Anti-Counterfeiting Program which uses strategies, technology, application techniques and monitoring methods to allow authentication of legitimate Celgene product throughout the global supply chain
  • Regional Security oversight for Celgene and third party GxP facilities in the International region
  • This position will report solid line to the Senior Director, Product Security & Integrity and have dotted line responsibility to the Head of Manufacturing – Couvet, Switzerland
  • The successful candidate must excel at working in a collaborative, cross functional, diverse, complex, resource-constrained environment and be able to drive decision-making processes that involve multiple constituencies and constraints
  • Bachelor’s degree in criminal justice/business administration/ supply chain/ legal or a related field
  • Minimum 10 years’ experience in security or law enforcement. Prior experience in criminal justice and/or investigations related to diversion, theft, product tampering, product counterfeiting, fraud, etc. is a plus
  • Supply chain security experience requested preferably in the pharmaceutical industry
  • Superior verbal/written communication abilities
  • Strong commitment to patient safety and compliance requirements
  • Basic understanding of commercial pharmaceutical operations and related supply chains including regulatory requirements (i.e. GxP, Track & Trace, etc.)
  • Superior audit and investigative skills to evaluate supply chain security risks as well as security program compliance
  • Must possess the ability to be a self-starter and work independently with internal and external groups on multiple simultaneous projects
  • Willing to travel 30 – 50% domestically and internationally occasionally on short notice
  • Position is located in Couvet, Switzerland
30

Principal Product Security Architect Resume Examples & Samples

  • Implement the product cybersecurity framework, including governance, definition of controls, standards, and policies (administrative, technical)
  • Define and maintain development and operational processes (compliance, incidents/crisis management, testing), including active participation in the product security incident / rapid response team
  • Define and maintain the threat intelligence program, including maintaining awareness of current vulnerabilities, response mechanisms, mitigation strategies, new technologies, trends, innovations and the changing aviation cybersecurity threatscape
  • Define development and operational strategy in support of regulatory requirements for aviation and data privacy
  • Communicate internally regarding critical cybersecurity incidents impacting the solution or product sub systems, and where appropriate, summarize for external communication as needed
  • Contribute continuous evolution of value-added cybersecurity solutions, roadmaps and supporting skills
  • Represent IFEC cybersecurity, in coordination with Thales internal counterparts in AVS/SIX/TGS GBUs and TUSA, to achieve compliance to group security standards
  • Represent IFEC cybersecurity at industry events and customer meetings
  • Bachelor’s Degree in information technology, computer science, engineering or related discipline
  • Minimum of 7 years of progressive responsibilities in information security, risk management or engineering
  • Demonstrated experience and knowledge in understanding global cybersecurity programs, including technologies, tools, architectures, network and application design, standards, policies, processes and business aspects of risk
  • Presentation and communication experience to management and customers
  • Certified Information Systems Security Professional (CISSP) is required or active pursuit with completion required within 6 months of assuming this position
  • Master’s Degree in information technology, computer science, engineering or related discipline
  • Familiarity with Payment Card Industry (PCI) certification requirements
  • Also considered - Certified Information Security Manager (CISM) or Certified Information Systems Security Officer (ISSO) or related certifications or active pursuit of one or more of these certifications
31

Technical Product Security Ethical Hacker Resume Examples & Samples

  • Conduct security assessments of applications using industry standard tools and techniques in an effort to identify vulnerabilities
  • Analyzing and assisting in the secure design and architecture of software/application solutions
  • Working with software designers, developers, and testers to review, assist and recommend changes and solutions to address the security of Lenovo and third party developed software
  • Producing reports to demonstrate assessment coverage and remediation effectiveness, and working with the Product engineers and software teams to insure corrective actions are implemented
  • Performing application security assessments on thick-client applications, web-based applications, and mobile applications
  • Penetration testing that identifies weaknesses in the transmission of data and supporting infrastructure of applications – servers, databases, networks, wireless, etc
  • Experience performing man-in-the-middle (MitM) based attacks, identifying weak or obsolete methods of encryption, fuzzing testing of protocols, files, drivers (IOCTLs), etc
  • Experience with proxying tools such as: Burp Suite, Fiddler, Mallory, Paros, etc
  • Experience with network assessment tools such as: Nessus, nmap, Retina, cURL, netcat, etc
  • Experience with general/open source tools such as: Kali, Metasploit, sqlmap, Hydra, Wireshark, etc
  • Experience in reverse engineering, disassemblers, debuggers, and developing exploits is a plus
  • The individual must have a very good understanding of vulnerabilities and attack methods and should be able to explain - DLL injection, privilege escalation, XXE, RFI, SQLi, ACL’s and race conditions, session hijacking, broadcast receivers/risks, CSRF, XSS, as well as numerous other attack methods, how to identify them, and what tools are best used for each
  • Bachelors Degree in Computer Science, related area or equivalent related work experience
  • Six years experience in Information Security with experience in secure product and infrastructure design, vulnerability management, penetration testing, security scanning and product security testing
32

