Senior Engineer

1 month ago


Jackson, Mississippi, United States TheCollegeBoard Full time
Senior Engineer - Product Security

College Board - Technology

Remote

About the Team

The College Board Product Security team is close knit and enthusiastic group of technologists with a thirst for knowledge in all things Security and Cloud. We collaborate closely daily to investigate and solve problems and have strong alignment with our Product Teams in order to be a step ahead in securing the organizations suite of Products. We are an agile organization, embracing DevSecOps and cloud-native systems, and are focused on improving speed and security of service delivery in support of our important mission. Our team is committed to diversity and inclusion, and we work to ensure everyone on the team has a voice. We hire great people from a wide variety of backgrounds and experience.

About the Opportunity

Our College Board Product Security Engineers work closely with Information Security, Governance and Compliance and Product teams to achieve product and security business objectives. They support the implementation of secure development practices, threat modelling, architecture, design, vulnerability assessments and security verification, as well as defining the security standards and managing operations for a variety of products and security tools.

In this role, you will frequently interact with a variety of stake holders in Technology and on the Business side to provide hands on risk remediation or recommendation solutions, including secure patterns and mitigation strategies. You will understand our product landscape and propose, and drive to implementation, new innovative security solutions, updates to existing solutions, negotiate alternative options and build technical and release roadmaps.

As a Senior Engineer, you will lead and mentor junior team members supporting their growth and development in Product Security concepts, tools and best practices.

In this role, you will:
  • Partner Program - Partnership Development (50%)
    • Act as a liaison between Product Security teams (both in IT and outside of IT) and the Information Security Office via regular engagements with assigned Partner teams. Embed into planning and grooming sessions.
    • Develop deep understanding of our Security Policies and Audit requirements in order to support assigned Partner teams, GRC Exceptions and Audit efforts (PCI, SOC2, ISO27001, GDPR, State Contract requirements)
    • Create Threat Models and Risk Registers for your assigned products and communicate application risks and vulnerabilities to technical stakeholders.
    • Lead application vulnerability reviews and remediation efforts. Develop deep skill sets in understanding, managing and determining exploitability of vulnerabilities to properly determine risk and priority.
    • Work to gain a deep understanding of your assigned products' architectures, Supply Chain (Vendors, Partners, Third Party) Development Practices, CI/CD, GRC Exceptions, Release cadence in order to understand and support mitigation of security risks.
    • Lead efforts to mentor developers through discussions, presentations, or hands on training sessions to demonstrate best practices in developing secure code and securing application infrastructure.
    • Ensure all assigned products and applications adhere to the Product Security Framework requirements and work to remediate any gaps.
  • Elevate Product Security 25%
    • Drive and lead efforts to promote, grow and enhance the Product Security Partners program to develop Security Champions and enable dev teams to shift left.
    • Lead development of innovative guidance and training sessions to grow Product Team's Secure Development LifeCycle skills and awareness and cultivate a culture of Product Security
    • Coach product teams and junior team members on performing secure reviews of application architectures and document and advertise new security patterns as needed.
    • Partner with junior team members and foster their ability to develop threat models and risk assessments to identify application security weaknesses or lack of maturity in development processes and provide coaching on remediation strategies.
    • Innovate, stay atop current activities in the industry to support continuous improvement of our Partner Program.
  • Operations 25%
    • Drive implementing and operationalizing security tooling and common integrated development environments (AWS).
    • Drive development of key metrics and KPI's to measure Product Security impact and report on assigned partner teams security posture and maturity of practices.
    • Participate in planning and grooming as part of agile ceremonies and manage assigned Epics.
    • Provide hands on expertise with CI/CD and build pipelines to further enhance quality and security gates; lead integration of automated solutions to increase security in CI/CD.
    • Work with broader ISO team on incident response and operational/strategic initiatives.
    • Lead evaluation and improvement of new and existing security standards, tools, and solutions with a focus on automation and securing build pipelines for a shift left approach.
About You

You Have:
  • 5-8 years of progressively responsible, directly related, hands on experience in application security or devsecops
  • Strong hands on knowledge of Secure Development practices, Secure Development LifeCycle, DevSecOps, Pen Testing and Threat Modeling
  • Solid experience with securing AWS Services, AWS Secure Architectures, Application Security and Cloud Applications, including Software Supply Chain and micro service architecture
  • Must have a thorough understanding of web protocols TCP/IP, UDP, HTTP, HTTPS, SSL, TLS, DNS, etc.
  • Hands on experience of reproducing and remediating common application vulnerabilities (OWASP/SANS) such as cross-site scripting (XSS), session hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors.
  • Solid hands on experience with CI/CD, Nodejs, React, Restful Api's and common development frameworks (Angular, Bootstrap, Node, Struts, Spring, ASP.NET MVC, etc.)
  • Experience with key Development tools/systems (Artifact Management, Version Control, Work Tracking, Secrets Management, NPM, Build and Deployment Tools, etc.)
  • Experience with RESTful web services and API's
  • Ability to travel when required.
  • You are authorized to work in the US
About Our Process
  • Application review will begin immediately and will continue until the position is filled
  • While the hiring process may vary, it generally includes: resume and application submission, recruiter phone screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks
About Our Benefits and Compensation

