Senior Product Security Engineer

2 weeks ago


united states Tyler Technologies Full time

Description

Tyler Technologies is seeking a passionate, talented Senior Product Security Engineer to support our Data and Insights (D&I) solutions on the Security team. This position is an exciting opportunity to influence the security posture of our D&I portfolio, augment our development processes with security-centric activities, and maintain our FedRAMP Moderate ATO. As a Senior Product Security Engineer, you will work in a fast-paced, results-driven environment with highly skilled and dedicated teams committed to transformational change.

The D&I solution serves as Tyler Technologies' central hub for data, reporting, analytics, and artificial intelligence capabilities. Our teams build and maintain the foundational services and solutions that enable data-driven innovation across Tyler's product portfolio. We empower teams throughout the organization to incorporate advanced analytics, AI, and data-driven features into their products, ultimately helping government agencies make better decisions and serve their communities more effectively. Team members contribute their expertise to reduce complexity, introduce innovative solutions, and advance Tyler's data-driven future.

Responsibilities

Conduct bi-weekly DAST assessments against our production environments. Investigate and report results. Collaborate with engineering for awareness and remediation. Develop and execute a DAST improvement plan inclusive of tool migration and automation inclusion. Coordinate, reproduce, and validate reported security findings from clients, cross-team researchers, and third-party penetration testers. Monitor and investigate inbound application and infrastructure security alerts. Manage an active bug bounty program. Develop and execute an improvement plan that elevates researcher interaction and general program involvement. Assume primary responsibility for control families that contribute to our FedRAMP Moderate, SOC2, GDPR, HIPAA, and CJIS certifications. Responsibility includes continuous improvements and auditing, evidence collection and submission, interview participation, internal security reviews, and tabletop exercises. Participate in security strategy and planning, including team vision, roadmaps, and increment planning. Coach and collaborate with team members to normalize and measure, through a maturity model, security best practices. Participate in engineering team meetings, facilitating secure design through instrumenting threat modeling. Investigate, document, and resolve security incidents (IRP and ISCP) and provide analysis to senior leadership. Stay informed about emerging security trends and technologies. Create and deliver security training and awareness programs for developers, testers, and other stakeholders.

Qualifications

Soft Skills

Strong organization and prioritization skills. A proven ability to react positively and decisively to change Superior verbal and written communication skills, with the ability to communicate complex technical solutions to non-technical audiences Deadline-driven, team-oriented, be a self-starter, have great people skills, a strong work ethic, and be enthusiastic and ambitious Flexible. Able to independently manage multiple efforts simultaneously while maintaining professionalism under pressure A passion for improving the client experience and a track record of successful interactions with internal/external clients Excellent troubleshooting skills A technical leader with the ability to inspire and support peers

Tools and Technology

3-5 years of security engineering experience Working experience in Agile Kanban development methodologies Expertise in collaboration and prioritization using Confluence, Jira, and Teams In-depth knowledge of common web application vulnerabilities, such as OWASP Top Ten (e.g., SQL injection, XSS, CSRF) Proficiency with a wide range of security testing tools, including but not limited to vulnerability scanners (e.g., Nessus, Qualys), web application scanners (e.g., Burp Suite Pro, Invicti, OWASP ZAP), and penetration testing frameworks (e.g., Metasploit) Familiarity with implementing and managing multiple NIST 800-53 control families: Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, System and Information Integrity Strong Python scripting skills and GitHub Enterprise experience Experience with static application security testing (SAST), security information and event management (SIEM) systems, and intrusion detection/prevention systems (IDS/IPS) Understanding of network and information security best practices Experience with Linux, Ubuntu, AWS, Red Hat Familiarity in one or more: threat analysis, security automation, penetration testing, incident response, IAM, bug bounty programs, third-party vendor management Working experience in cloud log management solutions (e.g., Sumo Logic) Experience securing cloud environments with an understanding of cloud security infrastructure and cloud security principles Understanding of DevOps and continuous integration/continuous delivery (CI/CD) pipelines and how to integrate security into the DevOps process Understanding of attack vectors for cloud environments Knowledge of encryption algorithms, certificate management, and cryptographic protocols Required to undergo and satisfactorily pass a fingerprint background check in accordance with CJIS requirements.

Other

Bachelor's degree in Computer Science, Engineering, Mathematics, Information Systems, or a related field preferred Valued Certifications: CompTIA Security+, CompTIA Cybersecurity Analyst (CySA+), AWS Professional, AWS Security

We aspire to be remarkable: in the culture we create, the products we build, and the services we deliver. We believe a diverse team that embodies different backgrounds and experiences is necessary for us to be the best we can be. We actively build and strengthen a culture of inclusivity, creating a welcoming environment where everyone can be their authentic selves. We are committed to living out all our values in our daily work as individuals. 



  • united states Medallia Full time

    Overview Medallia is the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia Experience Cloud, leads the market in the understanding and management of experience for candidates, customers, employees, patients, citizens and residents. We are more than a software company. We want to be known as a company that does the...


  • united states Lorven Technologies Full time

    Role: Senior Application Security Engineer Location: Remote role Duration: Long Term Contract Job Description: Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in web security, applied cryptography, software security vulnerabilities, IAM solutions, including federation, and...