Product Security Architect Resume Examples & Samples

  • Interact with internal product design teams to define product security requirements, analyze concept of operations, perform program information analysis, develop system security requirements, create tamper resistant system architectures, analyze cost/schedule/vulnerability tradeoffs, develop top-level system requirements and flow down requirements and implementation concepts to subsystems, manage the design and testing of secured system solutions
  • Provide system engineering trade analysis and serve as a thought leader in this domain, generate and secure IP
  • Drive strategic planning for the product security programs and lead activities in support of long and near term technology development plans. Guide product security implementations during development, integration, test, and fielding of systems and ensure programs are executed to meet or exceed requirements while meeting cost and schedule targets
  • Work closely with cross-functional teams to uncover and address strategic technology development and business development opportunities. Develop and implement strategy to develop new business in the Cyber security area
  • Advises on security best practices, security strategy, security architecture, and security desktop encryption solutions and constantly monitors and protects company systems from ongoing threats
  • Bachelor’s/Master’s degree in Computer Science/Engineering or equivalent experience with security technologies
  • Experience in driving effective implementation & adoption of Security Development Lifecycle (SDL) and software maturity model, especially in embedded systems design
  • Demonstrated knowledge of security best practices, principles, and common security frameworks, such as ISA/IEC62443, NIST, ISO, Common Criteria, etc
  • Strong proficiency in application threat modeling and experience in engineering mitigations
  • Knowledge of automated attack tools and developing mitigation techniques
  • In-depth knowledge of common application & network protocols, cryptographic technologies, common security threats, such as attack techniques, evasive techniques, and preventative & defensive methods
  • Strong understanding of methodologies and tools for threat analysis of complex systems, such as threat modeling and software fuzzing
  • Ability to execute in dynamic and highly technical organizations
  • 10+ years experience working with product development/engineering and product management
  • 5+ years experience in engineering leadership role
  • Experience as a technical lead and architect for embedded system product design
  • Strong embedded system design, development, integration, test experience and strong anti-tampering or hardware reverse engineering, failure analysis experience and experience with cryptographic systems
  • In-depth knowledge of common OS-designs, including Linux, Windows, mobile platforms
  • Strong knowledge of web, security, and network architecture
  • Highly proficient in design and analysis of algorithms and data structures
33

SW Developers Product Security Resume Examples & Samples

  • Bachelor’s degree in Computer Science/Engineering or equivalent experience with security technologies
  • Strong embedded system design, development, integration, test experience
  • In-depth knowledge of common application & network protocols, cryptographic technologies, common security threats, such as attack techniques, evasive techniques, and preventative & defensive methods on common OS-designs, including Linux, Windows IoT, mobile platforms
  • Proficient in application threat modeling and experience in engineering mitigations
  • Knowledge in anti-tampering or hardware reverse engineering, failure analysis experience and experience with cryptographic systems
  • Knowledge in security best practices, principles, and common security frameworks, such as ISA/IEC62443, NIST, ISO, Common Criteria, will be advantageous
  • Experience with automated attack tools and developing mitigation techniques
  • 3-5 years’ experience working with product development/engineering and product management
  • For senior position, experience as a technical lead for embedded system product design is preferred
  • Fresh graduate may also apply for entry position
34

