This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Identity Solutions team is seeking a skilled and experienced Security Engineer. You will play a crucial role to ensure products integrate security requirements during design and throughout the product’s lifecycle. You will work closely with various security teams to provide product engineers with security capabilities and recommendations. You'll mentor and guide technology, product and software development teams, ensuring high-quality outcomes, and play a vital role in shaping our technology and security landscape.
Job Responsibility:
Collaborate with software developers, system engineers, and other stakeholders to integrate security controls into the development lifecycle
Provide input to designs and architectures that include business and regulatory requirements
Provide guidance on best practices for secure designs
Guide developers through proper application development during various design phases
Conduct risk assessments and perform threat modeling to identify potential security vulnerabilities and design weaknesses
Identify security controls that will address security gaps
Evaluate and recommend security technologies, tools, and services
Perform security reviews and audits of system designs and implementations
Stay updated on industry trends, emerging threats, and best practices in security designs
Requirements:
Strong communication skills with the ability to collaborate with technical and non-technical stakeholders
Experience as a Security Design Engineer or in a similar role
Experience with secure software development methodologies (e.g. OWASP Top 10, CWE/SANS Tops 25, etc.)
Knowledge of encryption algorithms, authentication protocols, and secure communication protocols
Strong understanding of network security best practices, security principles and standards, and frameworks (e.g., ISO 27001, NIST Cybersecurity Framework, etc.)
Understanding of network protocols, architecture, and topology for cloud and on-premises implementations
Familiarity with cloud security principles and best practices (AWS, GCP, Azure)
Ability to perform risk assessments and threat modeling to identify security risks and mitigations
Effective communication and interpersonal skills, with the ability to work collaboratively in a team environment
Nice to have:
Technical experience with scripting/programming languages
CISSP, CCSP or industry-recognized / vendor-specific security certification(s)
Previous experience in an audited environment complying with common regulation standards