Job Closed
This listing is no longer active.
Ocrolus is the leading document automation platform in financial services, powering the digital lending ecosystem
Senior Security Engineer, Product Security
Location
India
Posted
46 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Engineer, Product Security
Ocrolus
• Work closely with the CISO to build the product security strategy, roadmap, and metrics to measure and monitor product security posture. • Conduct design and architecture reviews for Ocrolus products and infrastructure. • Perform code reviews and application security assessments, including AI/LLMs. • Engage with the development teams to conduct secure design reviews/threat modeling exercises. • Identify vulnerabilities/threats that could affect Ocrolus products through independent research and work with the developers on workarounds/mitigation plans. • Be the go-to person for developers in solving critical issues relating to secure product development. • Run penetration testing targeting critical data, services, and environments. Report underlying security issues and propose enhanced security protections. • Write and disseminate security guidelines for common security issues, remediation, and security technology baselines. • Collaborate with stakeholders to ensure secure deployment of AI systems by staying updated on AI security best practices and executing adversarial testing strategies. • Guide engineering teams on secure coding and testing principles/practices. • Be a role model for the team and provide a healthy platform for learning and growth. Build relationships with stakeholders throughout the engineering and product organizations. • Spread security culture throughout the organization.
Job Requirements
- A passion for identifying vulnerabilities and remediations.
- Ability to interpret and explain multiple classes of vulnerabilities, such as cross-site scripting, SQL Injection, CSRF, cryptographic-related weakness, and code injection, to various audiences, such as development and management teams.
- Experience in designing and building a wide variety of technical security controls.
- Experience in performing threat modeling, design reviews, code reviews, web application security, and enterprise cloud penetration testing.
- Stellar understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into development processes.
- Ability to automate product security processes and optimize productivity with SAST & DAST tools.
- Good proficiency with a programming language (e.g., Java, Python, Go, Bash).
- Good Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols.
- Experience in cloud security architecture and infrastructure.
- Self-driven with excellent communication and prioritization skills.
- A total of 4+ years of experience in product security (code, web application, API).
Benefits
- Health insurance
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Endpoint Security Engineer
SangomaSangoma Technologies is a trusted world leader in value-based Unified Communications & UCaaS solutions.
Sangoma is seeking a motivated and detail-oriented Endpoint Security Engineer with experience in Incident Response, SOC operations, operating system security, and automation. In this role, you will help strengthen the company’s security posture by designing and implementing new endpoint security solutions and improving existing controls. You will collaborate closely with teams across the technology organization to investigate security events, document lessons learned and drive meaningful improvements. This mid-level position is ideal for someone who can communicate effectively with both technical and non-technical stakeholders and enjoys building and enhancing security capabilities. At this time, we can only consider candidates with permanent, unrestricted U.S. work authorization (U.S. citizens or green card holders). This is a remote position with a preference for candidates located in the Central or Eastern time zones.
Cyber Security Manager - Studios, Film and Television
NBCUniversalHere you can create the extraordinary. Join us.
