Job Closed

This listing is no longer active.

Veracode logo
Veracode

Security for Cloud-Native Application Development

Senior Security Researcher

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 501-1,000Since 2006H1B SponsorCompany SiteLinkedIn

Location

Massachusetts

Posted

118 days ago

Salary

0

Seniority

Senior

2 yrs expEnglish.NET

Job Description

Senior Security Researcher

Veracode

• Conduct research to identify potential weaknesses and security vulnerabilities in C / C++ and C# / .NET applications as well as others as the need arises. • Describe vulnerabilities and potential exploits, and produce proofs of concept and representative examples to aid engineering teams in building product capabilities • Engage in binary and source static analysis/reverse-engineering of applications • Conduct research to improve automation, accuracy, and efficiency of detection techniques and related systems, using both our own proprietary software as well as open-source tools. • Contribute expertise to Veracode’s customer- and public-facing documentation to ensure information is current, accurate, and actionable • Mentor and provide technical guidance to developers and researchers • Actively participate in the software security community by attending and presenting at industry conferences, conducting and publishing original research, contributing articles to the Veracode blog and/or trade blogs and magazines, etc.

Job Requirements

  • 2+ years of practical reverse-engineering or binary static-analysis experience, including familiarity with Abstract Syntax Trees (AST), reflection, or other code transformation approaches; compilers and associated tooling; and decompilers, disassemblers, and/or debuggers used in binary analysis
  • 1+ years of practical application security experience, such as source code auditing, penetration testing, product assessment, vulnerability research
  • The ability to enter a “breaker” mentality – Veracode is defensively-oriented, but our research requires an offensive mindset, including the ability to assess the attack surface of a piece of software.
  • Prototyping ability – must be comfortable producing “quick and dirty hacks” to demonstrate a concept or solve a one-off problem
  • Strong professional skills:
  • Attention to detail as part of a commitment to quality
  • Analytical and organizational capability for advocating, planning, and executing projects independently
  • Ability to understand technical and security issues from a customer points of view
  • Strong written and verbal communication ability in English, especially technical writing for a developer audience.

Benefits

  • Outstanding Medical, Dental, and Vision Coverage to meet all your healthcare needs.
  • Wellness benefits to help you focus on what’s most important.
  • “Take What You Need” time off policy.
  • Extensive development and training offerings to help you grow your career at Veracode.
  • Generous 401k match to help save for your future.
  • Amazing community of professionals who take pride in what we do every day.

Related Categories

Related Job Pages

More Security Engineer Jobs

Lyra Health logo

VP of Information Security

Lyra Health

Transforming behavioral health through technology with a human touch

Security Engineer118 days ago
OtherRemoteTeam 501-1,000Since 2015H1B Sponsor

• Develop, implement, and maintain a comprehensive, long-term, global information security strategy aligned with business objectives and risk tolerance. • Refine and enforce security policies, standards, and procedures across the organization. • Report on the organization's security posture and risk profile to the executive team and the Board of Directors. • Establish and lead the security operations center (SOC) and incident response teams. • Develop and execute an incident response plan to ensure swift detection, containment, and recovery from security breaches. • Oversee the management of security technologies. • Provide strategic direction for the design and implementation of secure enterprise and cloud infrastructure. • Stay current with emerging cybersecurity threats, technologies, and best practices. • Evaluate and recommend new security technologies and services to enhance the organization's defenses. • Lead the identification, assessment, and mitigation of security risks and vulnerabilities. • Ensure the organization's compliance with relevant industry standards and regulatory frameworks (e.g., GDPR, HIPAA, ISO 27001, SOX). • Manage and assess the security risks associated with third-party vendors and partners. • Continue hardening vendor risk management program to ensure supply chain security. • Mentor, and lead a high-performing information security team. • Continue fostering a culture of cybersecurity awareness across all departments through training and communication programs. • Maintain strong working relationships with cross-functional teams, including DevOps, IT, Legal, Privacy, Engineering, Data and integrate security into business processes.

United States
$251K - $346K / year
ClickHouse logo

Product Security Engineer

ClickHouse

ClickHouse, Inc. is a database management system that allows users to generate analytical reports using real-time SQL queries. The company’s technology works

Security Engineer118 days ago

• Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing • Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL) • Nurture the engineering - security relationship, identify and implement process and technology improvements • Handle information security events and incidents across ClickHouse products and services • Develop processes, tooling and automation to scale security processes and mitigate risks to the business.

Germany
SNHU Careers logo

Online Adjunct Faculty – Cybersecurity

SNHU Careers

At SNHU, we do life-changing work — and not just for our students. Find out how your life can change, too.

Security Engineer118 days ago
OtherRemoteTeam 10,001+Since 1932H1B No Sponsor

• Engage students in an asynchronous and inclusive learning environment by providing guidance and resources in a pre-developed online course. • Prioritize Student Engagement – Work with students by responding within set timeframes and reaching out proactively to students needing additional support. • Recognize student needs holistically and connect them with resources. • Encourage participation, collaboration, and strong faculty-student relationships to enhance learning and build skills. • Share Expertise and Resources – Stay current in your field of expertise, share your experience, and recommend relevant supplementary materials to enhance student understanding of course content. • Find accessible ways to explain complex topics. • Offer Feedback & Assessment – Evaluate student work and provide individualized, constructive feedback within set timeframes to promote growth and mastery of course outcomes. • Facilitate Discussions – Encourage student interaction through active participation in online discussions while fostering an inclusive, engaging, and respectful environment that promotes open dialogue and diverse perspectives.

California
$2.2K - $2.5K
Job Closed
PermitFlow logo

Security Engineer

PermitFlow

Construction permit application and management software. Faster and easier permitting for builders.

Security Engineer118 days ago
OtherRemoteTeam 11-50H1B No Sponsor

• Architect, design, and implement secure, compliant, scalable, and cost-efficient infrastructure solutions to protect a rapidly growing product. • Lead the execution and maintenance of our SOC2 compliance program and other security-related certifications. • Design, implement, and audit Role-Based Access Controls (RBAC), Identity and Access Management (IAM), and secrets management systems. • Design and implement security best practices for backend, frontend services, APIs, and data pipelines. • Own security features end-to-end, from architecture and implementation to testing and production deployment. • Develop and maintain security automation, Infrastructure as Code, and secure CI/CD pipelines. • Implement and manage security monitoring, threat detection, and vulnerability management across our cloud infrastructure. • Establish and enforce security best practices for authentication, authorization, logging, and alerting. • Lead and participate in incident response, troubleshooting complex security issues and driving postmortem learning and improvements. • Collaborate across engineering teams to embed security into the software development lifecycle and balance compliance, velocity, and cost.

United States
$175K - $250K / year
Job Closed