Great careers start here
📁
Engineering/IT/Security/Software Development
📅
1900007V Requisition #
Position Summary
 

As an integrated member of the development teams, the Security Engineer is responsible for ensuring all product security requirements are defined and addressed throughout the entire product lifecycle.  Areas of specific technical subject matter expertise should encompass one or more of the following disciplines: secure product design, cryptography, vulnerability analysis, physical (electronic) security, defensive coding, side-channel threats, or security certifications.

 

As part of the product security certification efforts, the Security Engineer is required to collaborate with Certification Engineers to ensure timely and cost effective delivery of the certifications.  The Security Engineer may also liaise with evaluation laboratories and 3rd parties in order to provide them with technical information and to assist the Certification Engineer on the justification of technical security positions.

 
Essential/Key Areas of Responsibility
 
  • Collaborate in the creation of product functional specifications and designs for new products to ensure security requirements are addressed and implemented correctly; should be well versed in threat modelling and mitigation strategies;
  • Own, implement, and monitor the secure product development practices and processes for the entire product development lifecycle;
  • Serve as the primary point of contact for the team on security technologies and threat mitigation best practices; examples include practical application of cryptography, key management, trust, authentication, penetration testing, and defensive engineering techniques;
  • Liaise with the Certification Engineers and the product development team to ensure the design and implementation facilitate current and future certification roadmaps;
  • Act as a mentor to the development teams on how to create secure and certifiable designs;
  • Initiate security enhancements on existing products which positively affect the product's marketability;
  • Keep abreast of emerging security technologies as required by the business;



Technical Knowledge/Skills & Experience Required
 
  • 3+ years of direct experience relating to security product development; specific focus on secure software or hardware product developments to include application in the areas of general purpose cryptographic modules, payments processing, user authentication, or trust management;

  • 3+ years of experience applying cryptography in product developments; usage of interfaces such as PKCS #11, MS CAPI/CNG, or KMIP is desirable;

  • Practical experience and understanding of the following languages: C/C++, Java, or Python;

  • Experience with virtualization technologies such as VMWare, Xen, or VirtualBox is desirable;

  • Understanding and experience with commercial product release engineering practices; specifically with Scrum and/or Agile methodologies;

  • Exposure and understanding of product security evaluations, specifically with FIPS-140-2, PCI and/or Common Criteria;

  • Strong communication, presentation, and negotiation skills;

  • Ability to work in a fast paced environment with minimal direct supervisor

     
  • Educational Requirements
  • BSCS, BSCE, BSEE, or equivalent experience required.

 
Professional Attributes
 
  • Proactive - Develops practical solutions, takes ownership, has a ‘can do' rather than ‘won’t do’ approach

  • Technically curious – Regards technology problems as challenges

  • Teamwork - Connected to the business, communicates openly, shares information and knowledge, networks internally and externally, persuades rather than pushes, involves colleagues, respects colleagues

  • Creative – Connects the technical dots with a goal of building customer value

  • Responsive - Always reacts quickly and with a sense of urgency to requests, issues, e-mails or other events in a timely and flexible fashion

#LI-SD

Previous Job Searches

Similar Listings

GB-Cambridge, United Kingdom

📁 Engineering/IT/Security/Software Development

Requisition #: 1900008F

GB-Cambridge, United Kingdom

📁 Engineering/IT/Security/Software Development

Requisition #: 1900007X

GB-Cambridge, United Kingdom

📁 Engineering/IT/Security/Software Development

Requisition #: 1900007U