Posted in

Senior Security Engineer Assistant Vice President

Senior Security Engineer Assistant Vice President

CompanyState Street
LocationToronto, ON, Canada
Salary$Not Provided – $Not Provided
TypeFull-Time
DegreesBachelor’s
Experience LevelSenior, Expert or higher

Requirements

  • B.S. degree (or foreign education equivalent) in Computer Science, Engineering, Mathematics, Physics, or other technical course of study required.
  • A minimum of 7+ years of progressively responsible experience as security engineer, among which at least 2+ years of focus on secure SDLC is required.
  • Demonstrated knowledge of common vulnerabilities and corresponding remediation approaches.
  • Advanced technical knowledge of techniques, standards and state-of-the art capabilities for identity management, authentication, authorization, Single-Sign-On, applied cryptography, and security vulnerability remediation.
  • Strong working experience in security code reviews and vulnerability assessment is required.
  • Strong written and verbal communication skills.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Lead and perform security code reviews (automated/manual) and identify implementations that will lead to security vulnerabilities.
  • Perform security scans for open-source software, and document findings.
  • Conduct manual penetration tests, validate all applicable security controls, and document findings.
  • Collaborate with CRD Engineers to develop vulnerability remediation plans and drive implementation.
  • Triage and validate vulnerability remediation.
  • Identify vulnerabilities in third party libraries using security scan tools.
  • Identify security vulnerabilities in the release artifacts and work with engineering and product management to close out open vulnerabilities and approve releases.
  • Coach and mentor junior resources on security best practices.
  • Identify gaps and optimize existing security processes.
  • Champion innovation and lead technical projects.

Preferred Qualifications

  • Certifications such as CISSP, CISM, SABSA, TOGAF or similar are a plus.