Lead Security Engineer

6 days ago


San Francisco, United States Stars Group Full time

As our Application Security Lead Engineer, you will be responsible for the security of our apps/services – Web, Mobile and API–based at Scale. You will be responsible for threat modeling products from the ground up, implementing and managing security controls at various points of the Secure Software Development Lifecycle, and setting up processes and guidelines.
The Goal is to build Seamless Security. We want you to redefine how developers view security, eliminating friction and improving Security natively.

You will work closely with other Security functions, DevOps, Architects, Developers, and QA to build highly reliable and secure products.

Responsibilities

  • Identify novel ways to scale Threat modeling across multiple applications. A prior experience of 4+ years of threat modeling products and prior work on building Secure Architecture is desirable.
  • Expertise in 2 or more of the following areas with prior experience of solving at scale:
    • API Security
    • Web Application Security
    • Mobile Application Security
  • Prepare Secure by Design reference architectures for Developer adoption – Secure Architecture frameworks.
  • Lead and own the SSDLC and envision a frictionless experience for Developers in the lifecycle. Own the SAST, DAST, and other Security tools in the lifecycle. Work on findings evaluation, prioritization, and fix/mitigate at scale.
  • Build the SCA (Software Composition Analysis) map for all the third–party dependency usage at Scale and prioritize vulnerabilities based on EPSS, CISA KEV.
  • Perform Secure Code reviews. Minimum experience of 2+ years is desirable.
  • Own the Vulnerability Management with a focus on vulnerability prioritization using EPSS, CISA KEV.
  • Implement Data Security standards and work with Engineering to address Sensitive Data leakage.
  • Implement a robust way to identify all third–party applications (COTS–Commercial–Off–the–Shelf) used across the ecosystem. Work on providing proactive Security Best practice evaluation and enforcement for all such applications.
  • Lead and own the Security Champions program and build/curate developer/QA centric training modules.
  • Work with the Cloud Security team to improve Web App Firewalls (WAF). Prior experience with WAF rule fine–tuning is a plus. Ensure early identification of intrusion & attacks and implement countermeasures.

Partner with the SOC team for Security Incident Management and Remediation triage with Engineering across the ecosystem.

Requirements

  • Overall 7+ years of relevant experience.
  • Bachelor's degree in Computer Science or a related technical discipline, or equivalent practical experience.
  • Understanding of security frameworks and standards like OWASP & NIST. Solid understanding of security protocols, cryptography, authentication, and authorization. Prior Experience in solving any of OWASP Top 10 at scale is highly desirable.
  • Good understanding of Linux and Windows OS, TCP/IP protocol stack, networking fundamentals, and security principles at all layers of the OSI stack.
  • Experience with API security, network security, cryptography, PKI, and certificate management.
  • Experience in CI/CD Tools Including Git, Jenkins, Ansible, or similar.
  • Knowledge and experience in web application security testing, vulnerability assessment, penetration testing, and generating reports using tools like Burp Suite, Paros, AppScan, Wireshark, Nmap, and Nessus.
  • Advanced Expertise in at least one language, Shell scripting/Python/Go/NodeJS.

About Junglee Games

Junglee Games is a leader in the skill–gaming space, with close to 96 million users. Founded in San Francisco in 2012, and part of the $30 Bn Flutter Entertainment Group, Junglee Games is the fastest–growing skill–gaming company in the world. Some of our notable games are Junglee Rummy, Howzat, Eatme.io, Carron Stars, and Solitaire Gold.

Our mission is to build entertainment for millions of people around the world and connect people through high–quality games.

Since we were founded, we've drawn 700 of the world's most talented people into our ranks. Our team has worked on international AAA titles like Transformers, Star Wars: The Old Republic, Real Steel, Rio, Mech Conquest, and Dueling Blades. Our designers have worked on some of Hollywood's biggest hits including the movie Avatar.

Junglee is not just a gaming business – it is a blend of data science, innovation, cutting–edge technology, and, most importantly, a values–driven culture that is creating the next set of conscious leaders. Junglee Games is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

#J-18808-Ljbffr

  • San Francisco, United States IDENTIFY SECURITY Full time

    We are seeking a highly skilled Staff Application Security Engineer with a strong background in cloud software service management and application security to join our dynamic team. In this role, you will play a crucial part in ensuring the reliability, scalability, and security of our software systems and digital experiences. You will work closely with the...


  • San Francisco, United States IDENTIFY SECURITY Full time

    We are currently seeking a Staff Embedded Security Engineer. This position requires an experienced professional with a proven track record of cyber security development achievements. Our ideal candidate exhibits a can–do attitude and approaches his or her work with vigor and determination. Candidates will be expected to demonstrate excellence in their...

