Platform Security Manager
Summary
Engineering manager role at a Cambridge, MA vulnerability-management security company: build a product security (AppSec) function from the ground up, lead AppSec and cloud security engineers, and embed security tooling and 'guardrails, not gates' into CI/CD pipelines. Key tech: Java/Python/JavaScript, SAST/DAST tooling, AWS, and Terraform.
- Lead a team of engineers with disciplines in both Application Security and Cloud Security
- Extensive knowledge and experience with implementing best practices in a secure SDLC
- Experience with SAST, DAST, IAST, SCA, RASP, and/or WAF tooling
- Extensive knowledge and experience with one or more of the following: Java, Python, and JavaScript
- Knowledge of integrating custom security controls and security tests in development and build environments
- Automate IaaS assessments, reporting, remediation with a measurable and repeatable process
- Extensive experience building “guardrails, not gates” into CI/CD environments
- Working knowledge of one or more of the following technologies or design patterns:
- Microservice design and architecture
- Using and developing RESTful APIs
- Message queueing systems
- SQL and NoSQL databases (e.g. Cassandra)
- Containerization and virtualization technology (e.g. VMs, Docker)
- Ability to pivot quickly with changing priorities in a dynamic, hyper-growth environment
- Strong capability to communicate security concepts and requirements at all levels of the business
- Strong sense of project ownership and excellent time and task management skills
- Strong desire to mentor teammates and provide leadership on key initiatives/projects
- Education in Computer Science, Information Systems, or a similar field
- 5+ years of experience in the InfoSec and/or software development fields
- Extensive knowledge of AWS security concepts and best practices
- Working knowledge of managing infrastructure and resources in AWS using Terraform and Chef, Ansible, Puppet, or Salt
- Experience with one or more of the following: Go, Ruby, and Erlang
- Experience with Jenkins
- Experience creating threat models and remediation plans
- Working knowledge of identity and access management
- Experience working in Agile Scrum environments