  • united states Lorven Technologies Full time

    Our client is looking Senior Application Security Engineer for long term project in Remote Below is the detail requirement. Role : Senior Application Security Engineer Location : Remote Job Description: Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in web...


  • united states Stellent IT LLC Full time

    Hello, I hope you are doing well Kindly acknowledge me, are you Comfortable with this Position then please share with me your updated resume Job Title Product Security Engineer Location Remote Duration long term Job Description The Product Security Engineer will be responsible for implementing the enterprise Product Security strategy and framework...


  • united states ClickUp Full time

    ClickUp is the world's only all-in-one productivity platform that flexes to the way people want to work. It replaces all individual workplace productivity tools with a single, unified platform including project management, document collaboration, spreadsheets, chat, goals, and more. On a mission to make the world more productive, ClickUp is headquartered in...


  • united states Peloton Full time

    ABOUT THE ROLEPeloton inspires and motivates millions of people every day. A key part of delivering on that mission is not only an amazing experience that our instructors and platforms provide, but also the data, telemetry, and insights that empower our customers to be the best version of themselves anywhere, anytime. Earning and maintaining our customers'...


  • united states Rivian Full time

    About Rivian Rivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract. As a company, we constantly challenge what's possible, never simply accepting what has always been done. We reframe old problems, seek new solutions and operate...


  • united states Lorven Technologies Full time

    Job Title: Senior Security Cloud Engineer Location: Washington, DC 20001 (Remote) Durattion: 12 months contract Job Description: Position Requirements and Duties: In-depth knowledge of cloud security best practices, principles, and technologies, including IAM, encryption, network security, container security, and serverless security. Hands-on...


  • united states Varonis Full time

    Description Position: Senior Sales Engineering Trainer Location: Remote Overview: At Varonis, a leader in data security and analytics, we are seeking a Head of Sales Engineering Enablement to lead our enablement team. This role involves strategic leadership and management of a team responsible for the onboarding, training, coaching, and ongoing...


  • united states Mattermost Full time

    At Mattermost, we build the #1 collaborative workflow solution for defense, intelligence, security, and critical infrastructure organizations. Trusted by governments, financial institutions, and technology companies, our platform enables secure, efficient operations for the world's most critical teams. We're dedicated to empowering organizations to operate...


  • nc, united states Oracle Full time

    Do you want to advance your career with the world's first cloud company? Since 1998, Oracle NetSuite has been on a mission to deliver an agile, unified application suite that gives leaders a complete view into their business. Our team is growing, and we're looking for people like you to help us make a global impact. As the leading cloud business system,...


  • united states Grammarly Full time

    The opportunity   Grammarly is the world's leading AI writing assistance company, trusted by over 30 million people and 70,000 professional teams daily. From instantly creating a first draft to perfecting every message, Grammarly's product offerings help people at 96% of the Fortune 500 get their point across—and get results. Grammarly has been...


  • united states ClickUp Full time

    ClickUp is the world's only all-in-one productivity platform that flexes to the way people want to work. It replaces all individual workplace productivity tools with a single, unified platform including project management, document collaboration, spreadsheets, chat, goals, and more. On a mission to make the world more productive, ClickUp is headquartered in...


  • united states VENAFI Full time

    There are 2 actors on a network, people and machines. Just as usernames and passwords are used by people to access machines, machine identities are used by machines to identify and access each other. Venafi is the inventor of the technology that manages and protects machine identities, the most important security initiative in our Global 5000 customers. We...


  • alabama, united states BASF Corporation Full time

    Now Hiring Senior Production Engineer McIntosh, Alabama - On site / Relocation assistance / Annual bonus Come create chemistry with us We are looking for a Senior Production Engineer to join our Performance Chemicals team in McIntosh, AL.  As an innovative partner, BASF's Performance Chemicals division offers chemicals for various customer...


  • united states VENAFI Full time

    There are 2 actors on a network, people and machines. Just as usernames and passwords are used by people to access machines, machine identities are used by machines to identify and access each other. Venafi is the inventor of the technology that manages and protects machine identities, the most important security initiative in our Global 5000 customers. We...


  • united states Incode Full time

    POWER A WORLD OF TRUSTIncode is the leading provider of world-class identity solutions that is reinventing the way humans authenticate and verify their identities online to power a world of digital trust.Through our revolutionary identity solutions, we are unleashing the business potential of universal industries including finance, government, retail,...


  • united states Microsoft Full time

    Overview The Microsoft Security Response Center is looking for a Senior Security Incident Responder to join the Microsoft 365 (M365) Security response team. Microsoft 365 brings together cloud-hosted offerings of our most trusted communications and collaboration services (like Exchange, SharePoint, Teams, and more) with our cross-platform desktop and...

  • Security Engineer 4

    5 days ago


    united states Oracle Full time

    The Oracle Cloud Infrastructure (OCI) team can provide you the opportunity to build and operate a suite of massive scale, integrated cloud services in a broadly distributed, multi-tenant cloud environment. OCI is committed to providing the best in cloud products that meet the needs of our customers who are tackling some of the world's biggest challenges. ...


  • united states Oracle Full time

    OCI Security Architecture is looking for an experienced security engineer to join our team. The candidate will get the opportunity to work with and learn from outstanding security engineers and architects across Oracle. They will be a security lead and collaborate with cross-functional teams to drive security improvements, innovation and initiatives across...