Software Product Security Specialist Resume Examples & Samples

  • You will work with smart and passionate people to deliver results that have a direct impact on the company’s bottom line
  • You will take on important and exciting responsibility from day one, working with key stakeholders across the company
  • You will be challenged to excel and lead alongside the brightest talent in the industry and be rewarded for your achievements
  • Drive consistency and adoption of application security best practices through creation, implementation and execution of policies and procedures
  • Establish best practices for the efficient management and safeguarding of resources and assure internal controls meet company standards
  • Performs risk assessment of products to prioritize products requiring security scrutiny
  • Conducts security architecture reviews on existing products and offer plans for remediation
  • Works with development and testing teams to ensure the use of secure coding practices
  • Performs code review from a security perspective
  • Performs threat modeling activities
  • 3+ years of experience as a product security professional for a software engineering organization and/or ISV
  • Secure software development lifecycle experience and adherence to industry benchmarks (OWASP top 10, SANS top 25, MS SDL, etc.)
  • Detailed technical knowledge oftwo or more of the following security activities: product risk assessment, security architecture reviews, security code reviews, and threat modeling
  • Experience in using application security tools for both static and dynamic scanning; experience with IBM AppScan is a plus
  • Knowledge of web and distributed application architecture, programming languages and technology
  • Knowledge of Security Assurance and Certification benchmarks (ISO 27034, ISA 62443, etc.)
  • High energy, focus on delivering results, and ability to self-manage
  • Continual drive to increase your knowledge and enhance your skills
  • Demonstrated ability to convey complex information in a clear and concise manner
  • Certified Information Security Professional (CISSP), and Certified Information Security Manager (CISM) certifications
  • Proficiency in Enterprise System Security including Authentication, Authorization, Permissions, LDAP, Active Directory, OAuth, SAML 2.0 tokens
  • Experience in implementing dynamic and secure web services; knowledge of WS* Web Services and REST
  • Experience Agile Software Methodology, Scrum, iterative software methodologies
  • AspenTech is an Equal Opportunity Employer
35

Director of Product Security Resume Examples & Samples

  • Defines and directs the activities of product security resources responsible for engaging with EIG’s product delivery partners using a consultative approach
  • Establishes and maintains the security advocates program to enable security self-sufficiency, enable business agility, and improve the overall application security posture of products
  • Creates and deploys an application security training curriculum for the product delivery organization
  • Thinks and acts strategically, stays abreast of trends and advances in security solutions and monitors changes in the operating environment that affect security
  • Provides both internal and external thought leadership using business communications, active collaboration, and leading cross-functional internal/external groups
  • Develops external partnerships with vendors and outside entities as appropriate
  • Takes ownership of key initiatives, coordinating strategies with other members of the security team and business leaders to execute
  • Presents business updates, recommendations, strategic opportunities and assessments to leadership and senior management as needed
  • Develops, maintains, and communicates the product security strategy in partnership with senior product delivery leaders
  • Provides advice and leadership on a broad range of security items and strategies
  • Hires and develops outstanding product security talent
36

Senior Product Security Analyst Resume Examples & Samples

  • Bachelor's Degree in Computer Engineering or in a STEM major (Science, Technology, Engineering, or Math) and/or equivalent experience
  • Proven operational IT experience
  • Proven experience with Network Security Monitoring, SIEM and/or other log aggregation and correlation tools
  • Strong experience with host-centric detection & response skills, as well as process automation
  • Previous hands on experience in the information and cyber security field
  • Demonstration of leadership abilities as well as a strong comprehension of emerging threats
  • Experience in Network Security Monitoring practices, with direct hands-on experience with one or more NSM related technologies: Bro, Snort, Security Onion, Sguil, Snorby, or similar
  • Experience with host based detection and IR technologies such as McAfee EPO, OSSEC, Yara, MIR, CarbonBlack, Tanium, HBgary ActiveDefense or similar
  • Experience with host-centric tools or other forensic software and techniques
  • Demonstrated experience with web technologies a definite plus
  • Experience working with organizations with SaaS business models is a plus
37

Senior Product Security Analyst Resume Examples & Samples

  • Review documents of security requirements, threat modeling, security risks and controls, source code and etc
  • Generate security testing strategy, plan and test cases
  • Design and implement automation security testing framework
  • Interact with engineering team, Security Architect, project manager and other stakeholders for security testing related affairs
  • Improve security testing methodologies and productivity
  • Bachelor's degree in Computer Science, Electrical Engineering or similar discipline with an emphasis on electronic system security or cyber security
  • 3 - 5 years’ experience in cyber or software penetration test
  • Ability to handle penetration test (Manual and Automated), pinpoint security issues and suggest countermeasures
  • Familiarity with one programming language at least
  • Experience with security standards for industrial control systems such as ISA/IEC-62443
  • Knowledge and practice utilizing role-based access control and PKI certificates to authenticate end points, system processes, and users
38