  • Tech Lead Manager

    2 weeks ago


    San Francisco, United States Opal Security Full time

    Opal is building the next generation of access management. We've all felt the pain of not getting the access we need to do our job. At Opal, we’re building a central hub for authorization to make access management automated, intelligent, and easy to use. Our product prioritizes consumer grade simplicity with enterprise scale, reliability, and security. Our...


  • San Francisco, United States DoorDash USA Full time

    About the Team DoorDash Labs is an independent team within DoorDash. We are working on building autonomous delivery robots from the ground-up and other automation solutions as part of DoorDash's core delivery platform. If you have a passion for ensuring the robotic solutions used by millions of people are secure, then we want to talk to you! About the...


  • San Francisco, United States salesforce Full time

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job Category: ProductAbout SalesforceWe’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new...

  • Security Engineer

    2 weeks ago


    San Francisco, United States BlueVoyant Full time

    MXDR Security Engineer IILocation: Remote in SingaporeBlueVoyant is excited to invite applications for the role of Security Engineer II. In this dynamic position, you will use your expertise in Microsoft Cloud security technologies and SIEM platforms to enable our MDR solutions in customer environments. In this role, you will take the lead in client facing...

  • Security Engineer

    3 weeks ago


    San Francisco, United States BlueVoyant Full time

    MXDR Security Engineer IILocation: Remote in SingaporeBlueVoyant is excited to invite applications for the role of Security Engineer II. In this dynamic position, you will use your expertise in Microsoft Cloud security technologies and SIEM platforms to enable our MDR solutions in customer environments. In this role, you will take the lead in client facing...


  • San Francisco, United States Opal Security Full time

    Opal is redefining identity security for modern enterprises. The concept of least privilege access is well understood in theory but very hard in practice. We've all felt the pain of not getting the access we need to do our job - and security teams feel the pain of either being a bottleneck or authorizing everyone at the expense of risk. At Opal, we’re...

  • Security Engineer

    4 weeks ago


    San Francisco, United States Factory Full time

    ResponsibilitiesRole Overview Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript,...

  • Security Engineer

    3 weeks ago


    San Francisco, United States Factory Full time

    Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript, Python, Kubernetes, CI/CD,...

  • Security Engineer

    3 weeks ago


    San Francisco, United States Factory Full time

    Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript, Python, Kubernetes, CI/CD,...


  • San Francisco, United States Salesforce, Inc. Full time

    Lead Software Engineer, Application Security and DDoSApply remote type Office Tech-Flexible locations California - San Francisco Washington - Seattle Colorado - Denver time type Full time posted on Posted Yesterday job requisition id JR271916To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you...


  • San Francisco, United States Salesforce Full time

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job Category: ProductAbout SalesforceWe're Salesforce, the Customer Company, inspiring the future of business with AI + Data + CRM. Leading with our core values, we help companies across every industry blaze new...


  • San Francisco, United States Incode Technologies Full time

    The OpportunityWe are looking for a trustworthy and proactive Senior Security Engineer to be the technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations...


  • San Francisco, United States DoorDash USA Full time

    About the Team At DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Security is integral to the success of the business, as we secure the data and protect the privacy of our business and various stakeholders. The Security Operations team spans...


  • San Francisco, United States Abnormal Security Full time

    Job DescriptionJob DescriptionAbout The RoleEnterprises of all sizes trust Abnormal Security's cloud products to stop cybercrime. Being effective at stopping cybercrime, due to its adversarial nature, requires a high level of agility to respond to threats. Our Research and Development organization is forming a group to develop advanced AI-powered...


  • San Francisco, United States salesforce Full time

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job Category: Software EngineeringAbout Salesforce:We’re Salesforce, the Customer Company, inspiring the future of business with AI + Data + CRM. Leading with our core values, we help companies across every...


  • San Francisco, United States Nextdoor Full time

    Job DescriptionJob Description#TeamNextdoorNextdoor is where you connect to the neighborhoods that matter to you so you can belong. Our purpose is to cultivate a kinder world where everyone has a neighborhood they can rely on.Neighbors around the world turn to Nextdoor daily to receive trusted information, give and get help, get things done, and build...


  • San Francisco, United States Nextdoor Full time

    #TeamNextdoor Nextdoor is where you connect to the neighborhoods that matter to you so you can belong. Our purpose is to cultivate a kinder world where everyone has a neighborhood they can rely on. Neighbors around the world turn to Nextdoor daily to receive trusted information, give and get help, get things done, and build real-world connections with those...


  • San Francisco, United States Anthropic Limited Full time

    About the role:Anthropic is working on frontier AI research that has the potential to transform how humans and machines interact. As our models grow more powerful, securing them from exfiltration or misuse becomes critically important. In this role, you‘ll be helping to build and institute controls to lock down our AI training pipelines, apply security...