עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לחפש לבד בין מאות מודעות – תנו ל-Jobify לנתח את קורות החיים שלכם ולהציג לכם רק הזדמנויות שבאמת שוות את הזמן שלכם מתוך מאגר המשרות הגדול בישראל.
השימוש חינם, ללא עלות וללא הגבלה.
Team
Product Security is shifting everywhere and holistically improving the maturity of the security program. The Secure Software Development Lifecycle (SSDL) team helps the organisation measure and improve security activities. The team leads product threat modelling, helps to improve security behaviours, and manages a highly visible security champions program. The team is both highly technical and strategic.
Role
As a Staff Product Security Engineer on the ServiceNow SSDL team, you will collaborate with developers and software architects on highly technical solutions and help the organisation build secure and resilient software. You will be threat modelling software products and services to identify potential risks and participate in architectural reviews of products in development.
A key part of this position is to ensure the continued success of a large and growing security champions program. You will help mentor security champions and assist them in secure software design. As a Staff Product Security Engineer, you will help security champions be successful.
What you get to do in this role:
- Work on a wide range of technologies
- Work on complex architectural and technical challenges
- Participate in threat modelling activities
- Mentor and collaborate with development teams to adopt secure coding practices
- Work on strategic and highly visible security activities across the organisation
- Be an advocate for security and participate in a security champions program
Qualifications
To be successful in this role, you have:
- 6+ years of experience in software security (AppSec)
- 3+ years of experience in threat modelling software applications and services
- Proficient in threat modelling methodologies such as STRIDE or PASTA and their applied use in fast-moving, iterative development lifecycles
- In-depth knowledge of common web application vulnerabilities (OWASP Top 10)
- Developer-level proficiency in one or more languages - Python, Java, JavaScript, and Golang preferred
- Working knowledge of Machine Learning and taxonomies such as BIML that categorise known attacks on machine learning models
- In-depth knowledge of software design patterns and their security considerations
- In-depth knowledge of authentication and authorisation standards, including OAuth, OIDC, SAML, JWT, and PASETO
- Knowledge of symmetric and asymmetric cryptography, digital signatures, PKI, TLS, and cryptographic hash functions
במקום לחפש לבד בין מאות מודעות – תנו ל-Jobify לנתח את קורות החיים שלכם ולהציג לכם רק הזדמנויות שבאמת שוות את הזמן שלכם מתוך מאגר המשרות הגדול בישראל.
השימוש חינם, ללא עלות וללא הגבלה.