Senior Product Security Architect Resume Examples & Samples

  • 1) Bachelor's degree in Computer Science, Electrical Engineering or similar discipline with an emphasis on electronic system security or cyber security
  • 2) 6-8 years’ experience in cybersecurity or software development
  • 3) Technical leadership experience in the software or cybersecurity field
  • 4) Excellent communications skills
  • 5) Familiarity with both PC/server based software and embedded software in the automation and control systems domain
  • 6) Familiarity with software development lifecycle
  • 7) Familiarity with unmanaged and managed programming languages
  • 8) Fluent spoken English
  • 1) Experience with security standards for industrial control systems such as ISA/IEC-62443
  • 2) Knowledge and experience with key management using Trusted Platform Modules and Secure Elements
  • 3) Knowledge and experience with cryptographic algorithms including DES, RSA, ECC, AES and so on
  • 4) Knowledge and practice utilizing role-based access control and PKI certificates to authenticate end points, system processes, and users
  • 5) Experience and knowledge of penetration testing methodologies and tools such as OSSTMM and Metasploit
  • 6) Up to date knowledge of exploit techniques and hacker methodologies
  • 7) Understanding of multiple development processes and practices such as RUP, Agile/SCRUM, etc
  • 8) Research and development experience in cyber security
  • 9) Experience in system penetration testing
39

Product Security Architect Resume Examples & Samples

  • Masters’s degree
  • 5 to 8 years of software development with at least 4 years in developing secure systems
  • Excellent cyber security capabilities and strong software engineering skills
  • Strong knowledge of secure software development lifecycle and practices such as threat modeling, security reviews, penetration tests, and security incident response
40

Senior Product Security Analyst Shanghai Resume Examples & Samples

  • Perform white box, black box, fuzzing, and penetration test and record security issues in JIRA system
  • Self-drive to follow up with latest security attacks and countermeasures
  • Knowledge of Open Source ethical hacking tools (Kali Linux)
  • Knowledge of OWASP Top 10, SANS Top 25 and associated security controls
  • Intimate knowledge and hands-on experience using various penetration test tools like Nessus, Web Inspect, Nmap, BurpSuite, OWASP ZAP, Metasploit and so on
  • Fluent spoken English
  • Knowledge and experience with cryptographic algorithms including DES, RSA, ECC, AES and so on
  • Up to date knowledge of exploit techniques and hacker methodologies
41

Lead Product Security Architect Resume Examples & Samples

  • Building strong relationships with Autodesk’s technical teams
  • Ensuring that Autodesk’s security strategy is aligned with the objectives of our products
  • Functioning as a technical authority for product teams as it relates to security and privacy
  • Working with cloud and product architects on new projects and mitigation of risks in existing projects
  • Leading cross-functional projects and teams in establishing security development lifecycle (SDL) practices within applications
  • Consulting on security architectures related to desktop applications, web applications, and mobile and cloud computing products and services
  • Working with other security architects to ensure high quality standards for security
  • Helping guide security requirements and objectives for product features
42

Product Security Consultant Resume Examples & Samples

  • Liaise with customers to understand their needs and make appropriate recommendations
  • Conduct site surveys and design security systems based on users' requirements as well as company's quality standard
  • Prepare quotations and present to customers
  • Cold calls to create new customers
  • Secure sales orders and meet the quotas assigned
43

Product Security Architect Resume Examples & Samples

  • Responsible for providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based information
  • Provides consulting services and security support through Product Security Center of Excellence to internal product team
  • Reviews, develops, tests, and implements security plans, products, and control techniques
  • Maintains awareness of security and technology trends and shares that knowledge with others
  • Mentor security champions in relevant development and IT functions
  • Documents security policies and procedures where/when needed
  • Provides implementation support for risk assessment and data security procedures and products
  • Evaluates new and proposed security systems, products, and technologies
  • Reviews circumstances surrounding data security incidents and designs corrective actions
  • BS in Computer Science or equivalent desired
  • Consistent implementation of security solutions at the business unit level
  • 8+ years of IT experience required
  • Experience with at least one Static Application Security Testing (SAST) tool (e.g., CheckMarx, HP Fortify SCA, Coverity, Veracode, FindBugs, other), its use, reports results interpretation, developer community support in remediating verified code-associated security vulnerabilities. Product configuration & tuning experience a plus
  • Experience with the results interpretation of Dynamic Application Security Testing (DAST) reports
  • Familiarity with variety of assessment tools (e.g., BURP, Nessus, Qualys, SQLMap)
  • Professional experience as a software application developer in a leading development language (e.g., Java, .NET, C/C++ etc...), having performed web-based application development
  • Scripting skills (e.g., PERL, Python, shell scripting)
  • At least 5 years' commercial experience within a similar role
  • Results oriented, high energy, self-motivate
44

