Principal Offensive Security Engineer
2 weeks ago
Job Requisition ID #
25WD91774
Position Overview
Are you passionate about computers, software, and the art of dismantling code, devices-even cars? Do you love protecting people from digital threats, whether they come from cybercriminals or simple human error? If you've ever read 2600 or celebrated the Phrack anniversary edition at DEFCON33, we might have the perfect role for you.
At Autodesk, we're transforming how the world is designed and built. Our mission is to empower customers to create energy-efficient, low-carbon-footprint buildings through cutting-edge software. We're leading the Architecture, Engineering, and Construction (AEC) industry into a new era-one powered by AI and connected data platforms. As we grow into the Trusted Partner for the AEC industry, we're looking for someone who can help keep our innovations secure.
Autodesk is hiring a Principal Offensive Security Engineer to join our journey. In this role, you'll bring your offensive security expertise to a team of passionate technologists. You'll uncover critical security improvements in our products and identify creative ways to enhance our systems, processes, and practices.
You'll collaborate across teams and geographies, offering insight and support as they address vulnerabilities. You'll help mature our Secure Software Development Lifecycle (SSDLC) across AEC teams and improve our vulnerability and zero-day response processes.
We also invest in your growth-this role includes opportunities to attend top security conferences and training sessions throughout the year, so you can sharpen your skills and bring back fresh ideas.
This is a remote position open to candidates in the United States or Canada . (east coast strongly preferred).
Responsibilities
-
Work with the Senior Distinguished Architect,Trust; to document, maintain, and improve the AEC Secure Software Development Lifecycle
-
Work with theTrustOrganization in various Security Vulnerability Management and 0-day response capacities
-
Manage and mature the AEC security vulnerability and DoD response processes
-
Act as primary point of contact for AEC 0-day reports and assist in engaging Researchers and Engineers
-
Proactively fuzz, research, and investigate AEC Products and Processes for Security issues and improvements
-
Support all AEC Security incident BPM processes
-
Assist engineering teams in secure code development through expertise
-
Help with setting up policies, procedures, and standards to improve Security Posture
-
Engage with AEC engineers to establish training, awareness resources, and other mechanisms to dramatically improve the security of AEC products
-
Partner with other engineers across the company to share Software Security practices, lessons learned, and improve transparency and efficiency
-
Own the various Security metadata components within the Software Catalog, including creation, naming, and maintaining
-
AttendTrustmeetings across the AEC organization (bi-weekly, monthly, and quarterly)
-
Attend industry events and other conventions/conferences to gather new Software Security techniques and to continuously improve this roles' impact
Minimum Qualifications:
-
BS or MS or Equivalent Experience in Cybersecurity/Computer Science (or related technical field)
-
5+ years of hands-on Offensive Security experience or 7+ years of a mix
-
Experience with Offensive Security tools, techniques, and methodologies
-
Experience working with programming languages (Eg. C, C++, C#, Rust, Go, Javascript, Java, Python, Perl, PHP, TypeScript...)
-
Experience collaborating with cross-organizational teams
Preferred Qualifications
-
Experience with writing reports and communicating complex security concepts to technical personnel
-
Familiarity with modern software practices including Continuous Integration, Continuous Delivery, and Infrastructure-as-Code
-
Familiarity with Security Disciplines outside of Offensive Security (Privacy, GRC, Blue Teaming, Awareness)
-
Familiarity with authentication/authorization using OAuth2.0, OICD, SPIFFE, FIDO2, etc.
-
Familiarity with large-scale distributed systems, containing hybrid applications across desktop, mobile, and web
-
Experience in the AEC industry or other regulated industryThe Ideal Candidate
-
Easily collaborates with other members of a team to deliver value
-
Constantly strives to learn new technologies and methodologies
-
Is adaptable, customer-focused, and seek new ways to solve hard problems
-
Is transparent and work in an open sharing manner, leveraging automation
Learn More
About Autodesk
Welcome to Autodesk Amazing things are created every day with our software - from the greenest buildings and cleanest cars to the smartest factories and biggest hit movies. We help innovators turn their ideas into reality, transforming not only how things are made, but what can be made.
We take great pride in our culture here at Autodesk - it's at the core of everything we do. Our culture guides the way we work and treat each other, informs how we connect with customers and partners, and defines how we show up in the world.
