Staff Application Security Engineer

Logo of Ivanti

Ivanti

πŸ“Remote - United Kingdom

Job highlights

Summary

Join Ivanti, a global leader in IT systems and security management, and become our Staff Application Security Engineer. This key role involves conducting security assessments, threat modeling, code reviews, and penetration tests of Ivanti products and services. The ideal candidate will have extensive experience in web application security, a deep understanding of vulnerabilities and defense techniques, and excellent communication skills. We offer a competitive salary, benefits, flexible hours, and the opportunity to work with a globally recognized leader in IT security. Ivanti is committed to fostering a diverse and inclusive workplace. We are looking for a passionate security professional who wants to make a difference and have fun while doing it.

Requirements

  • 8+ years of experience in web application security roles
  • Deep technical understanding of both common and uncommon security vulnerabilities
  • Passion and self-drive for researching vulnerabilities and latest exploitation techniques
  • Ability to discover and exploit security vulnerabilities as well as to give practical and applicable remediation advice
  • Practical knowledge of applied cryptography and common attacks against modern cryptographic algorithms (encryption at rest, TLS, hashing, etc.)
  • Ability to explain vulnerabilities in a precise, concise and easy to understand manner to stakeholders of varying security and technical backgrounds
  • Ability to work in a self-directed environment that is highly collaborative and cross functional
  • Experience in performing Threat Modeling and providing actionable advice from its results
  • High level of experience in scoring security vulnerability severities through CVSS
  • Good understanding of SSDLC as well as development and integration tools and technologies uses as part of CI/CD pipelines
  • Experience implementing, running and maintaining tools and processes to reliably identify security issues across large code bases (SAST, SCA, DAST, container scanning, penetration tests, etc.)
  • Experience providing secure coding education to developers
  • Experience with at least one programming language (preferrable Python)
  • Ability to performing internal penetration tests as well as coordinating penetration tests executed by third party vendors
  • Ability to triage and reproduce security vulnerabilities from varying internal and external reporting sources
  • Experience in programs such as Responsible Disclosure, Bug Bounty or Vulnerability Disclosure Program

Responsibilities

  • Develop both broad and deep technical understanding of Ivanti products, services and architectures
  • Conduct security assessments such as threat modeling, secure architecture, code reviews and penetration tests on web and mobile applications and services
  • Interpret security vulnerability reports to stakeholders, providing advice on vulnerability prioritization, remediation and mitigation
  • Closely coordinate with all stakeholders to bake in security into all phases of SDLC
  • Create and maintain documentation for security processes
  • Deliver accurate metrics to stakeholders and business leaders in a clear and concise manner
  • Maintain high proficiency in relevant security topics (latest vulnerabilities, TTPs, exploits, etc.)
  • Create and deliver security education across the organization
  • Develop innovative and scalable tools, solutions and processes to enhance product security operations
  • Support accurate security tooling implementation to maximize their effectiveness and interpret their results to relevant stakeholders

Preferred Qualifications

  • Have high experience in web application, database and infrastructure security topics
  • Have high technical knowledge on security vulnerabilities, defense techniques and security best practices
  • Can easily explain complex topics
  • Have excelent verbal and written communication skills
  • Enjoy working cross teams and being a valuable resource to other engineers
  • Have experience in authentication and authorization standards and protocols (SAML, Oauth, LDAP, AD, etc.)
  • Know how to go beyond generic security vulnerability remediation advice
  • Can read and write code with ease
  • Love to learn about latest security topics even in your free time
  • Have good understanding of one or more major cloud providers (Azure, AWS, GCP)
  • Know how to educate others on security topics
  • Have previous experience in securing SaaS applications and cloud environments at scale
  • Understand in depth CI/CD pipelines, containerization (Kubernetes, Docker, etc.) and Microservices
  • Know how to coordinate external vulnerability reporting
  • Have B.S. Computer Science or similar combination of education and experience

Benefits

  • Competitive salary and benefits
  • Flexible hours

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.
Please let Ivanti know you found this job on JobsCollider. Thanks! πŸ™