Product Security Response Engineer Resume Examples & Samples

  • Assess and triage externally reported security issues impacting HP products and applications
  • Provide guidance to product teams on possible mitigations and drive issues to closure
  • Coordinate response on critical issues with key stakeholders and senior management
  • Author and publish security bulletins and advisories in coordination with product teams
  • Develop metrics and dashboards for executive level reporting
  • Research latest security best practices and emerging trends, staying current on new vulnerabilities and threats
  • Knowledge of applicable security standards and leading practices
  • Ability to consistently assess and communicate severity of security issues
  • Excellent interpersonal as well as verbal and written communication skills
  • Prior work experience as an information security practitioner is a plus
45

Senior Software Engineer Product Security Turbotax Resume Examples & Samples

  • Gathering functional requirements, developing technical specifications, and project & test planning
  • Designing/developing web, software, mobile apps, prototypes, or proofs of concepts (POC’s)
  • Act in a technical leadership capacity: Mentoring junior engineers, new team members, and applying technical expertise to challenging programming and design problems
  • Roughly 70-85% hands-on coding
  • Work cross-functionally with various Intuit teams: product management, QA/QE, various product lines, or business units to drive forward results
  • Contribute to the design and architecture of the project
  • Experience with Agile Development, SCRUM, or Extreme Programming methodologies
  • 6+ years experience developing web, software, or mobile applications
  • BS/MS in computer science or equivalent work experience
  • Strong experience with any of the following Object Oriented Languages (OOD)
  • Experience with the entire Software Development Life Cycle (SDLC)
  • 1+ years experience with web services (consuming or creating) with REST or SOAP
  • Solid communication skills: Demonstrated ability to explain complex technical issues to both technical and non-technical audiences
  • Strong understanding of the Software design/architecture process
  • Experience with unit testing & Test Driven Development (TDD)
  • Experience developing, maintaining, and innovating large scale, consumer facing web or mobile applications
  • Experience with social, mobile, cloud/SaaS, big data, or analytics
  • Familiar with the development challenges inherent with highly scalable and available web applications
  • Always Be Learning: Experience with open source technologies (if no practical work experience w/ Big Data, or cutting edge front-end technology—you’re prototyping and/or researching the up and coming technology and solutions
  • Experience with various, modern web frameworks
46

Director, Product Security Resume Examples & Samples

  • Build a team of security solution engineers that tackle improving the full stack implementation of Intuit Products based on findings from Intuit’s Red Team and CyberSOC
  • Work directly with Business Units to build security context for stakeholders that represent distributed security capabilities at Intuit
  • Ensure business unit understanding and compliance with Intuit’s Security Policies and Frameworks
  • Manage use and delivery of security services to business units for a portfolio of applications, services, and systems of a business unit
  • Partner with business leaders in integrating security as a design constraint for Intuit offerings
  • Partner with Intuit DevSecOps and Security Engineering teams to enable built-in security
  • Understand and evangelize the Secure Supply Chain with Shift-Left Security principles
  • Recruit, manage and improve talent, as well as the ability to coach, grow and develop your team
  • Create and provide responsible reporting metrics for reviews with senior management
  • Contribute to the continuous improvement and optimization of processes for existing and new security initiatives
  • Operate as a department point of contact for the assigned business unit
  • Manage multiple product team engagements or service areas and projects simultaneously to ensure on-time response, quality delivery and resolutions
  • 7+ years of technical experience
  • Bachelor's degree in computer science or information systems or equivalent field; Master's degree a plus
  • 2-4 years experience as a technical manager
  • Development, Security and Operations leadership experience desirable
  • Knowledge of AWS, Azure, Google Cloud Platform, a plus
  • Ability to operate in a highly matrixed environment
  • Experience managing teams of solution engineers, security professionals and technical/policy writers
  • Ability to understand and explain security measurements and reported defects
  • Hands-on technical knowledge as well as the ability to manage and lead a highly technical team across multiple disciplines, including web technologies, integrations/middleware/messaging platforms, big data, web service development, and other similar products and technologies
  • Experience in heterogeneous operating environments, including Windows, Linux, and newer technologies
  • Ability to handle multiple deliverables, be timely in responding to issue/incident management
  • Ability to be flexible and adapt in a fast paced and frequently changing environment
  • Ability to communicate technical issues to business leaders as well as to communicate business drivers to security engineers
  • Experience in a global company setting
  • Proven analytical abilities and using data/facts for decision-making
47

