Engineer IV, Product Security

1 month ago


Trenton, New Jersey, United States TheCollegeBoard Full time
Engineer IV, Product Security

College Board - Technology

Remote

About the Team

The College Board's Product Security team is an agile organization, embracing DevSecOps and cloud-native systems, and focused on improving speed and security of service delivery in support of an important mission. To enable this mission, the College Board is seeking an Engineer IV - Product Security to help drive the development of innovative and transformative security solutions in our DevSecOps and cloud transformation initiatives. The Engineer IV - Product Security is a highly technical and creative contributor to a bleeding edge cloud and application security team enabling the agile development of secure and reliable cloud-based solutions via strong partnerships and interactions with our Products Teams.

About the Opportunity

As a Product Security Engineer, you will support and manage a variety of projects in the Product Security team. In this role, you will both learn and introduce new security services, technologies, and technical solutions to secure our Products and platforms.

You will interact with different stake holders, product development leads, architects, Cybersecurity operations, Risk and Compliance teams and external partners/vendors such as ETS and various SaaS providers. You will review and adopt new innovative security solutions, make updates to existing solutions, negotiate alternative options and participate in building technical and release roadmaps.

As an Engineer IV, you will lead and mentor junior team members supporting their growth and development in Product Security concepts, tools and best practices.

In this role you will:
  • Partner Program - Partnership Development (50%)
    • Act as a liaison between Product Security teams (both in IT and outside of IT) and the Information Security Office via regular engagements with assigned Partner teams. Embed into planning and grooming sessions.
    • Develop deep understanding of our Security Policies and Audit requirements in order to support assigned Partner teams, GRC Exceptions and Audit efforts (PCI, SOC2, ISO27001, GDPR, State Contract requirements)
    • Create Risk Registers for your assigned products and communicate application risks and vulnerabilities to technical stakeholders.
    • Lead application vulnerability reviews and remediation efforts. Develop deep skill sets in understanding, managing and determining exploitability of vulnerabilities to properly determine risk and priority.
    • Work to gain a deep understanding of your assigned products' architectures, Supply Chain (Vendors, Partners, Third Party) Development Practices, CI/CD, GRC Exceptions, Release cadence in order to understand and support mitigation of security risks.
    • Partner with Senior Team members to mentor developers through discussions, presentations, or hands on training sessions to demonstrate best practices in developing secure code and securing application infrastructure.
    • Ensure all assigned products and applications adhere to the Product Security Framework requirements and work to remediate any gaps.
  • Elevate Product Security 25%
    • Work to promote, grow and enhance the Product Security Partners program to develop Security Champions and enable dev teams to shift left.
    • Develop and deliver guidance and training sessions to grow Product Team's Secure Development LifeCycle skills and awareness.
    • Grow skills to perform secure reviews of application architectures and security patterns as needed.
    • Grow skills to develop threat models and risk assessments in conjunction with architects and software engineering staff to identify application security weaknesses and provide coaching on remediation strategies.
    • Develop and deliver Secure Developer Training, Workshops, and training opportunities to cultivate a culture of Product Security
  • Operations 25%
    • Support implementing and operationalizing security tooling and common integrated development environments (AWS).
    • Develop, understand, and provide input into metrics and KPI's for assigned partner teams.
    • Participate in planning and grooming as part of agile ceremonies and manage assigned Epics.
    • Develop hands on expertise with CI/CD and build pipelines with an understanding of quality and security gates; participate in integration of automated solutions to increase security in CI/CD.
    • Work with broader ISO team on incident response and operational/strategic initiatives.
    • Evaluate and promote new and existing security standards, tools, and solutions with a focus on automation and securing build pipelines for a shift left approach.
About You

You have:
  • 3-5 years of progressively responsible, directly related experience
  • Hands on knowledge of secure development practices, Secure Development LifeCycle and DevSecOps
  • Understanding of key programming/scripting languages and secure best practices (Java, , Python, React, JavaScript, etc.).
  • Experience with key Development tools/systems (Artifact Management, Version Control, Work Tracking, Secrets Management, NPM, Build and Deployment Tools, etc.)
  • Knowledge of common vulnerabilities (OWASP/SANS) such as cross-site scripting (XSS), session hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors.
  • Familiar with common frameworks, spanning frontend and backend (Angular, Bootstrap, Node, Struts, Spring, ASP.NET MVC, etc.) and with AWS Services and with AWS cloud architecture security.
  • Experience with RESTful web services and API's
  • Ability to travel when required.
  • You are authorized to work in the US
About Our Process
  • Application review will begin immediately and will continue until the position is filled
  • While the hiring process may vary, it generally includes: resume and application submission, recruiter phone screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks
About Our Benefits and Compensation

College Board offers a competitive benefits and compensation program that attracts top talent looking to make a difference in education. As a self-sustaining non-profit, we believe in compensating employees equitably in relation to each other, their qualifications, their impact, and the relevant market.