Title: Cyber Security Manager (Studios, Film and Television) Location: New York United States Full-time Business Segment: Operations & Technology Compensation: USD 120,000 - USD 145,000 - yearly Job Description: Company Description NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our global theme park destinations, consumer products, and experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, NBC Sports, Telemundo, NBC Local Stations, Bravo, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through our powerhouse film and television studios, including Universal Pictures, DreamWorks Animation, and Focus Features, and the four global television studios under the Universal Studio Group banner, and operate industry-leading theme parks and experiences around the world through Universal Destinations & Experiences, including Universal Orlando Resort, home to Universal Epic Universe, and Universal Studios Hollywood. NBCUniversal is a subsidiary of Comcast Corporation. Visit www.nbcuniversal.com for more information. Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world. Job Description The Cyber Security Manager is a critical member of the NBC Universal Cyber Security organization, responsible for executing and contributing to the Cyber Security strategy and overseeing operational engagement with key leaders across Studios, Film, Television (Episodic), Operations & Technology, Media Services, and enterprise-wide business solution teams. NBC Universal takes a threat-centric, intelligence-forward view of Cyber Security, so this position requires a security professional with experience in proactive defense and the technical and business acumen to translate that insight into a tactical roadmap. The Cyber Security Manager will build strong relationships with the Studios, Film and Television (Episodic) organizations, Operations & Technology organization, leadership teams, and supporting teams to assess business practices, identify gaps in security controls and lead development and execution of cyber security strategies. A successful candidate is expected to effectively engage with Cyber Security leadership, business technical teams, internal audit, clients and regulators. This role requires the candidate to communicate the importance of key NBC Universal Cyber Security programs and services to obtain support, trust, and buy-in from business partners. Responsibilities: - Partner with business leadership and service owners on the execution of the Cyber Security strategy; proactively addressing the needs of the business to consistently meet or exceed established levels of security - Communicate and coordinate NBC Universal's Cyber Security strategy, programs and services with a diverse group of business stakeholders - Understand the business workflows and engage with business leadership and teams to identify risks and business-aware mitigation strategies - Provide Cyber Security thought leadership and counsel, with an understanding of business culture, audience and climate - Effectively articulate the threat landscape to business stakeholders and how cyber security's strategy is aligned to defend against these threats - Bridge individual security engineering assessments, compliance status and incident reports to calibrate the priorities. Look beyond the individual results to find overarching messages--both successes and shortcomings--and identify the critical needle moving efforts - Track and coordinate Cyber Security involvement in technical and business driven technology projects - Partner with security incident response team to resolve and close the investigation of incidents with postmortem and remediation plans - Support and develop business-relevant metrics and key performance indicators supporting the measurement of Cyber security program maturity Qualifications Requirements: - Minimum 5 years of work experience in Information Technology, OR 7 years of experience with a Master's level education in a related field - Minimum 3 years of work experience in Cyber Security - Minimum 2 years in customer facing technical engagement roles, including service and solution delivery. - Minimum 2 years managing, coordinating, tracking projects using various PM tools - Ability to travel up to 10% of time - Must be located within a commutable distance to New York City, NY. Desired Characteristics: - News or Media and Entertainment industry experience. - Preferred knowledge of Production, VFX, Post Production, and Content Creation (Creative) workflows. - Experience with security of enterprise products (i.e., Microsoft suite, Collaboration tools, development tools) - Ability to communicate effectively to business and technical teams - Degree in Computer Science or equivalent field of study - Training or Certifications in Cyber Security specific disciplines - Experience in supporting or leading Information Security or Technology teams and concurrent projects - Demonstrated work history delivering security solutions in a global enterprise environment - Demonstrated ability to communicate to all levels of an organization and build consensus - Demonstrated ability to oversee technical efforts while maintaining strategic alignment with key goals and objectives - Demonstrated negotiation and problem resolution skills - Demonstrated interpersonal, analytical, organizational, written and verbal communication skills - Demonstrated knowledge of recognized Information Security related standards, Media and Entertainment Security Standards and technologies - Demonstrated knowledge of International Information Security and Privacy regulations, laws, and policies Additional Requirements: - Commutable Remote: This position requires working a minimum of three days per week from our New York City offices, with the ability to work remotely the other days. This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $120,000 - $145,000 (bonus eligible) Additional Information As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law. For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