Director, Product Security Resume Examples & Samples

  • 8 years minimum of relevant security experience
  • Strong penetration testing skills and knowledge
  • Background in Agile Scrum methodologies
  • Experience in object oriented programming
  • Knowledge in security compliance standards (ISO, NIST, SOX)
48

Director of Product Security Resume Examples & Samples

  • 2 years minimum in a management or supervisory role
  • Bachelor’s degree or equivalent experience preferred
  • In-depth understanding of security architecture
  • Expertise in cloud technologies
  • Python and Ruby knowledge is a plus
49

Product Security Architect Resume Examples & Samples

  • Support NPI project product security process activities including threat modeling, final security reviews, threat vulnerability assessment, etc. for all software and firmware development in ACS
  • Audit key process deliverables related to security for correctness and completeness
  • Provide product security related coaching/mentoring and security expertise for all software and firmware development teams in ACS
  • Ability to travel worldwide 25%
  • 7 years of embedded software development with at least 4 years in developing secure systems
  • Experience in Embedded software design for electronic Smart metering / communications products
  • Experience in on-premise software development
50

Product Security Architect Resume Examples & Samples

  • Provide product security related coaching/mentoring and security expertise for all software and firmware development teams in HBT
  • Lead product security development activities including security requirements, threat modeling, risk analysis, testing and security reviews
  • Provide expertise to the development teams in order to quantify residual product risk and identify appropriate security controls
  • Drive a standardized set of security product requirements and design patterns into product and service offerings
  • Review and approve key process deliverables related to security for correctness and completeness
  • 7 years of software development with at least 4 years in developing secure systems
51

Senior Product Security Architect Resume Examples & Samples

  • Support NPI project product security process activities including threat modeling, final security reviews, threat vulnerability assessment, etc. for all software and firmware development in HBT
  • Drive a standardized set of security product requirements into product and service offerings
  • Bachelor’s degree in computer science or software engineering, electrical engineering or equivalent experience
  • 6 to 8 years of software development with at least 4 years in developing secure systems
52

Senior Product Security Analyst Resume Examples & Samples

  • Perform application layer security vulnerability assessments and penetration tests
  • Investigate reported vulnerabilities, provide information about defect types, steps to recreate, exploitation likelihood, impact, risk, etc
  • Work closely with all product development teams to assist them on improving the maturity of their Secure Software Development Lifecycle
  • Provide feedback to development teams about the security of their applications
  • Work with defect tracking / issue management / source code repository tools and solutions, as required
  • Work with and maintain automated static and dynamic application security testing tools
  • Analyze application security related defects for root causes, and make recommendations for mitigation
  • Participate in threat modeling exercises, paper based security assessments, audits, application security architecture reviews
  • Perform routine (Non-Critical/Widespread) threat and vulnerability management duties, vulnerability research, and internal dissemination and tracking
  • Stay up-to-date with application security related news, trends, tools, and testing techniques
  • Train, mentor and support development and quality assurance teams to help them be successful in their security testing activities
  • Assist in tracking the security maturity of all products and solutions pertaining to and in support of Secure Software Development Life Cycles
  • Produce clear, concise and unambiguous reports and technical whitepapers, and perform peer reviews and offer constructive criticism of other team member’s outputs
  • Setup and manage application security testing environments, and create solutions, (e.g. software, procedures, scripts, methodologies), to help locate security related software defects
  • Actively champion and participate in the perpetual improvement of the organization’s Product Security Assurance Program
  • Participate in long-term projects and initiatives pertaining to application security
  • Some exposure to application security vulnerability assessment and penetration testing tools and methods, (e.g. HP Fortify, IBM Security AppScan, Burp Suite Pro, Acunetix, HP WebInspect, W3AF, BeEF, sqlmap, ZAP, OWASP, SANS, etc.)
  • Some understanding of the security aspects of web-based applications, web services / RESTful APIs, web servers, databases, and hosting environments
  • Some knowledge / experience with Industry standard best practice application security controls, requirements, features, and specifications
  • Fair knowledge / experience with application security issues, weaknesses, vulnerabilities, and threats, risks, and impacts of exploitation
  • Good understanding of common web platforms, technologies, frameworks and languages, (e.g. JavaScript, HTML/HTML5, CSS, AJAX, Java, ASP.Net, PHP, Python; jQuery, Angular, Python, Ruby, Node.js; oScript, etc.)
  • A natural curiosity to learn how things work, and more importantly, how they can be made to work outside of their intended purposes, (i.e. the ethical hacker mentality)
  • Strong analytical, troubleshooting, writing, communication, and consultancy skills
  • Possess a commitment to quality and a thorough approach to work
  • The ability to work in a team and as an individual
  • The ability to manage multiple tasks simultaneously in a very fast paced working environment
  • B.E./B.Tech/Bachelors of Computer Science or similar
  • Hands-on application security penetration testing related certifications, (e.g. GWAPT, OSWE, OSCP, GPEN, CPTE, CEH, GWEB, GCIH, etc.)
  • General information security related certifications, (e.g. CISSP, CISM, GSEC, CCSP, etc.)
  • 1-3+ years of relevant experience
  • Highly developed professional and technical skills are needed to perform this job
  • Previous experience in software application development is also an asset
53