College Board offers a competitive benefits and compensation program that attracts top talent looking to make a difference in education. As a self-sustaining non-profit, we believe in compensating employees equitably in relation to each other, their qualifications, their impact, and the relevant market.

The hiring range for a new employee in this position is $144,000 to $157,000. College Board differentiates salaries by location so where you live will narrow the portion of this range in which you can expect a salary.

Your salary will be carefully determined based on your location, relevant experience, the external labor market, and the pay of College Board employees in similar roles. College Board strives to provide our best offer up front based on this criteria.

Your salary is only one part of all that College Board offers, including but not limited to:
  • A comprehensive package designed to support the well-being of employees and their families and promote education. Our robust benefits package includes health, dental, and vision insurance, generous paid time off, paid parental leave, fertility benefits, pet insurance, tuition assistance, retirement benefits, and more
  • Recognition of exceptional performance through annual bonuses, salary growth over time through market increases, and opportunities for merit raises and promotions based on increased scope of responsibility
  • A job that matters, a team that cares, and a place to learn, innovate and thrive
You can expect to have transparent conversations about benefits and compensation with our recruiters throughout your application process.

#LI-DC1

#LI-REMOTE

  • Jackson, Mississippi, United States Out Professionals Full time

    Join Our Team as a Senior Electrical Systems EngineerAt Chemours, we are committed to shaping the future of chemistry and making a positive impact on the world. Our employees play a vital role in this mission, contributing to innovations that enhance everyday life.Chemours, a leading $6.3 billion company, boasts a diverse portfolio of products and processes...


  • Jackson, Mississippi, United States CapLeo Global Full time

    Position: Senior Natural/ADABAS Software EngineerLocation: RemoteContract Duration: 12 MonthsWe are looking for an experienced Senior Natural/ADABAS Software Engineer to become a vital part of our innovative development and support team focused on enhancing state-level systems. This position entails the improvement and upkeep of the system, integrating...


  • Jackson, Mississippi, United States The Mathany Group Full time

    This is an exceptional opportunity to become part of a firm with a significant project pipeline projected to extend for several years, focusing on major private sector initiatives in the region with substantial financial investments. The firm also manages a variety of traditional civil engineering projects across multiple states.The Senior Civil Engineering...


  • Jackson, Mississippi, United States Evolution Mobility Full time

    Position Overview We are seeking a full-time Senior Industrial Engineering Manager (all genders) to become a vital part of our dynamic Operations Crew at Evolution Mobility. Our team is dedicated to developing, producing, and managing innovative Mobility-as-a-Service solutions that integrate both hardware and software components tailored for mobility...


  • Jackson, Mississippi, United States Consumers Energy Full time

    This position is hybrid (virtual/onsite) with a requirement to be onsite Monday, Tuesday and Thursday with the opportunity to work virtually Wednesday and Friday per business needs. The candidate may be assigned to Groveland Service Center located in Howell, MI or Flint Service Center location in Flint, MI (other Consumers Energy Service Centers nearby these...


  • Jackson, Mississippi, United States Lorven technologies Full time

    Job OverviewPosition: DevOps EngineerLocation: RemoteExperience: 10+ years in consultingRole Summary:We are seeking a skilled and highly efficient Senior DevOps Engineer to enhance our development and support initiatives. The focus will be on maintaining and upgrading our statewide systems, integrating the latest technologies to streamline processes and...


  • Jackson, Mississippi, United States Lorven technologies Full time

    Job OverviewPosition: DevOps EngineerLocation: Remote Work Option AvailableExperience Required: 10+ years in ConsultingJob Responsibilities:We are seeking a skilled and impactful Senior DevOps Engineer to enhance our development and support initiatives.The role involves the ongoing support, enhancement, and maintenance of a comprehensive state system,...


  • Jackson, Mississippi, United States Cadence Design Systems Full time

    Position Overview:As a Senior Applications Engineer specializing in Emulation Solutions at Cadence Design Systems, you will play a pivotal role in addressing critical customer challenges through our advanced hardware platforms. Key Responsibilities:In this customer-centric position, you will:1. Establish technical authority and build strong relationships...