When you're an Autodesker, you can do meaningful work that helps build a better world designed and made for all. Ready to shape the world and your future? Join us
Salary transparency
Salary is one part of Autodesk's competitive compensation package. For U.S.-based roles, we expect a starting base salary between $138,100 and $223,300. Offers are based on the candidate's experience and geographic location, and may exceed this range. In addition to base salaries, our compensation package may include annual cash bonuses, commissions for sales roles, stock grants, and a comprehensive benefits package.
Equal Employment Opportunity
At Autodesk, we're building a diverse workplace and an inclusive culture to give more people the chance to imagine, design, and make a better world. Autodesk is proud to be an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender, gender identity, national origin, disability, veteran status or any other legally protected characteristic. We also consider for employment all qualified applicants regardless of criminal histories, consistent with applicable law.
Diversity & Belonging
We take pride in cultivating a culture of belonging where everyone can thrive. Learn more here: https://www.autodesk.com/company/diversity-and-belonging
Are you an existing contractor or consultant with Autodesk?
Please search for open jobs and apply internally (not on this external site).
-
Principal Engineer, Security Platform
2 weeks ago
Augusta, ME, United States Confluent Full timeLocation: Remote, United States Employment Type: FullTime Location Type: Remote Department Engineering Compensation: $310.5K - $372.6K - Offers Equity At Confluent, we are committed to providing competitive pay and benefits that are in line with industry standards. We analyze and carefully consider several factors when determining compensation, including...
-
Principal Security Engineer
1 week ago
Augusta, ME, United States Oracle Full timeJob Description The Principal Security Engineer is responsible for overseeing and managing the organization's cybersecurity strategy, policies, and programs. This includes ensuring the protection of digital assets, sensitive data, and networks from cyber threats, unauthorized access, and data breaches. The role requires a strategic thinker with strong...
-
Principal Security Architect
1 week ago
Augusta, ME, United States SHI GmbH Full timeAbout Us Since 1989, SHI International Corp. has helped organizations change the world through technology. We've grown every year since, and today we're proud to be a $16 billion global provider of IT solutions and services. Over 17,000 organizations worldwide rely on SHI's concierge approach to help them solve what's next. But the heartbeat of SHI is our...
-
Principal Security Architect
6 days ago
Augusta, ME, United States SHI GmbH Full timeAbout Us Since 1989, SHI International Corp. has helped organizations change the world through technology. We've grown every year since, and today we're proud to be a $16 billion global provider of IT solutions and services. Over 17,000 organizations worldwide rely on SHI's concierge approach to help them solve what's next. But the heartbeat of SHI is our...
-
Principal Sales Engineer
1 week ago
Augusta, ME, United States Rocket Software Full timeIt's fun to work in a company where people truly BELIEVE in what they're doing! Job Description Summary: The Principal Sales Engineer role will support Account Executives in new and existing partner relationships, as well as direct business to grow revenue opportunities. Rocket Software Principal Sales Engineers are experienced technical professionals with...
-
Principal Salesforce Development Engineer
2 weeks ago
Augusta, ME, United States CVS Health Full timeAt CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care. As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues –...
-
Provider Digital Principal Software Engineer
6 hours ago
Augusta, ME, United States CVS Health Full timeAt CVS Health, we're building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care. As the nation's leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues - caring for...
-
Principal Software Engineer
6 days ago
Augusta, ME, United States Oracle Full timeJob Description Oracle Cloud Infrastructure (OCI) Search Service with OpenSearch is an insight engine offered as an Oracle managed service. Without any downtime, Oracle automates patching, updating, upgrading, backing up, and resizing the service. Customers can store, search, and analyze large volumes of data quickly and see results in near real time. We are...
-
Principal Software Engineer
1 week ago
Augusta, ME, United States Oracle Full timeJob Description Oracle Cloud Infrastructure (OCI) Search Service with OpenSearch is an insight engine offered as an Oracle managed service. Without any downtime, Oracle automates patching, updating, upgrading, backing up, and resizing the service. Customers can store, search, and analyze large volumes of data quickly and see results in near real time. We are...
-
Principal Software Engineer
1 day ago
Augusta, ME, United States Oracle Full timeJob Description Oracle Cloud Infrastructure (OCI) Search Service with OpenSearch is an insight engine offered as an Oracle managed service. Without any downtime, Oracle automates patching, updating, upgrading, backing up, and resizing the service. Customers can store, search, and analyze large volumes of data quickly and see results in near real time. We are...