Product Security Leader Resume Examples & Samples

  • Analyze reports from Static and Dynamic Code Analysis tools and use as material for software engineering education
  • Coordinate/participate in and perform design reviews, peer reviews, and code reviews
  • College / University degree in Computer Science, Computer Engineering, Electrical Engineering or related experience
  • Minimum 5 years experience required in any combination of the following - software development, systems design, product development, secure coding practices
  • Excellent communication, listening and problem solving skills including
  • Experience in all aspects of security including direct experience resolving OWASP Top 10 and CWE Top 25 issues
  • Ability to perform research on systems and products and present findings to internal audiences
  • Collaboration skills and a history of working with internal and external partners
  • Possess an understanding of government system and crypto standards
  • Experience with developing security standards
  • Experience with complex authentication and authorization systems
  • Ability to work with people from other countries/cultures
  • Experience analyzing secure design and architecture of IIoT devices, IoT devices, software and cloud services
  • Experience conducting security assessments of IIoT devices, IoT devices, firmware and software
  • Experience in secure development practices in several languages such as C/C++, Java, JavaScript, .NET, PHP, Python, HEX, Embedded C, Embedded Java
54

Global Product Security Architect Leader Resume Examples & Samples

  • Build & grow world class security architecture team
  • Help engineering and Product Management teams identify security requirements
  • Lead and coordinate cross-functional activities for incident response
  • Minimum of 10 years of software development with at least 4 years in developing secure systems
  • 3+ years’ experience leading & recruiting cyber security talent
  • Experience in developing secure requirements and creating threat model
  • Strong knowledge of secure software development life cycle and practices such as threat modeling, security reviews, penetration tests, and security incident response
  • Certifications in security and privacy demonstrating deep practical knowledge such as CSSLP or CISSP
  • Ability to travel worldwide ca. 25%
55

VP, Product Security Resume Examples & Samples

  • Work with business units to identify, capture, escalate, and close security vulnerabilities found in products and platform. Leverage tools to deliver vulnerability information back to the development organization for remediation
  • Actively lead and participate in the implementation of a Product Security Incident Response (PSIRT) function working with the Security Operations team
  • Coordinate/participate and deliver threat modeling for product designs and architectures
  • Drive strategy for centralized inventory management lifecycle for high priority products
  • Work with the sales teams and global account directors develop a knowledge management capability to simplify security requirements across a diverse customer segment
  • Oversee design reviews, peer reviews, and code reviews
  • Able to build and develop a team who are able to partner with business groups to define security requirements products
  • Work closely with customers and regulators to stay current with security requirements for solutions
  • Set goals, work efforts, and evaluate results to ensure that departmental and organizational objectives and operating requirements are met and are in line with the needs and mission of the organization
  • Extensive experience of technology leadership with breadth across information security
  • Be a team player able to work effectively at all levels of an organization with the ability to communicate design rationale and influence others to move toward consensus
  • Experience with developing security standards and educational cross-functional training
  • Knowledge of industry wide information security frameworks including ISO 27001/2, NIST
  • Solid information security commercial experience having worked directly with customers
  • Must have unrestricted authorization to work in the in the United Kingdom or United States
  • Bachelor's degree in Information Technology related area
56

Advisory Senior Consultant Cybersecurity Connected Product Security Resume Examples & Samples

