Senior Product Security Engineer mitigating security risks and ensuring compliance with industry standards at HPE. Collaborating with cross-functional teams and leading security initiatives in software development.
Responsibilities
Play a critical role in identifying and mitigating potential security risks, collaborating with cross-functional teams and other stakeholders, and maintaining compliance with industry standards and regulations.
Conduct secure design assessments and vulnerability tests to identify potential security threats and develop strategies to mitigate them.
Collaborates with all stakeholders like product management and engineering teams to integrate security into all stages of design and development for complex products and platforms, including solution design, analysis, coding, testing, and integration.
Provide guidance and support to product development teams in implementing secure coding practices and security best practices.
Implement automated tooling strategies and techniques that include but are not limited to static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), etc.
Lead key initiatives to mature HPE’s security programs like secret management, cloud security, supply chain security, AI/LLM security etc.
Educating and communicating security information and best practices to other stakeholders at HPE.
Lead investigations into security incidents and develop corrective action plans to prevent future occurrences.
Monitor the effectiveness of security controls and drive innovation and integration of new security technologies within the organization.
Represent HPE at industry events and conferences as a product security subject matter expert.
Provides guidance and mentoring to less-experienced staff members.
Requirements
Bachelor's or Master's degree in Computer Science, Information Systems, or equivalent.
Typically 6-10 years experience in a security role.
Extensive experience with product security for multiple software systems design tools and languages.
Experience in cloud security technologies.
Experience in common security vulnerability classes and taxonomies.
Experience in security constructs in programming languages like python, java, go, and C.
Experience in overall architecture of software systems for products and solutions.
Excellent analytical and problem-solving skills.
Excellent written and verbal communication skills; mastery in English and local language.
Ability to effectively communicate product architectures, design proposals and negotiate options at senior management levels.
Benefits
Health & Wellbeing We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
Unconditional Inclusion We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
Cyber Security & Compliance Lead protecting data and systems at Displayr. Responsible for risk management, compliance frameworks, and innovative security solutions using AI.
Lead Engineer in Security Engineering at Allstate overseeing security controls and product security teams. Collaborating with global stakeholders to manage security architecture and meet key performance indicators.
AI Security Architect focusing on AI security and governance for Voya Financial's applications and projects. Leading initiatives in artificial intelligence and securing innovative technology solutions.
Application Architecture Engineer responsible for defining software architecture frameworks and leading implementation teams. Driving innovation in developing robust and scalable applications at Schneider Electric.
Senior Analyst for Third - Party Security at a leading law firm. Responsible for program execution and risk assessment regarding vendors and service providers.
Security Officer managing safety and security at Cromwell Hospital and Canary Wharf locations. Responding to security requests and maintaining logs while ensuring compliance with safety regulations.
Behavioral Health & Security Associate in Peoria providing care and oversight for patients with behavioral health needs. Ensuring a safe environment and effective support for patients and staff.
AI Security Engineer at Prologis focused on securing AI integrations and developing AI security controls. Collaborating with engineering and business teams to promote secure AI practices.
Project Coordinator managing security projects at The Missing Link, ensuring client satisfaction and project deliverables. Coordinating teams and maintaining timelines for project success in the IT field.
Information Security Specialist ensuring optimal protection of data and systems at University of Toronto. Implementing security platforms and best practices for data integrity and threat mitigation.