Senior Security Engineer Assistant Vice President
Company | State Street |
---|---|
Location | Toronto, ON, Canada |
Salary | $Not Provided – $Not Provided |
Type | Full-Time |
Degrees | Bachelor’s |
Experience Level | Senior, Expert or higher |
Requirements
- B.S. degree (or foreign education equivalent) in Computer Science, Engineering, Mathematics, Physics, or other technical course of study required.
- A minimum of 7+ years of progressively responsible experience as security engineer, among which at least 2+ years of focus on secure SDLC is required.
- Demonstrated knowledge of common vulnerabilities and corresponding remediation approaches.
- Advanced technical knowledge of techniques, standards and state-of-the art capabilities for identity management, authentication, authorization, Single-Sign-On, applied cryptography, and security vulnerability remediation.
- Strong working experience in security code reviews and vulnerability assessment is required.
- Strong written and verbal communication skills.
- Strong analytical and problem-solving skills.
Responsibilities
- Lead and perform security code reviews (automated/manual) and identify implementations that will lead to security vulnerabilities.
- Perform security scans for open-source software, and document findings.
- Conduct manual penetration tests, validate all applicable security controls, and document findings.
- Collaborate with CRD Engineers to develop vulnerability remediation plans and drive implementation.
- Triage and validate vulnerability remediation.
- Identify vulnerabilities in third party libraries using security scan tools.
- Identify security vulnerabilities in the release artifacts and work with engineering and product management to close out open vulnerabilities and approve releases.
- Coach and mentor junior resources on security best practices.
- Identify gaps and optimize existing security processes.
- Champion innovation and lead technical projects.
Preferred Qualifications
- Certifications such as CISSP, CISM, SABSA, TOGAF or similar are a plus.