Cyber Security Specialist
Apex SystemsApex Systems, an IT staffing and workforce solutions firm, provides recruiting and staffing services to large and small companies alike. Founded in 1995 by thre
Title: Cyber Security Specialist Job Description: Job#: 3024458 Job Description: Cybersecurity Analyst Location: Remote but must live within 50 miles of Hazelwood, MO Email resume to Julissa at [email protected] to apply Job Description Develops, deploys and/or maintains enterprise-wide computing and information security requirements, policies, standards, guidelines and procedures for secure, isolated environments. Advises on a broad range of compliant information security and data protection requirements. Determines acceptability of unique configurations and verifies security parameter placement. Investigates and resolves security incidents. Participates in security assessments and audits. - Employ best practices when implementing security requirements within an information system including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques. - Capture and refine information security requirements and ensure that the requirements are effectively integrated into information systems through purposeful security architecting, design, development, configuration and documentation for delivery to a wide customer base. - Perform security assessments of software, including research and manual/automated testing, and document security findings and recommended mitigations. - Educate team members on security best practices and participate in architecture meetings with application owners. - Analyze security situations, environmental factors and business objectives. Advises on a broad range of information security issues and interprets data protection requirements. Contributes to or develops security plans to meet assurance or protection requirements. - Analyze and documents computing security events. Identifies root causes, prioritizes threats and recommends and/or implements corrective action. Determines acceptability of unique configurations and verifies security profile settings. Tests and deploys risk mitigation processes and tools. - Investigate, analyze and resolve security questions and issues. Tests and deploys incident response processes and tools. Leads or participates on incident response teams. - Perform security compliance monitoring. Participates in security policy assessments and audits. Evaluates and tests security controls and applications. Contributes to corrective action planning Requirements - Minimum DoD Interim Secret Clearance - DoD 8570 Certification IAT Level 2 (Security+ Recommended) Skills/Experience - Be very detail oriented and be able to manage priorities in a fast-paced environment. - Must have solid troubleshooting skills and knowledge of common ports and protocols. - Familiarity with NIST security standards and Risk Management Framework (RMF). - Have a solid understanding of programming logic and API implementation. - The ability to read, write, understand and follow instructions within an installation script is necessary. - Must have scripting experience in at least 2 of the following: PowerShell, Python, Bash, SQL, VBScript, HTML, XML, JSON, CSV, JavaScript. - Must have knowledge of common security tools such as: Wireshark, NMAP, and vulnerability scanners such as Nessus. - Must have Systems Engineering and Administration experience in the following: Logging Utilities (ElastiSearch, Splunk, etc..), Enterprise Security Utilities (HIDS, NIDS, DLP), Virtualization Platforms, Windows Server services (AD, DNS, DHCP, Group Policy), UNIX/Linux/Microsoft Administration (file services, configuration, updates), Web servers (IIS, Apache), Software Installation - Knowledge of web applications and database technologies with basic understanding of common vulnerabilities affecting these technologies (OWASP Top 10 / CWE) - Experience installing\configuring complex Client\Server Applications that include multiple servers and\or a database is a plus EEO Employer Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at [email protected] or 844-463-6178. Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Apex uses a virtual recruiter as part of the application process. Click here for more details. Apex Benefits Overview: Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide. Employee Type: Contract Location: Hazelwood, MO, US Job Type: Pay Range: $35 - $55 per hour Similar Jobs - Cyber Security Analyst - Cyber Security Engineer - Cyber Security Analyst - Cyber Security Engineer (Ping) - Cyber Security Researcher - Remote
Advanced Cyber Security Architect Engineer
Honeywell AerospaceHoneywell Aerospace products and services are used on virtually every commercial, defense, and space aircraft. We build aircraft engines, cockpit and cabin electronics, wireless connectivity systems, mechanical components. Our hardware and software solutions help create more fuel-efficient aircraft, more direct and on-time flights and safer skies. Safer, More Fuel-Efficient Flying and Innovations for the Future of Aviation.
As a Network Security Engineer here at Honeywell, you will oversee the daily operations of our perimeter security technologies across global data centers and cloud environments, including firewall and proxy services. You will serve as a key technical resource—proactively identifying potential risks, proposing solutions, and ensuring seamless service delivery across interconnected infrastructure. You will collaborate closely with internal customers by responding to service requests and supporting secure operations across the enterprise. You will report directly to our Cybersecurity Manager and you’ll work remotely.



