This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Secure Development Lifecycle (SDL) Engineer, you will take an active role in a cross functional team, focused on planning and guiding the implementation of multiple product security assurance initiatives. You will plan and manage the application and compliance tracking of secure development lifecycle activities.
Job Responsibility:
Define, commit, and track secure development lifecycle activities across the entire product development organization
Continually working to improve application security through new and adjusted methodology and tooling
Collaborate with engineers and other project stake holders, serve as an expert in secure design, development, and delivery
Perform technical security assessments including threat modeling, security baseline analysis and final security reviews and recommendations
Develop security satellites as security leaders or SMEs within individual product teams
Coordinate NetApp Technology Groups during the product lifecycle, ensuring security checkpoints are understood and completed
Requirements:
A minimum of 4 years of experience is required. 5 to 7 years of experience is preferred
A Bachelor of Science Degree in Engineering or Computer Science, a master’s degree, or a PhD
or equivalent experience is required
CSSLP is desirable
Strong understanding of static analysis, dynamic analysis, OWASP top 10 and vulnerability scanning
Strong understanding of third-party and open source software integration and usage methodology
Strong understanding of the network stack including ports and protocols
Strong understanding of concepts related to computer architecture, data structures and standard programming practices
Proven experience in leading teams in software security test planning, automation, documentation and process improvement
Hands on experience in DevSecOps or Security Tools Pipelining
Storage background and understanding of network topologies is a plus
Hands on experience in Cloud Security is a plus
Understanding of maturity models such as BSIMM or Open SAMM preferred
Nice to have:
Storage background and understanding of network topologies
Hands on experience in Cloud Security
Understanding of maturity models such as BSIMM or Open SAMM
CSSLP certification
What we offer:
Volunteer time off: 40 hours of paid volunteer time each year
Employee Assistance Program, fitness, and mental health resources