  • Jackson, Mississippi, United States E-Solutions INC Full time

    Job OverviewWe are seeking a skilled and dynamic Senior DevOps Engineer to become a vital part of our development and support team at E-Solutions Inc.. This role involves enhancing and maintaining complex systems while integrating cutting-edge technologies.Key ResponsibilitiesDesign, configure, and manage both public and private cloud infrastructures.Utilize...


  • Jackson, Mississippi, United States Lorven technologies Full time

    Job OverviewPosition: DevOps EngineerLocation: Onsite - Local candidates preferredExperience: 10+ years in consultancyRole Summary:We are seeking a skilled and impactful Senior DevOps Engineer to enhance our development and support initiatives. The role involves maintaining and improving the statewide MDHS system, incorporating the latest technologies for...


  • Jackson, Mississippi, United States Dewberry Full time

    About the RoleDewberry is seeking a highly skilled Senior Electrical Engineer to join our team in a leadership capacity. As a key member of our electrical engineering team, you will provide technical guidance and oversight to ensure the successful completion of projects.Key ResponsibilitiesProvide technical guidance and quality oversight of all project work...


  • Jackson, Mississippi, United States LGL Technologies Full time

    Job OverviewLGL Technologies is seeking a highly skilled and effective Senior DevOps Engineer to enhance our development and support operations. The role involves maintaining and improving the statewide MDHS system through the integration of advanced technologies across various platforms and the automation of existing processes.Key ResponsibilitiesDesign,...


  • Jackson, Mississippi, United States E-Solutions INC Full time

    Job OverviewWe are seeking a highly skilled and effective Senior DevOps Engineer to become a vital part of our development and support team at E-Solutions Inc.. This role is essential in enhancing and maintaining our statewide systems through the implementation of cutting-edge technologies and automation of existing processes.Key ResponsibilitiesDesign,...


  • Jackson, Mississippi, United States LGL Technologies Full time

    Job OverviewLGL Technologies is seeking a highly skilled and effective Senior DevOps Engineer to enhance our development and support initiatives. This role focuses on maintaining and improving the statewide MDHS system through the integration of cutting-edge technologies and the automation of existing processes.Key ResponsibilitiesDesign, configure, and...


  • Jackson, Mississippi, United States LGL Technologies Full time

    Job OverviewWe are seeking a highly skilled and experienced Senior DevOps Engineer to enhance our development and support capabilities. This role involves maintaining and improving the statewide MDHS system, utilizing cutting-edge technologies to facilitate integration with various platforms and automating existing processes.Key ResponsibilitiesDesign,...


  • Jackson, Mississippi, United States Elegant Enterprise- Wide Solutions Inc Full time

    Job OverviewWe are seeking a highly skilled Senior .NET Software Engineer to contribute to our innovative projects at Elegant Enterprise-Wide Solutions Inc. The ideal candidate will possess extensive experience in developing and maintaining applications utilizing Microsoft Technologies.Key ResponsibilitiesTechnical Expertise Required:Proficient in...


  • Jackson, Mississippi, United States E-Solutions INC Full time

    Job OverviewWe are seeking a skilled and proficient Senior DevOps Engineer to become a vital part of our development and support team. The ideal candidate will play a crucial role in enhancing and maintaining our statewide system, leveraging the latest technologies to ensure seamless integration with various platforms and automating existing processes.Key...


  • Jackson, Mississippi, United States electra Full time

    About Us:Electra is transforming ironmaking to decarbonize steel production and reduce 3.7 gigatons or 10% of global CO2 emissions. Utilizing established industrial-scale electrochemical and hydrometallurgical techniques, and supported by prominent sustainability-driven investors, our team is creating cost-effective, scalable solutions that harness...


  • Jackson, Mississippi, United States Goodwin Recruiting Full time

    Application ProcessGoodwin Recruiting is seeking an experienced Electrical Engineer to lead innovative projects within the renewable energy sector. This role is pivotal in advancing our initiatives in solar technology.Compensation & Benefits for the Electrical Engineer Position:Paid Time Off and Vacation401k Plan with Employer MatchComprehensive Health,...


  • Jackson, Mississippi, United States Waniprojects Full time

    Position OverviewWe are seeking a Senior Project Coordinator with a robust background in civil engineering and extensive experience in managing large-scale projects.QualificationsExperience: 10 to 12 years in project management.Education: Bachelor’s degree in Civil Engineering.Key ResponsibilitiesAs a Senior Project Coordinator, you will:Develop detailed...