The hiring range for a new employee in this position is $132,000 to $143,000. College Board differentiates salaries by location so where you live will narrow the portion of this range in which you can expect a salary.

Your salary will be carefully determined based on your location, relevant experience, the external labor market, and the pay of College Board employees in similar roles. College Board strives to provide our best offer up front based on this criteria.

Your salary is only one part of all that College Board offers, including but not limited to:
  • A comprehensive package designed to support the well-being of employees and their families and promote education. Our robust benefits package includes health, dental, and vision insurance, generous paid time off, paid parental leave, fertility benefits, pet insurance, tuition assistance, retirement benefits, and more
  • Recognition of exceptional performance through annual bonuses, salary growth over time through market increases, and opportunities for merit raises and promotions based on increased scope of responsibility
  • A job that matters, a team that cares, and a place to learn, innovate and thrive
You can expect to have transparent conversations about benefits and compensation with our recruiters throughout your application process.

#LI-DC1

#LI-REMOTE

  • Trenton, New Jersey, United States The Chemical Engineer Full time

    Join Our Team at The Chemical EngineerAt The Chemical Engineer, we are dedicated to addressing significant global challenges, from ensuring access to clean water for millions to developing materials crucial for modern technology and sustainable practices.Why Choose Us?We empower our employees to innovate and excel in their careers. Our competitive...


  • Trenton, New Jersey, United States L3Harris Technologies Full time

    Job Title: Senior Manager, Systems Engineering Job Code: 13295 Job Location: Greenville, Texas – (Responsibilities must be performed on-site.) Job Schedule: 9/80 Work Schedule – (Every other Friday is a non-workday.) Position Overview:L3Harris Technologies is in search of a Senior Manager in Systems Engineering, who will serve as a pivotal technical...


  • Trenton, New Jersey, United States L3Harris Technologies Full time

    Position Title: Senior Manager, Systems Engineering Position Code: 13295 Location: Greenville, Texas – (On-site responsibilities required.) Work Schedule: 9/80 Work Schedule – (Every other Friday is a non-working day.) Position Overview:L3Harris Technologies is in search of a Senior Manager for Systems Engineering, who will serve as a pivotal technical...


  • Trenton, New Jersey, United States SHI International Full time

    Job OverviewThe ASG Technical Solutions Engineer will serve as a technical expert, concentrating on the development and testing of solutions within both physical and virtual laboratory settings.This role involves collaboration with pre-sales engineering, cloud services, and other teams to comprehend market strategies and customer requirements, enabling the...


  • Trenton, New Jersey, United States Macom Technology Solutions Holdings, Inc. Full time

    Company Overview: MACOM Technology Solutions Holdings, Inc. specializes in the design and production of semiconductor solutions tailored for DataCenter, Telecommunications, and Industrial and Defense sectors. With its headquarters in Lowell, Massachusetts, MACOM operates design centers and sales offices across North America, Europe, and Asia. The company...


  • Trenton, New Jersey, United States Meta Full time

    Summary: The Meta Technical Program Management (TPM) community is pioneering technologies to bring people (and businesses) closer together at a global scale. TPMs work at the cross-section between technical execution and business strategy and are expected to partner closely with Engineering and Product teams. Being a TPM at Meta means driving impact by...


  • Trenton, New Jersey, United States Kinly's Global Services Full time

    Position: Lead Project Engineer - Audio Visual SolutionsEmployment Type: PermanentWork Location: United States – flexible location with some travel requirementsCompensation: Competitive salary and benefits package based on experienceInterview Structure: Two-stage interview processKinly's Global Services is a premier provider of audio-visual and unified...


  • Trenton, New Jersey, United States Integer Holdings Corporation Full time

    By living according to a common set of values, we create a culture that unifies, embraces the uniqueness we all bring to the company, and positions Integer for long-term success.At Integer, our values are embedded in everything we do.Customer We focus on our customers' successInnovation We create better solutionsCollaboration We create success...


