Senior Product Security Engineer mitigating security risks and ensuring compliance with industry standards at HPE. Collaborating with cross-functional teams and leading security initiatives in software development.
Responsibilities
Play a critical role in identifying and mitigating potential security risks, collaborating with cross-functional teams and other stakeholders, and maintaining compliance with industry standards and regulations.
Conduct secure design assessments and vulnerability tests to identify potential security threats and develop strategies to mitigate them.
Collaborates with all stakeholders like product management and engineering teams to integrate security into all stages of design and development for complex products and platforms, including solution design, analysis, coding, testing, and integration.
Provide guidance and support to product development teams in implementing secure coding practices and security best practices.
Implement automated tooling strategies and techniques that include but are not limited to static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), etc.
Lead key initiatives to mature HPE’s security programs like secret management, cloud security, supply chain security, AI/LLM security etc.
Educating and communicating security information and best practices to other stakeholders at HPE.
Lead investigations into security incidents and develop corrective action plans to prevent future occurrences.
Monitor the effectiveness of security controls and drive innovation and integration of new security technologies within the organization.
Represent HPE at industry events and conferences as a product security subject matter expert.
Provides guidance and mentoring to less-experienced staff members.
Requirements
Bachelor's or Master's degree in Computer Science, Information Systems, or equivalent.
Typically 6-10 years experience in a security role.
Extensive experience with product security for multiple software systems design tools and languages.
Experience in cloud security technologies.
Experience in common security vulnerability classes and taxonomies.
Experience in security constructs in programming languages like python, java, go, and C.
Experience in overall architecture of software systems for products and solutions.
Excellent analytical and problem-solving skills.
Excellent written and verbal communication skills; mastery in English and local language.
Ability to effectively communicate product architectures, design proposals and negotiate options at senior management levels.
Benefits
Health & Wellbeing We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
Unconditional Inclusion We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
Senior Cloud Security Engineer enhancing cloud security measures for Iterable's customer engagement platform. Collaborating across teams to identify vulnerabilities and drive architectural improvements in security.
Security Specialist managing critical firewall operations and secure network environments at Vodafone. Collaborating with cross - functional teams to ensure strong service continuity.
Data Scientist for Security and Intelligence consulting focusing on analytics and machine learning capabilities in secure environments. Collaborating with multidisciplinary agile teams on operational intelligence challenges.
Data Engineer designing and maintaining secure data platforms for advanced analytics in Security and Intelligence consulting. Collaborating with agile teams to deliver robust data engineering solutions.
Lead Security Controls Technician installing and troubleshooting electronic door control systems in correctional facilities. Requires experience in low - voltage systems and strong troubleshooting skills.
Lead Information Security Engineer evaluating and integrating cybersecurity technologies at Wells Fargo. Collaborating with teams to enhance defense capabilities and maintain security innovation efforts.
Lead Information Security Engineer at Wells Fargo responsible for cybersecurity tools management and support. Ensuring effective operation of critical defense technologies and collaboration with security teams.
Lead Information Security Engineer at Wells Fargo overseeing email security and threat mitigation strategies. Collaborate across teams to enhance security controls and policies.
Principal Information Security Architect utilizing extensive cybersecurity knowledge including threat modeling and risk assessment. Implementing Saviynt IGA solutions and collaborating with security teams.
Security Guard ensuring access control at healthcare facilities in Cincinnati, OH. Monitoring premises and responding to security incidents in Cincinnati location.