  • Execution and delivery on a broad range of projects including technical security assessments, planning and implementing enterprise security capabilities and processes, and developing Cyber security strategy
  • Demonstrate in-depth technical capabilities and professional knowledge. Demonstrate ability to assimilate to new knowledge. Assist with recruiting, process improvements and research into emerging client-relevant topics
  • Possess good business acumen. Support in new business development activities
  • Remain current on new developments in advisory services capabilities and industry knowledge. Assist in developing our knowledge around industry leading practices, trends and security threats regarding emerging technology platforms
  • Solid understanding of fundamental cyber security concepts, including authentication, authorization, access control, auditing, and cryptography
  • Experience in performing security assessments of IT systems and applications including - threat model development, application security architecture design, blackbox testing and source code review, risk/flaw mitigation strategies
  • Experience as part of a team in performing analysis of IT Security program and related processes/functions – performing current state assessment via interview, determining necessary future state, providing of recommendations to reduce risk and improve effectiveness
  • Understanding of security design patterns relevant across the IT ecosystem (mobile, web, middleware, cloud, database), cyber security solutions engineering, security technology implementation
  • Familiarity with security concerns around emerging technology platforms – mobile device platforms (iOS, Android), cloud services (IaaS, PaaS, SaaS), Big Data, Social media
  • Knowledge of and familiarity with industry laws and regulations mandating cyber security and information risk management requirements (HIPAA, PCI-DSS, Sarbanes-Oxley)
  • Proficiency in Java concepts or other object-oriented languages
  • Must hold or be willing to pursue related professional certifications such as the CISSP, SANS GSEC, CCSKCISM, CRISC, SANS GWAPT, ISSAP, CSSLP, SABSA
57

Application & Product Security Manager Resume Examples & Samples

  • 5 years previous experience in application security required
  • 2 years experience in software development required
  • Secure code review experience with Fortify, Veracode, and Burp preferred
  • Familiarity with Secure SDLC practices required
  • Familiarity with iOS and Android software development preferred
  • Experience with designing secure host, database, and application solutions for multi-tier systems
  • Experience with developing software on and MS .Net platforms
  • Experience with agile system development practices
  • Experience with implementation and administration of security assessment tools
  • High level of personal integrity, with the ability to professionally handle confidential matters, and reflect appropriate level of judgment and maturity
58

Application & Product Security Manager Resume Examples & Samples

  • Help in create, maintain and drive application security technology strategies and roadmaps related to application and platform security, addressing from legacy Data Center network to Cloud network
  • Partner with other security groups to plan and drive the implementation of the technology and their capabilities
  • Set up best practices and provide directions and guidance of how to utilize the technology and its capabilities. Drive the development of application security specifications, standards, and processes to ensure adequate protection of corporate network
  • Work with the architecture groups to design the security solutions for applications or systems, and/or provide expertise and consulting to the project teams on security controls needed
  • Help governing application security standards and architecture directions when supporting business needs and establishing business capabilities
  • Serve as an application security advisor to key technology and business stakeholders, establishing trust relationships through active engagement and collaboration
  • Coordinate with the Training, Education, and Awareness teams to develop and establish developer security training programs
  • Produce metrics reporting the state of the application security program and effectiveness of the application security controls
  • Coordinating with the SoC and Vulnerability Management teams during incident response and detection
  • Hire, retain, and grow a team of application security engineers to support secure product development and the application security program
  • Strong ability to give direction, identify the path, and troubleshoot infrastructure and application problems
  • Self-motivated and passionate about application development and security
  • Be willing to take risks and be able to step up to take initiative
  • Strong interpersonal and relationship building skills
59

Welch Allyn Lead Engineer, Product Security Resume Examples & Samples

  • Develops, and communicates product security technical attributes to product teams
  • Designs and documents the implementation an improvements of information security solutions
  • Drives product verification and acceptance criteria for each release and migration
  • Identifies security tools to build out security program
  • Completes security assessments for customers based on the current architecture
  • Supports customer calls and queries on security
  • Assists with internal security and privacy initiatives
  • Collaborates with a cross functional team to provide responses to security incidents for a broad range of customers
  • Interacts directly with the security community on vulnerabilities & threats
  • Implements continuous monitoring of vulnerabilities on Welch Allyn products
  • Directs penetration testing and other security related testing on products
  • Bachelor’s degree in computer science, or equivalent technical discipline required (or equivalent combination of education and experience)
  • 7 years related experience in IT services for healthcare IT or product related security required
  • Technical expertise in cybersecurity areas such as PKI, encryption standards required
  • Demonstrated ability in C++ or C# programming languages is required
  • Working knowledge of Linux and Windows platforms is preferred
  • Experience in FDA, Medical Device and or other similar environment desired