  • Trenton, New Jersey, United States HUBER + SUHNER Full time

    Position Overview:As a Production Assembler, you will play a crucial role in the assembly of Huber+Suhner products, ensuring quality and efficiency in your work.Key Responsibilities:- Adhere to assembly guidelines and procedures for Huber+Suhner products.- Utilize designated tools, materials, and equipment effectively.- Identify opportunities for enhancing...


  • Trenton, New Jersey, United States Hutchinson Industries Full time

    Position Overview: The Nautical Systems Engineer will serve as the principal technical authority for the research, design, and innovation of products and systems that enhance the offerings of Hutchinson Industries. The ideal candidate will possess extensive experience in product design tailored for marine vessels and demonstrate a profound understanding of...


  • Trenton, New Jersey, United States Crescens Full time

    CrescensWe are seeking a skilled Portal Software Engineer to become a part of our dynamic team. This position involves the development of innovative software solutions, with a focus on analyzing and implementing Microsoft Dynamics 365 and Power Platform cloud-based enterprise applications.Key ResponsibilitiesDesign and develop software solutions by assessing...


  • Trenton, New Jersey, United States Hutchinson Industries Inc Full time

    Position Overview: The Naval Engineering Specialist plays a crucial role in the innovation, design, and enhancement of products and systems for Hutchinson Industries Inc. The successful applicant will possess a robust background in the design of maritime vessels and onboard systems. Primary Duties: Execute research, testing, and evaluations for prototype...


  • Trenton, New Jersey, United States Motion Recruitment Full time

    Position Overview:We are seeking a talented Senior Embedded Engineer to contribute to a prominent organization in the security devices and electronics sector, specifically within the Research and Development division.This division is crucial in the creation of globally utilized connected devices for esteemed clients, fostering innovation in the industry.This...


  • Trenton, New Jersey, United States Motion Recruitment Full time

    Position Overview:We are seeking a highly skilled Senior Embedded Engineer to contribute to a pioneering company specializing in security devices and electronic solutions. This role is integral to our Research and Development team, which is responsible for creating innovative connected devices utilized by prestigious clients worldwide.Work Environment:This...


  • Trenton, New Jersey, United States Motion Recruitment Full time

    Position Overview:We are seeking a highly skilled Senior Embedded Engineer to contribute to our innovative projects in the security devices and electronics sector. This role is integral to our Research and Development team, which is responsible for creating cutting-edge connected devices that serve a global clientele.Work Environment:This position is based...


  • Trenton, New Jersey, United States JENSEN HUGHES Full time

    About Jensen HughesAt Jensen Hughes, we prioritize our Purpose + Principles and value our team members. Our global network of experts, clients, and communities recognizes us for our leadership in fire protection engineering, a legacy we have proudly upheld since 1939.Our ExpertiseWe extend our expertise across various interconnected risk management fields,...


  • Trenton, New Jersey, United States Schneider Electric Full time

    Position: Senior Systems Application Engineer at Schneider ElectricIn the role of Senior Systems Application Engineer, you will be instrumental in managing the technology that underpins the Security Command Center, along with the enterprise physical access control and video management systems. Your key duties will encompass monitoring technical safeguards...


  • Trenton, New Jersey, United States HNTB Full time

    Position Overview:As an Electrical Engineer II, you will play a crucial role in contributing to the design and development of innovative engineering solutions that support our infrastructure projects.About HNTB:At HNTB, we are dedicated to creating meaningful careers while enhancing the communities we serve. With over a century of experience, we have...

  • Production Manager

    1 month ago


    Trenton, New Jersey, United States Michael Page Full time

    Five years' experience in fabrication or installation environmentAdvance level technical knowledge of the proper operation of any / all equipment About Our Client The client is a leader in the Countertop Industry. Its Purpose is "CREATING VALUE FOR OUR CLIENTS WITH RELATIONSHIPS". SUMMARY:To provide the necessary leadership to plan, organize, direct,...


  • Trenton, New Jersey, United States LMT Mercer Group Inc Full time

    Job OverviewPosition: Plastic Materials EngineerRole Summary:The Plastic Materials Engineer is tasked with the innovation and development of plastic-based materials and products. This role encompasses the creation of specifications, the establishment of manufacturing control protocols, and the design of components and assemblies. This position requires...